GmailVibe data and access
GmailVibe accesses your Gmail account only after Google consent. The gmail.modify permission allows searching and reading messages, preparing drafts, replying, sending, labeling, starring, marking importance, archiving, moving to Trash, and restoring. It does not allow immediate permanent deletion or changing Gmail settings. You can revoke access at any time.
Starting a conversation does not automatically send email bodies to the model. A voice-requested search sends result headers and short snippets to Gemini; a message body is sent only when opened to answer your request. GmailVibe shows the consulted message or action in a contextual preview. This data is used solely to provide the features you requested, never for advertising or sale.
Microphone audio is sent to a secure kayaXstudio relay, which forwards it to Gemini Live during the conversation. To read an action aloud, its recipient, subject, and proposed text may also be sent by the server to Gemini Text-to-Speech; if that service is unavailable, the browser's speech synthesis may read it instead. Captions remain in the tab's memory. kayaXstudio does not retain conversation audio or transcripts. Google processes data sent to Gemini under the terms applicable to the service used. Gemini API Terms.
At the end of a conversation, GmailVibe offers an optional feedback form. If you submit it, only your comment is sent to kayaXstudio through Brevo and kept in its mailbox. It is private by default. If you check the publishing permission, its text and chosen display name (or “Anonymous”) are also stored on the server and shown publicly in Labs. Earlier private feedback is not published. You can request removal at contact@kayaxstudio.com. No Gmail message, audio or caption is attached. The prompt appears after every conversation and does not use your IP address or browser storage to decide whether to appear.
To connect your account, the server stores your email address, granted permissions, an encrypted refresh token, and an HTTP-only session. The Google token is sent neither to the browser nor to Gemini. Action proposals are encrypted, bound to your account, and expire after ten minutes. Their outcome may be retained briefly to prevent duplicate sends. An uncertain network result is never retried automatically.
Before any change, the assistant reads back the details and asks for an explicit spoken confirmation phrase. An ambiguous answer or interruption triggers nothing. You can say “cancel”. Before sending an email or reply, the recipient, subject, and complete text are read back.
While public testing is paused, you can request disconnection and deletion of GmailVibe-related data at contact@kayaxstudio.com. Google's OAuth review remains necessary before public access resumes. contact@kayaxstudio.com.