Trust & data protection
What we can see, and what we can't.
Written in plain English, on purpose. If you were sent here because you asked a hard question about inbox access — good. Here are the actual answers.
You never have to connect your inbox at all.
StrideFollow works without any access to your email account. Connecting Gmail is one option, not a requirement, and plenty of our customers never do it.
Three ways a quote reaches us — you pick
1. CC or BCC us — zero access
You get a private address like yourbusiness@leads.stridefollow.com. CC or BCC it when you send a quote, and only that one email reaches us. We never touch your mailbox, never see anything else in it, and could not read another message if we wanted to. This is the most private option and it works with any email provider — Gmail, Outlook, Zoho, anything.
2. Type it in — zero access
Add the client, the amount, and the date by hand, or upload the quote file. No connection to anything. Some of our customers use only this.
3. Connect Gmail — read-only, sent mail only
The convenient option: we find quotes you already sent, so you do not have to remember anything. Exactly what this does and does not allow is spelled out below.
If you do connect Gmail, here is the literal search we run
Not a paraphrase. This is the query, copied out of our source code:
in:sent (quote OR estimate OR proposal OR invoice) newer_than:30dRead that in plain English, it means:
- in:sent — only mail you sent. Your inbox, meaning everything other people sent you, is never searched.
- quote OR estimate OR proposal OR invoice — only messages containing one of those four words.
- newer_than:30d — only the last 30 days. Your email history is not trawled.
Separately, when a quote is waiting on a reply, we check for messages from that one client's address so the follow-ups can stop. That is the only reason we ever look at incoming mail, and it is scoped to the specific person you already quoted.
The exact permissions we request
gmail.readonly— read-only. We cannot delete, modify, or archive anything in your account. This is the permission that lets us run the search above.gmail.send— lets a follow-up go out from your address so it lands in the client's existing thread instead of arriving from a stranger.openidandemail— so we know which Google account was connected.
That is the complete list. There is nothing else.
What we store, and what we don't
We store:
- The client's name and email address, the quote amount, and the date — the details you would write on a sticky note.
- A short snippet of the quote email, so you can recognise which deal a reminder refers to. This is the preview line Gmail itself shows in your message list, not the full email.
We never:
- Sell your data, or share it with data brokers or advertisers.
- Use anything in your email for advertising or ad targeting.
- Download or store full copies of your mailbox.
- Read messages that are not sent quotes or replies to them.
- Let a human browse your email. Nobody at StrideFollow reads your mail.
Nothing sends unless you asked for it
The fear we hear most is reasonable: that some bot misreads a thread, decides it is a quote, and fires a tone-deaf chase at an important client. Here is why that cannot happen, path by path.
- Gmail detection — we are guessing, so we treat it that way. Every detected quote lands in a review queue and sends nothing. It only becomes a real lead when you tap approve. If you ignore the queue forever, no email is ever sent.
- CC/BCC — you chose to CC that specific quote. That deliberate act, on that one email, is the approval.
- Typed in by hand — you entered it yourself.
After that, you stay in control: pause any lead, edit the wording, change the timing, or switch a lead to track-only so it is watched but never chased. And the moment a client replies, the sequence stops on its own.
The rules we are bound by
Gmail access is governed by Google's API Services User Data Policy, including its Limited Use requirements. Those rules explicitly prohibit transferring or selling user data to advertising platforms or data brokers, using it to serve ads, and letting staff read it outside narrow, defined circumstances. We follow them. They are not our promises — they are conditions Google enforces, and breaking them costs an app its access.
Under GDPR terms, your business is the data controller and StrideFollow is a data processor acting on your instructions. If your customer or your lawyer needs a data processing agreement, email us and you will get one.
Where we are with Google's verification
Being straight with you, because you will notice it yourself the moment you connect:
You will see a screen that says “Google hasn't verified this app.”
That is accurate. We are preparing our submission for Google's restricted-scope verification. Because gmail.readonly is a restricted scope, that process requires an independent security assessment by a Google-approved assessor, and it has to be renewed every year. It takes weeks, and we are early in it.
We would rather tell you here than let you hit that warning cold and wonder what we were hiding. If you would prefer to wait until it is finished, use the CC/BCC address in the meantime — it needs no Google permission at all, and you can switch on Gmail later.
Turning it off
Go to Settings and click Disconnect Gmail. We immediately revoke the token with Google and delete the stored connection, including the access and refresh tokens and any detections still sitting in your review queue. You can also revoke us yourself at any time from your Google account permissions page, without asking us first. If you delete your StrideFollow account, your leads and quote data go with it.
Still have a question?
Ask it. If the honest answer is “we have not built that yet” or “we cannot do that,” that is the answer you will get. Email support@stridefollow.com.
See also our Privacy Policy and Terms of Service.