Security

Is it safe to give AI access to your email?

It can be, if the connection limits what the AI can do. Through Mailopoly, an assistant or agent gets OAuth-scoped access where reading, making changes and sending are separate permissions, every tool call is audit-logged against your account, your mailbox password is never typed into a chat, and you can revoke the assistant at any time from Settings → Security. Start with reading only; add sending when you want it. Nothing makes an AI incapable of mistakes. What you can control is how far a mistake can reach, and whether you can see it afterwards.

Start a free trial

7-day free trial, no credit card.

Can AI read your email at all?

Yes. Claude, ChatGPT and most assistants can read, search and reply to your email once you connect it. Claude’s own connectors cover Gmail and Microsoft 365 work or school accounts; ChatGPT’s cover Gmail and Outlook on its paid plans; Grok Bot ships a Gmail plugin. Each of those reaches one account at a time, raw, and none of them covers Yahoo, iCloud or an IMAP mailbox.

Mailopoly is the other route: one connection that gives any assistant or agent every account you own — Gmail, Outlook, Yahoo, iCloud, IMAP — and, if you add them, your Slack, Teams, WhatsApp Business, Instagram, Messenger, TikTok and X, already sorted by Cleanbox and summarised, with invoices, events and deliveries extracted. The rest of this page is about doing that safely.

What the sceptics get right

  • A bot that logs in as you is a liability. Scripts that sign in to Gmail with your password from a machine you don’t control are what get accounts flagged and locked, and they hold a credential that can be stolen.
  • Scopes are usually too broad. Many integrations ask for full mailbox access, including sending, when the job was reading. Whatever goes wrong then goes wrong with full power.
  • Prompt injection is real. An email can contain text written to steer an AI that reads it. An assistant with the power to send or delete can be steered into doing so.
  • Training is a fair worry. People do not want their correspondence feeding a model.

What Mailopoly does about each

  • No bot logs in to your provider. Your Gmail and Outlook connect to Mailopoly through Google’s and Microsoft’s own sign-in (Mailopoly is a Google-verified OAuth provider; Microsoft verification is in progress). Yahoo, iCloud, AOL and IMAP mailboxes use an app password you enter on Mailopoly’s own page, never in a chat. The assistant connects to Mailopoly, not to your mailbox, and never holds a password.
  • Scopes are separate and yours to choose. Reading, making changes and sending are three grants. Tick reading only and the assistant can search and summarise but cannot touch anything. Add making changes for drafts, labels, tasks and reminders. Add sending only if you want it to send — and sending is flagged as a confirm-first action in the protocol itself, so a well-behaved client asks before it does.
  • Every call is logged. Each tool call an assistant makes is recorded against your account — what was asked, by which connection, when — so there is always a record, and several assistants can work the same inbox with their actions kept apart.
  • Revoke in a tap. Settings → Security → Connected AI assistants lists every connection and its permissions. Revoke one and its access ends immediately.
  • Prompt injection, honestly. Mailopoly hands the assistant your mail as data. Whether the assistant follows instructions hidden inside an email is down to that assistant’s own guardrails. The protection you control is scope: an assistant that can only read cannot be steered into sending, and one whose sends need confirmation cannot send behind your back.
  • Your mail is not training data. Mailopoly uses your email only to deliver its features, never sells it, and never uses it to train general AI models. The AI providers Mailopoly uses to summarise and sort run under commercial data agreements that exclude training. That is Mailopoly’s commitment; what a separate assistant does with the answers it receives is governed by that assistant’s own policy.

Start read-only

The sceptics’ advice is good: give an AI the least it needs, then widen it. When you connect an assistant to Mailopoly, the permissions screen shows three boxes. Tick reading and nothing else. Use it for a week: search, summaries, “what needs me today”. If you want it to draft, add making changes; drafts go to Mailopoly for you to review and send yourself. Only add sending when you have decided you want it, and consider giving the assistant one of your @mly.life addresses to send from, so nothing goes out under your main address unless you say so.

Before you connect any AI to your email

  • It connects with a sign-in you can revoke, not a password you hand over.
  • Reading, changing and sending are separate permissions, and you can grant only the first.
  • There is a log of what the AI did, that you can read.
  • You can see every connected AI in one place and cut any of them off.
  • The provider says, in writing, what it does with your mail and whether it trains on it.
  • Sending needs confirmation, or at least can be left off.

Mailopoly meets all six, and is independently security-assessed to CASA Tier 2 by TAC Security, with data encrypted in transit and at rest on AWS infrastructure. The full picture is on the security page.

Related: Security at Mailopoly · Connect Claude, ChatGPT or any assistant · Email for AI agents · Set-up guides for every provider

Start a free trial

7-day free trial, no credit card. Connect read-only first; widen it when you want to.

Frequently asked questions

letter

Take back your inbox. Take back your time

Try Mailopoly free and feel more organised by tomorrow. Connect your inbox in 60 seconds

Get Started for Free