Your Google account
What Overcoat can and can't do with your Google account.
Overcoat reads your Gmail and Google Calendar so it can answer questions about them. It can't send, delete, move or change anything. If you allow it, it can save a draft or add an event to your calendar, only when you tap to do it, and put your morning brief in your own inbox at the time you choose.
The permissions you grant
You sign in with Google from Overcoat's setup on your Mac, using a Google Cloud project that you create (so Google shows it as an "unverified app": it's your own, not a company's).
gmail.readonlyCopies your mail to your Mac so it can be searched and counted, and reads your Gmail settings so the security check can spot unexpected forwarding or filters. Read-only: checked when you sign in, every time Overcoat starts, and every time Google renews its access.Yescalendar.readonlyCopies your calendars to your Mac. Read-only, checked the same way.Yesopenid, userinfo.emailTo know which account it's reading.Yesgmail.composeOff unless you turn it on: by default a reply opens in Gmail ready to send (Open in Gmail), which needs no permission. With it on, Save draft puts the reply in Gmail Drafts instead. You send it yourself, from Gmail. Google's permission for this also covers sending; Overcoat's network layer allows only the one "create a draft" request, and there is no code that sends. Leave it off and nothing on your Mac holds a permission that can send mail.Optional, kept separatecalendar.events.ownedAdds an event to a calendar you own when you tap Add to calendar. Overcoat only creates events, with no guests and no invitations sent.Optional, kept separategmail.insertPuts your morning brief and evening wrap into your own inbox, at the times you choose, if you turn on email for them. It adds a message to your mailbox and nothing else: it can't read, send, change or delete anything, and the brief never passes through anyone's server.Optional, kept separateThe optional permissions are separate sign-ins, stored apart from the reading one, each allowed exactly one kind of request. Nothing is saved to Gmail or your calendar without your tap, and each tap is recorded before the request leaves your Mac.
What it can never do
- Send an email, or reply on your behalf.
- Delete, move, archive, label or mark your mail.
- Change Gmail settings, filters or forwarding.
- Edit or delete calendar events, or invite anyone to anything.
- Reach Google Drive, Contacts, Photos or any other Google service.
These aren't promises in a policy: there is no code for them, and automated tests on every build fail if a way to do any of them appears.
Where your data goes
- Your Mac. Mail and calendars are copied into an encrypted database on your Mac, which also holds your chats, notes and files (the key is in your Keychain). No Overcoat server ever sees your mail, and there are no analytics. Your Overcoat account (free, just an email) holds your email address, the Macs you've linked and, for Premium, billing status, and nothing else.
- Your phone. The phone app talks to your Mac directly, over your own private network (Tailscale), signed in with a passkey.
- A cloud AI model, only if you connect one (Claude by default, or ChatGPT or Gemini; with your own key from that provider, inside daily and monthly limits you set). Only the provider you choose gets anything, and only what a question needs. Passwords, codes and account numbers never go, links in your mail are replaced by placeholders, and private chats never leave your Mac. Names, email addresses, phone numbers and street addresses go as written unless you turn on Hide names (Settings → AI). The model can search the web for public information, but it can't open web pages once your mail is part of the conversation. Every request is listed in the app (Activity) exactly as it was sent, with the provider it went to.
How it keeps itself honest
A security check runs on your Mac every 15 minutes. It compares what was written to Google with what you tapped, and watches for new Gmail forwarding addresses, filters that forward or delete, unexpected devices, and changes to Overcoat's own code. It only reports what it finds; it never changes anything by itself.
How to turn it off
- In Overcoat: Settings → Devices → Lock down. It revokes Overcoat's Google access, removes its keys and signs out your devices.
- In Google: myaccount.google.com/connections, find your Overcoat project and remove its access.
- To remove everything: delete the Overcoat app and the
~/assistantfolder on your Mac.
Worth knowing
- Overcoat is new, and built by one person. Expect rough edges in answers and screens; the limits above are the parts that are built to be strict.
- The Mac app isn't notarized by Apple yet, so macOS asks you to confirm before it opens the first time.
- Your Google Cloud project is yours. Google may ask you to sign in again from time to time; Overcoat tells you when it needs that.