Money Clarity

    Is it safe to connect Gmail to an app? Read the scope first

    Is it safe to connect Gmail to an app? The honest answer starts with something the permission screen rarely says out loud: Gmail has no permission for only my bank emails, and none of Google's Gmail permissions is limited to particular senders. So when a finance app says it reads only transaction alerts, the narrowing is something the app chooses to do on its own servers. Google does not enforce it message by message. What stands behind the promise is a different set of things: Google's rules on what the app may do with your data, a security assessment the app has to pass and repeat, and your ability to cut it off yourself at any time.

    That changes the question you should be asking. Is this app safe is too vague to answer. What can this permission reach, what does the app say it touches, and who checks the gap between the two, can be answered. In the illustrative month worked through below, an inbox receives 400 emails. A spending tracker needs 62 of them. A filter on the exact alert senders touches 73, including 11 one-time passwords and security notices it had no use for. The permission itself reaches all 400.

    Below: each Gmail permission in Google's own classification, what read access cannot do and what it still exposes, what Google checks, three routes compared on exposure, how to revoke, and a checklist for any app.

    Last reviewed 2026-09-28

    Is it safe to connect Gmail to an app? Read the scope

    The technique

    The permission is the mailbox; the filter is a promise

    People judge an email permission by what the app says it wants, because that is what the marketing describes. Google grants access by scope, and a scope describes a class of access to the whole account. An app that wants 62 emails a month has to ask for a permission that reaches every email, then choose to search for the 62. The distance between what it asks for and what it uses is exactly the part you are trusting.

    A scope is the unit of permission an app requests when you connect a Google Account. Google's Gmail API scope reference at developers.google.com/workspace/gmail/api/auth/scopes lists each one with a description and a class: non-sensitive, sensitive or restricted. Restricted scopes are the ones Google describes as giving wide access to user data, and every scope that lets an app read message content falls in that class. Here are the ones that matter when a finance app asks for Gmail.

    ScopeWhat Google says it allowsClass
    mail.google.com (full)Read, compose, send and permanently delete all mailRestricted
    gmail.modifyRead, compose and send mail, without bypassing trashRestricted
    gmail.readonlyView email messages and settingsRestricted
    gmail.metadataView message metadata, labels and headers onlyRestricted
    gmail.sendSend email on your behalfSensitive
    gmail.addons.current.message.readonlyView messages while an add-on is runningSensitive
    Descriptions paraphrased from Google's Gmail API scope reference. None of these scopes is limited to particular senders or labels; narrowing to bank mail is done by the app, not by the permission.
    • A tracker that reads alert text needs message content, so the narrowest scope that fits is read-only access to the mailbox. Anything that adds compose, send or delete is more than reading alerts requires, and is worth asking about before you accept
    • Metadata-only access sounds smaller but is not much safer: subject lines and senders across the whole inbox already say who you bank with and which hospital writes to you. And an alert's amount is usually in the body, which metadata cannot see
    • The add-on scopes are the one genuinely narrow case, limited to the message you have open. They suit a tool you click while reading an email, not a tracker that has to see every alert as it arrives

    What read-only Gmail access cannot do

    A read-only permission lets an app look. It does not let the app act in your mailbox: sending mail is a separate scope, gmail.send, and deleting or moving messages needs a broader one. If the consent screen mentions sending, composing or deleting, the app has asked for more than reading.

    It also does not reach your Google password. Google's help page on linked apps at support.google.com/accounts/answer/14012355 says linked apps can access only the data and services you authorise, and warns never to type your Google Account password into a third-party app, because the password would give full access to the account.

    And it cannot move money. Email is where a bank tells you money has moved, not where it moves. A payment needs a net-banking login, a UPI PIN or card details, and none of those travels through an email permission. The worst case of a read permission is that someone learns things about you, not that someone spends your balance.

    Learning things is not nothing, though. Two kinds of message in an ordinary inbox turn read access from a privacy question into a security one.

