Guide

Is it safe to give an AI access to your email?

A vendor answering that question about itself is worth nothing, so this page is eight questions to put to any vendor, phrased to work on a competitor, with our own answers underneath, in full.

  • Reading About 7 minutes
  • Questions 8, usable on anyone
  • Ours All eight, in full

The short version

The risk lives in the connector, not the AI. Ask who holds the credential, what it can reach, what is stored, and how you revoke it without their help. If any answer is vague, that is the answer.

Framing

The question is about the connector, not the AI

"Is it safe to give an AI access to my email" sounds like one question and is really two, aimed at two different companies.

The assistant sees whatever passes through the conversation. That is between you and whoever makes it, it is governed by their terms on retention and training, and no mail connector can answer it for you.

The connector holds a credential to your mailbox and can use it. That is the part with the interesting failure modes, it is almost never the company whose name is on the assistant, and it is the one nobody asks about.

Nearly all the useful scrutiny belongs to the second. An assistant with no connector cannot touch your mail at all; a connector with a bad answer to question four can touch it whether or not an assistant is involved.

Email AI safety depends on the connector, not the assistant: the robot standing between a screen and a padlocked mailbox, holding the key that joins them.
The key is the part worth asking about

The checklist

Eight questions to ask any vendor

Written so you can send them to somebody else. A vendor who answers all eight plainly is one you can assess; a vendor who answers in adjectives has told you something too.

  1. What credential do you hold, and can I revoke it without asking you? The second half is the important half. Access you can only end by emailing support is access you do not control.
  2. What exactly can that credential reach? "My mailbox" is not an answer. Can it reach the calendar, the contacts, the files, other people's mailboxes in the same organisation?
  3. Do you store my messages, and where? Ask for the storage rather than the intention. "We do not read your mail" and "we keep a copy of your mail" are both true of a great many products at once.
  4. Does reading a message change it? A tool that marks everything read while surveying is a tool that has destroyed your unread count, which is a signal you were using.
  5. What can it do without me asking? Rules, schedules, background jobs and auto-replies are all things that act while you are asleep. Some products want them. You should know which.
  6. Who is the legal entity, and where? A trading name with no company behind it is a company you cannot pursue.
  7. What have you NOT done? Nobody volunteers this. A vendor who names a gap is a vendor doing an inventory; one who claims none is one who has not looked.
  8. What happens to my access if you disappear? If the answer involves your mail being somewhere other than your mailbox, that is worth knowing before rather than after.

The one that separates them

Question seven. Everything else can be answered well by a careful marketing page. A specific, uncomfortable, checkable gap cannot be, and a vendor willing to publish one is telling you the other seven answers were written by somebody who meant them.

Our answers

Our own answers, including the bad ones

Question Our answer
1. Which credential, and can you revoke it? An app password (Gmail), an OAuth grant (Microsoft 365) or an IMAP password. All three are revoked from your own account without our involvement.
2. What can it reach? One mailbox, and one calendar if you connect one, which is a separate step. No contacts, no files. Shared and delegated mailboxes are not supported, so your account does not expose the team's.
3. Do you store messages? No. There is no database, no cache and no message store in the server. The credentials we do hold are encrypted at rest with AES-256.
4. Does reading change anything? No. Message source is fetched with IMAP's BODY.PEEK, which does not set the Seen flag. Marking read is a separate tool.
5. What acts without you? Nothing. No rules, no schedules, no background jobs. Every action follows a tool call, and a tool call follows a request from you.
6. Who is the entity? BSolve IT Limited, company 04607330, registered in England and Wales. The registered address is on the terms.
7. What have you not done? Shared and delegated mailboxes, contacts, files, archiving and export, and a calendar on anything other than Microsoft 365. Each is a deliberate boundary, and each is written on the page it belongs to rather than left to be found later.
8. If you disappear? Your mail is in your mailbox and there is no copy anywhere else. Nothing about your mail changes.

Where the boundaries are written down

Answer seven is the one worth checking rather than taking on trust, so it is worth saying where to check it. Every page on this site ends with a section headed "what it does not do", and the entries are specific enough to test: shared and delegated mailboxes are not supported, attachments are capped at 10 MB per message in total across every file rather than per file, and nothing archives, backs up or exports a mailbox. A vendor whose limits section says "some restrictions apply" has not answered the question.

The advice above is to start on a mailbox you would mind least. The free tier lets you do exactly that, with no card.

Realistic

What you are actually exposing

Worth being concrete, because "access to your email" covers everything from a signature block to a decade of legal correspondence and people picture the wrong end of that.

