OAuth 2.0 Scopes
All scopes requested by ELLARI applications, with rationale for each permission and instructions to revoke access.
View scope documentation →Registered Applications
Every application operating under the ELLARI umbrella that uses external OAuth or API credentials.
View all applications →Data Use Policy
How ELLARI handles data obtained through third-party integrations: what is stored, for how long, and who has access.
Read data use policy →Developer Support
Technical questions, integration requests, access revocation, or data inquiries. Response within one business day.
Contact us →Privacy Policy
Full policy covering data collection, retention, sharing, and your rights under applicable privacy law.
Read privacy policy →Terms of Service
Terms governing access to ELLARI developer tools, APIs, and third-party integration infrastructure.
Read terms of service →ELLARI-MCP — Gmail Integration
The ELLARI-MCP application connects Gmail accounts to the ELLARI AI operations layer via the multi-gmail-mcp server. This enables Claude Desktop to read, search, and manage email on behalf of authorized internal operators. No end-user data is collected. All authentication is performed via Google OAuth 2.0 with tokens stored locally on the operator's device.
| Scope | Purpose | What we access |
|---|---|---|
| userinfo.email | Account identification | Identify which authorized operator account is active. No profile data beyond email address is accessed. |
| gmail.labels | Label taxonomy management | Create and manage deal-context label hierarchies (e.g. SIGWELL/Live Oak, INVOICES/Outstanding) for inbox organization. |
| gmail.send | Send email on behalf of the account | Send pre-reviewed outbound messages composed by the operator. No automated sends without explicit approval. |
| gmail.modify | Read, compose, label, and archive | Search and read messages; apply labels; archive resolved threads; mark messages read. Supersedes readonly and compose — no separate scopes needed. No deletion of emails. |
| gmail.metadata | Header-only triage | Scan inbox by subject, sender, and date without loading message bodies. Used for fast deal-correspondence triage and vendor invoice detection. |
| gmail.settings.basic | Filter and rule management | Create and manage Gmail filters that automatically route incoming deal correspondence to the correct label (e.g. from:liveoak.bank → SIGWELL/Live Oak). Provisioned on account setup; modifiable by the operator at any time. |
To revoke access at any time: visit myaccount.google.com/permissions, locate "ELLARI-MCP," and click Remove Access. All locally stored tokens are deleted upon revocation.
Active Integrations
The following applications are registered under the ELLARI Google Cloud project (ELLARI-MCP) and use OAuth 2.0 for authentication.
✓ What we do
- Store OAuth tokens locally on the operator's device only
- Use Gmail access exclusively for internal business operations
- Log all tool calls with timestamps for audit purposes
- Revoke access immediately upon request
- Encrypt credentials at rest using OS keychain
- Limit scope requests to the minimum required
✕ What we never do
- Sell, license, or transfer your data to third parties
- Use your email content to train AI models
- Send automated emails without explicit operator approval
- Retain email content beyond the active session
- Share credentials or tokens outside the local device
- Access accounts outside the authorized operator list
Developer Support & Data Inquiries
For technical questions, integration requests, data deletion, or access revocation, contact the ELLARI developer team. We respond to all inquiries within one business day.