    • One-time passwords. Some banks and card issuers email an OTP alongside the SMS. An OTP is half of an authorisation; the other half, a card number or a login, is not in the permission. The OTP expires in minutes, but a reader of your inbox sees it while it is live, which is why a tracker should skip these rather than fetch them
    • Password reset links. Many services send a reset link to your email. Anyone reading your inbox in real time could, in principle, finish a reset you did not start. The risk here is less the app reading your mail than its servers or stored access tokens being broken into
    • Statements. An emailed statement is a year of your spending in one attachment. A tracker that reads statements holds a fuller picture of you than one reading alerts, so ask what it keeps once it has parsed one

    Gmail access for a finance app: 400 emails sorted

    To see what a tracker needs from an inbox, sort one month. The household here banks with two banks and holds three credit cards from two issuers, so four institutions send it mail. The month's 400 emails, all illustrative, sorted by who sent them. Then two ways an app might narrow its reading: a filter on the exact addresses the alerts come from, and a looser filter on every address at those banks' and issuers' domains.

    Emails in the monthCountSender filterDomain filter
    Transaction alerts: debits, credits, card spends57ReadRead
    E-statements with PDF (2 bank, 3 card)5ReadRead
    OTPs and security notices from alert senders11ReadRead
    Offers and newsletters from the same institutions31Not readRead
    Shopping orders, deliveries, receipts64Not readNot read
    Work and personal mail48Not readNot read
    Promotions and newsletters from others142Not readNot read
    Social and app notifications42Not readNot read
    Total40073 read104 read
    Illustrative month for one person with two bank accounts and three cards. Counts vary widely by person; the shape is what matters. Sender filter: the specific addresses alerts and statements come from. Domain filter: any address at the bank or issuer.
    • What the tracker actually needs is the 57 alerts and 5 statements: 62 emails, 15.5 percent of the inbox. Transaction alerts alone are 14.25 percent. Everything else is either noise to it or something it should not see
    • The sender filter touches 73 emails, 18.25 percent of the month, and leaves 327, or 81.75 percent, unread. But 11 of its 73, 15.07 percent, are OTPs and security notices, because banks often send them from the same address as the alerts. A careful app filters them out by content after fetching, or does not fetch them at all
    • The domain filter is lazier and reads 104 emails, 26 percent of the inbox. 42 of those, 40.38 percent of what it touches, are marketing and security mail it has no use for. Asking which of the two an app uses is a fair question with a checkable answer
    • The permission reaches all 400, about 6.45 times what the tracker needs. Over a year that is 4,800 emails in reach against 744 needed and 876 touched by a sender filter, of which 132 are security messages. The gap between 4,800 and 876 is what Google's rules and the app's own conduct have to hold

    What Google checks before an app reads Gmail

    Because read access to Gmail is a restricted scope, an app that wants it for the public has to clear more than a consent screen. Google's page on restricted scope verification, at developers.google.com/identity/protocols/oauth2/production-readiness/restricted-scope-verification, says every app that requests restricted data and can access it from or through a third-party server must go through a security assessment. The assessment uses the App Defense Alliance's cloud application security assessment framework, known as CASA, and is carried out by assessors Google has empanelled. To keep the access, the app has to be reverified and reassessed at least every 12 months. Google's Cloud help page on verification requirements, support.google.com/cloud/answer/13464321, describes the same thing as an annual security assessment.

    The rules on use come from the Google API Services User Data Policy at developers.google.com/terms/api-services-user-data-policy. Its Limited Use terms say an app may use restricted data only to provide or improve user-facing features that are prominent in its interface, must not transfer or sell it to advertising platforms, data brokers or information resellers, and must not use it to serve ads. They also say humans at the company must not read the data, except with your affirmative agreement to view specific messages, for security or legal compliance, or when it is aggregated for internal operations. The same policy tells developers to request the minimum relevant permissions.

    • Verification checks how an app is built and what it says it does. It is not a daily audit of what it does with your mail, which is why you still want an app whose business does not depend on your data
    • Google lists exceptions to verification, including apps for personal use by a limited set of known users and apps used only inside one organisation. A tool a stranger built and shared informally may never have been assessed at all
    • The assessment is repeated at least every 12 months. An app that was verified once and says so in old marketing is making a claim with a date on it. Ask when its current assessment was completed

    Bank password, AA consent or alerts: exposure

    The technique

    Separate what a route can see from what it can do

    People rank these three routes by how intrusive the setup feels, and the email permission feels most intrusive because the inbox is personal. On the question that costs money, whether the route can act on your account, it is the password that stands apart, not the inbox.

