Plain English, no fine print. Forward this URL to whoever signs off on your tools.
Our Google integration asks for exactly one permission: gmail.settings.basic. It manages
send-as settings — your email signature — and nothing else. Your admin sees it on the consent screen and
can revoke it in one action.
Not a pledge. A permission boundary.
gmail.settings.basicThis is the only Gmail permission we request, and it is the narrowest one that can set a signature.
| What it lets us do | What it cannot do |
|---|---|
| Read and update send-as settings (your signature) | Read your email |
| Manage basic Gmail settings | Send email on your behalf |
| Search your inbox | |
| Read your contacts | |
| Read your calendar | |
| Read your drafts or attachments |
Names, titles, phone numbers, photos — the details you already broadcast at the foot of every message.
| What we store | What we never touch |
|---|---|
| Name, email, job title, phone | Email content |
| Profile photo and company logo | Inbox and sent items |
| Your signature template and tags | Contacts |
| Provider connection settings | Calendar |
| Drafts and attachments |
Your data is processed and stored in the EU. It is not routed through US data centers, and it is never sold or shared with third parties.
All traffic is HTTPS, and stored data is encrypted at rest on Cloudflare's infrastructure.
The two documents procurement asks for — available up front.
We commission an independent penetration test and share the executive summary with customers under NDA.
A ready-to-sign DPA covering our role as a data processor under the GDPR. Ask sales for a copy.
No. We only request gmail.settings.basic, which manages send-as settings and nothing else. It cannot read, send, or search email.
One: gmail.settings.basic. Your admin sees it on the Google consent screen and can verify it at any time.
In the EU. We do not route data through US data centers.
No. We are not a data broker. The only data we hold is the business-card data you give us, and we use it solely to render your signatures.
In the Google Admin console: Security → API controls → Domain-wide delegation, and remove our client ID. Access stops immediately.
Yes. A signable Data Processing Agreement is available on request from sales@teamsig.org.