Family Sentinel
Trust & permissions

You're evaluating two risks.
Here's our answer to the second one.

The criminal in the inbox is one risk. Granting us access is the other — and you should judge it just as hard. This page shows exactly what we request, what those permissions can and cannot do, what we keep, when a human sees anything, and how to cut us off in one click.

Who you're dealing with

Company identity.

Family Sentinel LLC, a Texas limited liability company, family-owned and run by a working Security Architect. Reach a person at security@familysentinel.org or (940) 281-6672 — calls are returned the same business day. Service health is monitored continuously, around the clock — and if an incident ever affects your monitoring, we tell you by email rather than expecting you to go and check a page.

The exact permissions

What we request, what it allows, what it can never do.

These are the actual permission names from your provider's consent screen — not a summary. You will see them yourself, on your own screen, when you authorize.

PermissionWhy we need itWhat it allowsWhat it does NOT allow
Read email
gmail.readonly
Analyze senders, links, attachments, and message content for malware, ransomware, phishing, impersonation, and malicious intent Read messages and their technical headers Send, delete, edit, forward, or reply to anything. Move a message. Touch a folder.
Read mail settings
gmail.settings.basic
Detect the fingerprints of a hijacked account — hidden auto-forwarding rules and filters that quietly delete bank & security alerts View forwarding rules, filters, and aliases Create, change, or delete any rule, filter, or setting. Being exact, because this row is the one place on this page where the honest answer is longer: Google does not publish a read-only version of this permission, so unlike the row above — where the restriction is enforced by Google and we could not send mail if we wanted to — this one is a restriction we impose on ourselves. We only ever read these settings. We would rather tell you which of these two kinds of promise you are getting.
Microsoft Mail.Read
(Outlook inbox monitoring — rolling out; Microsoft 365 admin-console monitoring is available today via Org Guard)
The same read-only analysis for Outlook & Hotmail inboxes Read messages and headers Send, delete, or modify anything.
What we never have: your password. Authorization happens on Google's or Microsoft's own pages — credentials go to them, never to us. We receive a revocable token, and revoking it (below) shuts us out instantly.
Data handling

What we keep — and what we refuse to keep.

Ordinary mail: nothing

Messages that analyze as safe are not stored. Not archived, not indexed, not "retained for quality purposes." Analyzed and released.

Flagged threats: two clocks

The message itself is kept encrypted for 14 days — your proof if you need it for a bank or a police report — then destroyed. The verdict (who it was from, what it was, why we judged it) is kept as metadata for 13 months, so you have a record of what was caught. Both deletions run automatically on a timer, not when somebody remembers.

Never, under any plan

No selling data. No advertising. No AI training on your mail — our AI provider processes under terms that exclude training. No sharing beyond the subprocessors that run the service.

The honest answer

Why you can hand us an inbox — without taking our word for anything.

You are about to give a small company access to your parent's email. That should feel like a big decision, and anyone who tells you it isn't is selling. So here is the argument, and note what it does not rest on: our good intentions.

  • The permission we hold cannot do the thing you are afraid of. We ask for a read-only authorization. That is not a policy we adopted; it is a category of access Google and Microsoft enforce at their end. There is no setting we could flip, no employee who could be bribed, and no breach of our systems that would let anyone send mail as them, delete their mail, or read their password. We did not request that power, so we do not have it to lose.
  • Nobody is sitting there reading it. The analysis is automatic and it happens in memory — the message is examined and released, not filed somewhere for later. There is no queue of reviewers browsing inboxes, because there is no queue and there are no reviewers. A person sees one specific message in exactly two situations: it was judged dangerous and a human is checking that judgement before your family is frightened, or you forwarded it to us yourself and asked.
  • There is very little to leak, because we keep very little. A safe message leaves behind its provider ID and nothing else — no sender, no subject, no body — and even that is deleted. The only mail we store is mail we are warning you about, encrypted, for fourteen days. Every one of those deletions is an instruction that runs on a schedule and writes to an audit log. The strongest privacy guarantee available to any company is not encrypting data well. It is not having it.
  • You hold the switch, and it is not on our side of the door. Access is granted at Google or Microsoft, and it is withdrawn there too — in under a minute, without asking us, without an email to a retention team, and whether or not this company still exists. If we ever behave badly, you do not have to negotiate with us. You just turn us off.
And the one claim we will not make. Plenty of security companies say some version of “we can't see your data.” We can. Reading the message is the service — software that cannot read an email cannot tell you that it is a scam, and any company claiming both is telling you one of the two things it thinks you want to hear. What is true is narrower and it is the part that actually protects you: the reading is done by software, in memory, and thrown away; no person sees your mail unless we are warning you about it; and we cannot alter, delete, or send anything at all. If a vendor ever tells you they read your mail for threats and also cannot see it, that is the moment to ask a second question.
When does a human see anything? Automated analysis handles the reading. A real Security Architect looks at a specific message in exactly two cases: a serious threat is being verified before your family is alerted, or you forwarded it to us yourself (Ask Sentinel). Access is purposeful and logged — never browsing.
Always in your control. You can disconnect us anytime in one click from your Google account's connections page (or just ask us and we'll disconnect, delete your data, and confirm in writing) — our access ends instantly. Found a security issue? Email security@familysentinel.org with "vulnerability" in the subject for a fast human response. And one honest note: no security system catches every threat, so an alert is never a substitute for verifying a request for money or personal information through a channel you already trust.
Stated as refusals, not promises

Three things we will never do

Ask our founder anything.

Questions this page didn't answer? Ask them before you connect anything — that's the right order. Our founder is a working Security Architect who answers every message personally, no sales team in between.

Ask the founder a question

Call or text (940) 281-6672 · security@familysentinel.org · A free 20-minute checkup is available too, and needs no inbox access.