    There are three common ways a finance app gets your transactions. They expose very different things, and the one that feels most personal is not the one that can cost you money. The full route-by-route ledger of what each can see and do, with its upkeep, is on the page about an expense tracker without a bank login; how consent, purpose and expiry work under the RBI-regulated framework is on the account aggregator explainer.

    Net-banking passwordAccount aggregator consentEmail-alert reading
    What it seesEverything the login shows, for every account on itThe accounts and data range you consent toWhat the scope reaches: in practice the whole inbox
    Can it move moneyYes, whatever the login permitsNo, it is a data-sharing consentNo, email is not a payment channel
    Non-financial data exposedLittle beyond the bankNone by designAll mail, unless the app filters
    Who sets the limitsOnly the app's conductThe consent: purpose, range, expiryGoogle's scope and Limited Use rules
    How you stop itChange the bank passwordRevoke in the aggregator's appRemove access in your Google Account
    General comparison. Account aggregator coverage differs by bank and account type, and each consent sets its own terms. Banks tell customers never to share net-banking credentials; doing so can breach the account terms.
    • The password is the only route that can act on your money, and the only one limited by nothing but the app's good behaviour
    • Account aggregator consent is the narrowest on data: bounded by account, date range, purpose and expiry, and it carries only financial data. Its cost is coverage: not every institution or account type is on the network, and card data availability varies
    • Email reading exposes the most non-financial data and none of the ability to transact, so trust in the app's filtering carries the most weight here

    Revoke app access to Gmail, and what it leaves

    You can cut off any app yourself, without contacting it. Google's help page on managing third-party links, support.google.com/accounts/answer/13533235, gives the steps. Open myaccount.google.com/linkedapps. Choose Access to your Google Account, pick the app, select See details, then Remove access, and confirm. After that, Google says, the app cannot access your Google Account.

    The same page separates this from Sign in with Google. An app listed only under Sign in with Google has a sign-in link, not access to your Google Account data; apps that can read data appear under Access to your Google Account. Stopping Sign in with Google ends the automatic sign-in and, in Google's words, does not delete your data on the app.

    Revoking stops the future. It does not reach back. Google's linked apps page, support.google.com/accounts/answer/14012355, says that after you revoke access you may need to contact the developer to ask them to delete the data they already have.

    Connected for three months, then revoked
    Emails touched by a sender filter per month
    73
    Months connected
    3
    Emails already fetched when you revoke
    219
    Of which transaction alerts
    171
    Emails the app can fetch after you revoke
    0

    Uses the illustrative 400-email month above. What the app kept of those 219 depends on its retention; revocation removes access, not stored data.

    • Revoke and delete are two separate actions. Remove access in your Google Account, then use the app's own account deletion, or write to it, for what it holds. An app that makes the second step hard is telling you something
    • Review the list once a quarter. Any app you do not recognise, or no longer use, with access to your Google Account is exposure with nothing in return

    Google account third-party access risk: a checklist

    Nothing in the checklist below needs technical knowledge, and every item has a checkable answer. It works for any app that asks for your inbox, finance or otherwise. If no email permission feels right, the route that reads bank SMS on Android is covered on the SMS expense tracker page.

    • Read the consent screen. Viewing messages is what a tracker needs. Sending, composing or deleting is more than reading alerts requires
    • Ask what the app actually fetches: exact alert senders, whole bank domains, or everything. The answer changes 73 emails a month into 104 or 400
    • Ask whether it has completed Google's restricted-scope verification and when its current security assessment was done. It is repeated at least every 12 months, so a date matters
    • Find out how it earns money. An app paid by subscription or commission has less reason to want your mail than one whose model is unclear, and Google's Limited Use terms forbid selling or advertising use of the data anyway
    • Check what it stores after parsing: the transaction lines only, or the full email and attachment. Parsed lines are enough to track spending
    • Confirm it never asks for a net-banking password, a UPI PIN, a card CVV or an OTP. Reading alerts needs none of these, and a request for any of them is a reason to leave
    • Know where to revoke it before you connect it: myaccount.google.com/linkedapps. And know how to delete what the app kept, because revoking does not

    How Unyfy helps with tracking from email alerts

    The problem this page describes is getting an accurate record of your spending without handing an app more than it needs. Unyfy reads bank and card transaction emails and, on Android, transactional SMS, and turns them into a record of your debits with no manual entry. When the same debit arrives through both an SMS and an email, it drops the second copy, so a payment is counted once. It never asks for your bank password or UPI PIN, and every payment is one you authorise.

