Skip to content
Sortmailsortmail
Permissions

What Sortmail asks your mailbox for.

Read this before you connect anything. Google or Microsoft will show you their own consent screen; this is the same list in plain language, with what each permission technically allows and what Sortmail actually does with it.

Last reviewed 25 September 2026

At a glance

Read message headersSender, recipients, subject, date and mailing-list headers. This is what most sorting is decided from.
Needed
Read message textOnly with “Read message text to sort accurately” on. You see that choice before anything is sorted.
Your choice
Label and archiveLabels on Gmail, categories and folders on Outlook. This is the product.
Needed
Send mailSortmail never sends, replies or drafts on your behalf.
Never
Delete mailSortmail never deletes or trashes a message. Archived mail is still in your mailbox.
Never
Contacts, calendar, filesNot requested from either provider.
Never

Signing in asks for nothing but who you are. The mailbox permission is requested later, at the step where you turn sorting on, so you can create an account and look around before granting anything.

Gmail

Google restricted scope
gmail.modifyhttps://www.googleapis.com/auth/gmail.modify
Read a message to decide its category, then add or remove labels and archive it. This is the one mailbox permission Sortmail uses on Gmail.
openidopenid
Confirms which Google account you signed in with.
emailemail
Your address, so we know which mailbox the permission belongs to and where to send the digest.

Why gmail.modify, and not something narrower

Sorting means putting a label on a message and, for mail that does not need you, taking it out of the inbox. On Gmail, archiving is itself a label change: the message loses its Inbox label. Google's narrower scopes cannot do either. gmail.readonly and gmail.metadata can only read. gmail.labels can create and rename labels, but cannot put one on a message. gmail.modify is the narrowest scope that can.

What it technically allows

Google describes gmail.modify as permission to read, compose and send email, and to move messages to the trash. It does not allow immediate, permanent deletion. That is broader than what Sortmail needs, and we would rather say so than let you find out from the consent screen.

What Sortmail actually does with it

  • Lists new messages in your inbox and reads their headers.
  • Reads a short excerpt of the text, only if you leave that option on (see below).
  • Creates the labels for your categories, and adds or removes labels on messages.
  • Asks Gmail to tell us when new mail arrives, so it is sorted as it comes in rather than on a timer.

Sortmail's code never calls Gmail's send, draft, trash or delete functions, and a test fails our build if anyone adds a call to one. We do not request gmail.send or the full-access mail.google.com scope at all.

Google's security assessment

Google classes gmail.modify as a restricted scope, and every app that uses one must complete an annual security assessment (CASA). Our letter of assessment has not been issued yet; when it is, it will be published on our security page.

Outlook and Microsoft 365

Mail.ReadWritehttps://graph.microsoft.com/Mail.ReadWrite
Read a message to decide its category, then set an Outlook category on it and move it out of the inbox.
User.Readhttps://graph.microsoft.com/User.Read
Your basic profile, which is how we learn the mailbox address. Nothing about other people in your organisation.
offline_accessoffline_access
Lets sorting continue when you are not signed in. Without it, access would lapse within the hour and new mail would pile up unsorted.
openidopenid
Confirms which Microsoft account you signed in with.
emailemail
Your address, so we know which account is yours.
profileprofile
Your name, asked for at sign-in only. It is not needed to sort mail.

Why Mail.ReadWrite

Sortmail sorts Outlook mail by setting a category on the message and moving it out of the inbox into a folder. Both are changes to a message, and Microsoft has no permission that allows them without also allowing it to be read. Mail.ReadBasic leaves out the message text but is read-only, so it cannot sort anything.

What it technically allows

Mail.ReadWrite lets an app read, create, change and delete messages in your mailbox. It does not include sending: that is a separate permission, Mail.Send, which Sortmail does not request. Sortmail's code sets categories and moves messages; it never deletes one.

One difference from Gmail is worth knowing. Google can deliver a message with only its headers, so with the text option off the body never reaches us at all. Microsoft has no header-only permission that can also sort, so on Outlook that restraint is enforced by Sortmail asking only for the header fields, not by Microsoft.

What Sortmail reads

By default, the headers of each new message:

FromToSubjectDateList-IdList-UnsubscribePrecedenceAuto-SubmittedContent-TypeIn-Reply-ToReferencesReturn-Path

Headers are enough to recognise a newsletter or an automated sender. Telling a receipt from a personal note needs the words, which is what the “Read message text to sort accurately” option is for. You see it, already ticked, before anything is sorted, and you can untick it there or change it per mailbox in Settings at any time.

With it on, and only when your rules and past corrections cannot decide:

  • The sender's address, the subject and the first 400 characters of the text are sent to our classifier, with the names of your categories to choose from.
  • Card numbers, national identifiers and one-time codes are masked before it leaves our servers.
  • It is never stored, by us or by the classifier, and never used to train any model.
  • The classifier answers with a category and how sure it is; Sortmail keeps those and nothing else.

With it off, only headers ever leave your mailbox, and only Newsletters and System can be filled. The classifier is listed with every other provider we use on our sub-processor page.

What Sortmail stores

A fingerprint of each message, never the message. For each one: the sender and their domain, the mailing-list identifier if there is one, a keyed hash of the subject, a handful of true-or-false characteristics such as whether it had an attachment, the category, and why it was chosen.

Never stored: message bodies, attachments, or subject lines in readable form. The database has no column that could hold them, and an automated test fails our build if anyone adds one. The permission itself is kept as an encrypted token, until you disconnect.

What Sortmail never does

  • Sends, replies to, forwards or drafts mail as you.
  • Deletes or trashes a message. Archived mail is still in your mailbox, one search away.
  • Asks for your contacts, calendar or files, on either provider.
  • Uses your mail for advertising, sells it, or uses it to train any AI model.
  • Lets a person at Sortmail read your mail. Support never opens a message on your behalf.

How to take the permission back

In Sortmail: Inboxes → Disconnect stops sorting that inbox straight away and deletes our copy of the permission. On Google it also revokes the permission itself. Microsoft gives apps no way to revoke, so on Outlook remove Sortmail at Microsoft as well. The inbox’s sorting history is kept, and every label already applied stays where it is.

At your provider, which works even if Sortmail is unreachable:

Googlemyaccount.google.com/connections — Third-party apps and services → Sortmail → Delete all connections.
Microsoft (personal)account.live.com/consent/Manage — Apps and services you have given access → Sortmail → Remove these permissions.
Microsoft (work or school)myapps.microsoft.com — Or ask your administrator, who can remove the app for everyone in your organisation.

Disconnecting is not deleting. Account → Delete revokes each Google permission first, then purges everything — the stored permissions and fingerprints included — within 24 hours. See Revoking access for more.

Google user data and Limited UseSortmail's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.