Google and Microsoft Data Use
Version: 5 October 2026
Google sign-in is separate from sending
The login flow requests openid email profile to identify your account. It does not authorize sending. Lettrium uses a separate OAuth client/project for connecting a Gmail sender.
Gmail sending permission
When you explicitly connect Gmail in Settings → Sender accounts, Lettrium requests openid email profile and https://www.googleapis.com/auth/gmail.send. Identity scopes identify the connected sender; send permission allows the worker to submit the messages you approve. Offline authorization provides a refresh token so queued user-requested work can run without keeping the browser open.
The app does not request Gmail read, modify, full-mailbox or Google Contacts/Drive access. Send-only permission cannot tell us whether your message reached the inbox or received a reply. The result “accepted” records provider acceptance, not inbox placement.
Microsoft connection
The separate Outlook flow requests openid profile email offline_access, delegated User.Read to identify the connected account and Mail.Send to submit approved messages. It does not request inbox-reading permission. Availability depends on deployment settings.
Storage and revocation
Tokens are encrypted and used by server-side delivery processing. They are not included in user exports. Disconnecting clears local tokens; removing the app in provider account settings also revokes provider authorization. Messages already accepted by a provider cannot be recalled by disconnecting.
Limited Use
We follow the Google API Services User Data Policy, including Limited Use. Google data is used to provide the disclosed user-facing features, not sold, used for advertising or used for generalized AI training. See our Privacy Policy for access, sharing, retention and controls.
Operator and contact
Lettrium is operated by Semih Arda Öngül in Türkiye.
For support, privacy requests, abuse reports and other concerns: support@lettrium.com.