Is it safe to connect Gmail to an app? Read the scope
The technique
The permission is the mailbox; the filter is a promise
People judge an email permission by what the app says it wants, because that is what the marketing describes. Google grants access by scope, and a scope describes a class of access to the whole account. An app that wants 62 emails a month has to ask for a permission that reaches every email, then choose to search for the 62. The distance between what it asks for and what it uses is exactly the part you are trusting.
A scope is the unit of permission an app requests when you connect a Google Account. Google's Gmail API scope reference at developers.google.com/workspace/gmail/api/auth/scopes lists each one with a description and a class: non-sensitive, sensitive or restricted. Restricted scopes are the ones Google describes as giving wide access to user data, and every scope that lets an app read message content falls in that class. Here are the ones that matter when a finance app asks for Gmail.
| Scope | What Google says it allows | Class |
|---|---|---|
| mail.google.com (full) | Read, compose, send and permanently delete all mail | Restricted |
| gmail.modify | Read, compose and send mail, without bypassing trash | Restricted |
| gmail.readonly | View email messages and settings | Restricted |
| gmail.metadata | View message metadata, labels and headers only | Restricted |
| gmail.send | Send email on your behalf | Sensitive |
| gmail.addons.current.message.readonly | View messages while an add-on is running | Sensitive |
- A tracker that reads alert text needs message content, so the narrowest scope that fits is read-only access to the mailbox. Anything that adds compose, send or delete is more than reading alerts requires, and is worth asking about before you accept
- Metadata-only access sounds smaller but is not much safer: subject lines and senders across the whole inbox already say who you bank with and which hospital writes to you. And an alert's amount is usually in the body, which metadata cannot see
- The add-on scopes are the one genuinely narrow case, limited to the message you have open. They suit a tool you click while reading an email, not a tracker that has to see every alert as it arrives