    What you see is your spending as transactions, each with the amount, the date and a merchant name, which it maps from UPI handles using a merchant database. If you would rather not connect Gmail, statement PDFs from Axis, HDFC, ICICI, Kotak and Federal Bank can be parsed instead, and on Android the SMS route works on its own.

    Read the consent screen when you connect, check it against the scope table above, and remove access at myaccount.google.com/linkedapps whenever you choose. Install Unyfy on Android, or use the web app at app.unyfy.co.in on an iPhone.

    Common questions

    Is it safe to connect Gmail to an app that tracks spending?

    It can be, if three things check out. The consent screen asks to view messages, not to send or delete them. The app fetches only alerts and statements, which in an illustrative 400-email month is 62 messages, rather than the whole inbox the permission reaches. And it has completed Google's restricted-scope verification, which includes a security assessment repeated at least every 12 months. Read access cannot move money; the real exposure is OTPs and reset links in the same inbox.

    Is an app reading my email safe if it says it only reads bank alerts?

    The claim is about the app's behaviour, not the permission. Gmail has no scope limited to certain senders, so an app that reads only bank alerts has access to the whole mailbox and chooses to search for alerts. Ask how it filters: exact alert senders touch about 73 emails in the illustrative month, whole bank domains about 104.

    Is Gmail access for a finance app safer than sharing a bank password?

    On the question that costs money, yes. A net-banking password lets whoever holds it act on the account, and sharing it usually breaks the bank's terms. Read access to email cannot make a payment, because payments need a login, a UPI PIN or card details, none of which an email permission carries. Account aggregator consent is narrower than both on data.

    How do I revoke app access to Gmail?

    Open myaccount.google.com/linkedapps, choose Access to your Google Account, select the app, then See details, Remove access and Confirm. Google's help page says the app then cannot access your Google Account. Revoking does not delete what the app already fetched: connected for three months with a sender filter, that is 219 emails in the illustrative example. Ask the app to delete that separately.

    What is the Google account third-party access risk I might have forgotten?

    Old connections. An app you once granted access can keep it until you remove it, whether or not you still use the app. Apps listed only under Sign in with Google have a sign-in link rather than data access; the ones to scrutinise are those listed under Access to your Google Account.

    Does Google verify apps that read Gmail?

    For apps offered to the public, yes. Reading Gmail content is a restricted scope, and Google's developer pages say any app that requests restricted data and can access it through its own servers must pass a security assessment by a Google-empanelled assessor under the CASA framework, and repeat it at least every 12 months. Personal-use tools with a few known users are exempt, so confirm rather than assume.

    Connecting Gmail to an app is safe to the extent that three things hold: the scope is no broader than reading, the app fetches only what it needs, and it has passed and keeps passing Google's security assessment for restricted scopes. The permission reaches the whole inbox either way: 400 emails in the illustrative month, of which a tracker needs 62. Read access cannot send mail or move money, but it can see OTPs and reset links. Revoke it from your Google Account at any time, and ask the app separately to delete what it kept. Informational page, not security or financial advice. Email counts are illustrative. Google's scopes, verification rules and account settings can change; Google's own developer and help pages govern, not this page, and each app's privacy policy and terms govern what it does with your data.

    Our Partners

    Banks and NBFCs we compare

    Unyfy compares offers from these lenders and earns a commission if you take one. The comparison is shown first, and it can tell you not to switch.

    HDFC Bank logo
    ICICI Bank logo
    Axis Bank
    State Bank of India logo
    IDFC First Bank logo
    Kotak Mahindra logo
    IndusInd Bank logo
    Yes Bank logo
    Bajaj Finserv logo
    Tata Capital logo