You're evaluating two risks.
Here's our answer to the second one.
The criminal in the inbox is one risk. Granting us access is the other — and you should judge it just as hard. This page shows exactly what we request, what those permissions can and cannot do, what we keep, when a human sees anything, and how to cut us off in one click.
Company identity.
Family Sentinel LLC, a Texas limited liability company, family-owned and run by a working Security Architect. Reach a person at security@familysentinel.org or (940) 281-6672 — calls are returned the same business day. Service health is monitored continuously, around the clock — and if an incident ever affects your monitoring, we tell you by email rather than expecting you to go and check a page.
What we request, what it allows, what it can never do.
These are the actual permission names from your provider's consent screen — not a summary. You will see them yourself, on your own screen, when you authorize.
| Permission | Why we need it | What it allows | What it does NOT allow |
|---|---|---|---|
| Read email gmail.readonly |
Analyze senders, links, attachments, and message content for malware, ransomware, phishing, impersonation, and malicious intent | Read messages and their technical headers | Send, delete, edit, forward, or reply to anything. Move a message. Touch a folder. |
| Read mail settings gmail.settings.basic |
Detect the fingerprints of a hijacked account — hidden auto-forwarding rules and filters that quietly delete bank & security alerts | View forwarding rules, filters, and aliases | Create, change, or delete any rule, filter, or setting. Being exact, because this row is the one place on this page where the honest answer is longer: Google does not publish a read-only version of this permission, so unlike the row above — where the restriction is enforced by Google and we could not send mail if we wanted to — this one is a restriction we impose on ourselves. We only ever read these settings. We would rather tell you which of these two kinds of promise you are getting. |
| Microsoft Mail.Read (Outlook inbox monitoring — rolling out; Microsoft 365 admin-console monitoring is available today via Org Guard) |
The same read-only analysis for Outlook & Hotmail inboxes | Read messages and headers | Send, delete, or modify anything. |
What we keep — and what we refuse to keep.
Ordinary mail: nothing
Messages that analyze as safe are not stored. Not archived, not indexed, not "retained for quality purposes." Analyzed and released.
Flagged threats: two clocks
The message itself is kept encrypted for 14 days — your proof if you need it for a bank or a police report — then destroyed. The verdict (who it was from, what it was, why we judged it) is kept as metadata for 13 months, so you have a record of what was caught. Both deletions run automatically on a timer, not when somebody remembers.
Never, under any plan
No selling data. No advertising built on your data — we buy ads to reach new families, and nothing from a customer’s account is ever used to target them or shared with an ad platform. No AI training on your mail — our AI provider processes under terms that exclude training. No sharing beyond the subprocessors that run the service.
Why you can hand us an inbox — without taking our word for anything.
You are about to give a small company access to your parent's email. That should feel like a big decision, and anyone who tells you it isn't is selling. So here is the argument, and note what it does not rest on: our good intentions.
- The permission we hold cannot do the thing you are afraid of. We ask for a read-only authorization. That is not a policy we adopted; it is a category of access Google and Microsoft enforce at their end. There is no setting we could flip, no employee who could be bribed, and no breach of our systems that would let anyone send mail as them, delete their mail, or read their password. We did not request that power, so we do not have it to lose.
- Nobody is sitting there reading it. The analysis is automatic and it happens in memory — the message is examined and released, not filed somewhere for later. There is no queue of reviewers browsing inboxes, because there is no queue and there are no reviewers. A person sees one specific message in exactly two situations: it was judged dangerous and a human is checking that judgement before your family is frightened, or you forwarded it to us yourself and asked.
- There is very little to leak, because we keep very little. A safe message leaves behind its provider ID and nothing else — no sender, no subject, no body — and even that is deleted. The only mail we store is mail we are warning you about, encrypted, for fourteen days. Every one of those deletions is an instruction that runs on a schedule and writes to an audit log. The strongest privacy guarantee available to any company is not encrypting data well. It is not having it.
- You hold the switch, and it is not on our side of the door. Access is granted at Google or Microsoft, and it is withdrawn there too — in under a minute, without asking us, without an email to a retention team, and whether or not this company still exists. If we ever behave badly, you do not have to negotiate with us. You just turn us off.
Three things we will never do
- Send, delete or change a single email. This is the one that matters most, and it is not a policy we could quietly change — the read-only scope above does not contain the ability to write. Google and Microsoft enforce it at the account level, not on our honor.
- Sell, share or train on anyone's mail. No advertising partners, no data brokers, no model training. Our AI provider operates under terms that forbid training on our data. The only people who ever see a flagged message are the ones protecting the person who received it.
- Use fear to sell. No countdown timers, no invented statistics, no scare calls. Our entire reference library is free and ungated, because a family that reads it and never buys a thing is still a family that got helped.
Ask our founder anything.
Questions this page didn't answer? Ask them before you connect anything — that's the right order. Our founder is a working Security Architect who answers every message personally, no sales team in between.
Ask the founder a questionCall or text (940) 281-6672 · security@familysentinel.org · Organizations can also book a free 20-minute checkup — it needs no inbox access.