What permissions an app that reads your email asks for (and which you can refuse)
Reading mail, calendar and tasks to show you the day; writing only if you are going to let it act. They are separate blocks and can be granted one at a time.
The short answer: the read permissions are the essential ones; the write permissions are optional and asked for separately. Showing you the day requires reading mail, calendar and tasks. Replying, archiving or creating something requires a different permission, granted afterwards and only if you want it. Contacts and Drive documents sit in their own block, because they are not needed for the basics.
The blocks, one by one
- Reading mail, calendar and tasks. The minimum for the screen to have anything to show. Without it there is no list for today.
- Mail actions (mark as read, star, archive, draft, reply). Here every verb has its own permission: preparing a draft and sending it are not the same thing and are not requested together.
- Calendar and task actions (create or complete). Also separate.
- Contacts. Used to put names to the people who write to you and to autocomplete. Refuse it and you see addresses instead of names; everything else carries on.
- Drive documents attached to an event. Read-only, and only so the summary of the eleven o'clock meeting can tell you what needs preparing. The easiest one to say no to.
What anyone asking for permissions should do
Three things, and they are fair to demand of any application, not only ours:
- Ask when the permission is used, not all of them at the door. A first screen demanding ten permissions to show an inbox is asking just in case.
- Work when you say no. Refusing contacts should not leave the application blank.
- Be revocable. A Google or Microsoft permission is revoked from the account itself, without going through whoever asked for it.
What happens to what was already read
Revoking cuts off future reading; it does not by itself erase what was stored to keep the screen fast. That is why it matters what is kept and for how long: it is written down in the retention policy, and the processing in the privacy policy. Sensitive material is stored encrypted at rest, including the addresses of linked calendars, which are credentials even when they do not look like one.
What we do not ask for
We do not ask for your Google, Microsoft or Apple password: everything goes through the provider's consent screen. We do not ask for access to your whole Drive, only to what is attached to an event, and only if you authorise it. And with Microsoft we ask for read access only, because that is all the integration can do today.
One detail about this beta
Madrugo is in private beta, with allowlisted access: connecting any account is not enough. We mention it here because it is an honest part of the answer to "what do I need in order to use it".
If you want to keep going, privacy gathers the pieces on memory, consent and what these assistants know about you; and the full setup is in how to organise email, calendar and tasks in one place.
Frequently asked questions
- Can I use it granting read access only?
- Yes. Reading mail, calendar and tasks is enough for today's list and the daily summary. Actions — reply, archive, create — are a separate permission you can decline forever.
- How do I revoke access?
- From your Google or Microsoft account, in its connected applications panel. Reading stops immediately; what is kept, and for how long, is set out in the retention policy.
- Do I have to grant Drive access?
- No. It is optional and read-only, and it exists so the summary can look at the document attached to a meeting. Everything else works the same without it.