Your Google account

What Overcoat can and can't do with your Google account.

Overcoat reads your Gmail and Google Calendar so it can answer questions about them. It can't send, delete, move or change anything. If you allow it, it can save a draft or add an event to your calendar, only when you tap to do it, and put your morning brief in your own inbox at the time you choose.

The permissions you grant

You sign in with Google from Overcoat's setup on your Mac, using a Google Cloud project that you create (so Google shows it as an "unverified app": it's your own, not a company's).

PermissionWhyNeeded?
Read Gmail
gmail.readonly
Copies your mail to your Mac so it can be searched and counted, and reads your Gmail settings so the security check can spot unexpected forwarding or filters. Read-only: checked when you sign in, every time Overcoat starts, and every time Google renews its access.Yes
Read Calendar
calendar.readonly
Copies your calendars to your Mac. Read-only, checked the same way.Yes
Your email address
openid, userinfo.email
To know which account it's reading.Yes
Save drafts
gmail.compose
Off unless you turn it on: by default a reply opens in Gmail ready to send (Open in Gmail), which needs no permission. With it on, Save draft puts the reply in Gmail Drafts instead. You send it yourself, from Gmail. Google's permission for this also covers sending; Overcoat's network layer allows only the one "create a draft" request, and there is no code that sends. Leave it off and nothing on your Mac holds a permission that can send mail.Optional, kept separate
Add events
calendar.events.owned
Adds an event to a calendar you own when you tap Add to calendar. Overcoat only creates events, with no guests and no invitations sent.Optional, kept separate
Brief emails
gmail.insert
Puts your morning brief and evening wrap into your own inbox, at the times you choose, if you turn on email for them. It adds a message to your mailbox and nothing else: it can't read, send, change or delete anything, and the brief never passes through anyone's server.Optional, kept separate

The optional permissions are separate sign-ins, stored apart from the reading one, each allowed exactly one kind of request. Nothing is saved to Gmail or your calendar without your tap, and each tap is recorded before the request leaves your Mac.

What it can never do

These aren't promises in a policy: there is no code for them, and automated tests on every build fail if a way to do any of them appears.

Where your data goes

How it keeps itself honest

A security check runs on your Mac every 15 minutes. It compares what was written to Google with what you tapped, and watches for new Gmail forwarding addresses, filters that forward or delete, unexpected devices, and changes to Overcoat's own code. It only reports what it finds; it never changes anything by itself.

How to turn it off

Worth knowing