InboxwellGitHub
Account access

OAuth permissions, explained

Inboxwell asks only for access needed to work as an email client. You approve access on Google or Microsoft pages and can revoke it at any time.

Effective August 12, 2026

Google account permissions

Inboxwell's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • View and manage your mail: download and display messages, synchronize threads and labels, mark read or unread, archive, move, delete, draft and send mail.
  • View basic mailbox settings: read your configured Gmail send-as identities so Inboxwell can show the correct sender name and address.
  • Identity and offline access: identify the connected account and renew access without asking you to sign in every time.

Microsoft account permissions

  • User.Read: identify the signed-in account and display its profile name and address.
  • Mail.ReadWrite: synchronize messages and folders and perform actions you request, such as mark, move, archive or delete.
  • Mail.Send: send new messages and replies you compose.
  • offline_access: refresh authorization so synchronization can continue after the initial sign-in.

What Inboxwell does not request

  • Your Google or Microsoft password.
  • Access to Drive, Calendar, Contacts, OneDrive or Teams unless a future feature clearly asks for separate consent.
  • Administrative access to your organization.

How to revoke access

Remove the account inside Inboxwell to clear its local cache and credential. You can also revoke access from your Google Account connections or Microsoft account permissions.