Skip to main content

Security & connections

Your connections. Your controls.

Connecting an account gives Konnect permission to do specific work for you. Here’s what that access means, how your team can review the work, and how to disconnect.

See Google permissions

Day-to-day controls

Keep people in the loop.

Your team sets the rules for connected accounts and assisted replies. These controls help you keep track of who has access and what needs a review.

Credentials are encrypted at rest

Connected-service credentials and OAuth refresh tokens are encrypted when stored. Each connected mailbox’s refresh token belongs to its own workspace and account.

You choose when AI can send

Require approval before assisted drafts go out, or enable automatic replies for the workflows you choose. You can pause the replier for a conversation or across the workspace.

Access follows your workspace

Roles and workspace boundaries help manage who can see and do what. Audit history gives your team a record to review when following up on activity.

Google account connections

What you share when you connect Google.

Connecting Google is optional and starts only when a workspace member chooses it. Konnect uses Google data to provide the connected mailbox, sending, support, and reply features you choose. It is not used for advertising or the sale of Google user data.

Account identity

The openid and email permissions identify the connected mailbox and let Konnect show which Google account is active in your workspace.

Gmail read access

The gmail.readonly permission retrieves messages and thread context for the Personal Email Replier and Customer Service workflows you enable.

Gmail organization access

The gmail.modify permission lets the Personal Email Replier reply in the original thread, clear the unread flag on messages you have already handled, and — only when you switch it on — file an answered conversation under a label you already created. Konnect never creates labels and never deletes mail.

Gmail signature access

The gmail.settings.basic permission reads the signature you composed in Gmail so replies you send through Konnect carry it. It is read-only: Konnect never changes a Gmail setting.

Gmail send access

The gmail.send permission delivers user-initiated or configured replies and workspace email through the Google account you connected.

Offline access and storage

Offline access supports mailbox polling and configured replies while you are away, until you disconnect or revoke access. OAuth credentials are encrypted at rest.

If you enable an AI-assisted workflow, relevant message content may be processed to classify a message or prepare the user-facing draft you requested. Read more about how information is handled in our Privacy Policy.

Changing your mind

You can disconnect.

Remove the connection from Konnect or revoke Konnect’s access from your Google Account. Offline access supports polling and configured replies only until you disconnect or revoke access.