To the connector

The ability to act on one mailbox: read, search, send, reply, forward, move, delete to Trash, flag. That is genuinely a lot, and it is the same access your desktop mail client has had for years with the same kind of credential.

To the assistant

Only what passes through the conversation. If you ask it to read four messages, four messages are in the conversation. It is not indexing your mailbox in the background, because there is no background.

To anyone who gets the credential

This is the real risk and it is the one worth thinking about, because it is the same risk as any other stored credential anywhere. It is why question one matters most, and why "revocable by you, without us" is the property to insist on rather than any promise about intentions.

What connecting an AI to email actually exposes: the robot beside one open mailbox while three other closed mailboxes stand untouched behind him.
One mailbox open, the others not reachable

Practice

How to reduce the exposure

Five things that cost nothing and are worth doing whichever product you choose.

  • Start on a mailbox that is not your main one. An old domain, a side project, an enquiries address. You learn the same lessons with a fraction of the exposure.
  • Use an app password rather than your account password wherever the provider offers one. It is revocable on its own and it does not unlock anything else.
  • Prefer OAuth where it exists. On Microsoft 365 no password reaches us at all, and you can see and withdraw the grant from your own account page at any time.
  • Read the consent screen properly. It is the one moment the true permission list is put in front of you. Ours asks for four Microsoft permissions; if a consent screen asks for more than the product needs, that is the moment to stop.
  • Revoke when you stop using it. Dormant access is the access nobody remembers to review.
Reducing the risk of connecting an AI to email: the robot working a small open mailbox while a larger padlocked one stands untouched beside it.
Start on the one you would mind least

Connect an old domain or a side-project address first, and revoke it from your own account whenever you like.

Limits

What this guide cannot tell you

  • Your assistant's terms

    Whether your assistant provider trains on your conversations. That is in their terms, not ours, and it changes.

  • A vendor's answer

    Whether any other vendor's answers are true. The questions are checkable; the answers are theirs to give and yours to weigh.

  • Your employer's rules

    Whether your employer permits any of this. On a work mailbox that is a question for your IT department first, and an administrator can block it regardless.

  • Past the security page

    Anything about our own security beyond what is on the security page, which is deliberately specific about what has not been done.

Is it safe to give an AI access to my email?

It depends almost entirely on the connector rather than on the AI. The assistant is one party and the thing holding your mailbox credential is another, and they are usually different companies with different answers. Ask the eight questions on this page of whoever holds the credential, and judge from the answers rather than from the assurance.

Can the AI company read my messages?

They see the messages you ask it to read, in the conversation, the same way they see anything else you put in front of it. What they do with that is governed by your agreement with them, not with us. It is a real consideration and it is not one any mail connector can answer for you: read your assistant provider's own terms on training and retention.

What happens if I change my mind?

You revoke it from your own account and it stops working immediately, without needing our cooperation. An app password is revoked in your Google Account, an OAuth grant in your Microsoft account, and an IMAP password by changing it. That is the property worth insisting on: access you can end without asking anyone.

Is a local MCP server safer than a remote one for mail?

Less than it appears. A local mail server keeps the credential on your own disk, which is a genuine advantage, but your messages still travel to Gmail or Microsoft over the same connection either way. What changes is who holds the key, not whether the mail moves.

Could it send email as me without my asking?

A tool call happens when a client asks for one, and a client asks when you do. There is no scheduler, no rule and no background process, so nothing sends while you are away. That is a design property rather than a promise, and it is why there is no "automation" feature here.

What happens to my mail if you go out of business?

Nothing. Your mail is in your mailbox with your provider, where it has always been, and there is no copy of it anywhere else. Stopping using this changes nothing about your mail, which is the practical benefit of a connector that does not keep anything.

Attribution

Sources

Keep going

Read next

What an email MCP server is, and what one can actually do

The protocol in plain terms, the twenty-eight tools a mail server exposes, and the difference between an AI that can describe your inbox and one that can work it.

Remote and local MCP servers, and which one you need

One is a program your client launches, the other is a URL your client calls. The distinction decides your whole setup, and it is the thing most people get wrong first.

Folders, filing, and the mail an AI should not touch

What a move actually does to a message, why delete means Trash and not gone, how folder naming differs by host, and the categories worth keeping an AI away from entirely.

Start on a mailbox that does not matter.

That is the advice above and it is also the free tier: 5 calls a day, no card, on whichever mailbox you would mind least.