Security
Your email stays private.
MailSignatures.io only accesses the information needed to create and manage your team’s Gmail signatures. We can’t read or send email.
No email access
We cannot read, search or process message content.
Signature settings only
We can update the signature field—nothing inside your inbox.
No employee installation
One Workspace admin connects the account. Employees install nothing.
You remain in control
Disconnect anytime and remove your stored workspace data.
Reviewed for Google Workspace security
Before Google will grant the Gmail settings access we need, an independent, non-Google assessor has to sign off. MailSignatures.io has completed a CASA Tier 2 security assessment, carried out by TAC Security under the App Defense Alliance framework. Our Letter of Validation was issued in 2026, and we revalidate every year to keep that access — if it lapses, Google can revoke it.
How access works
- One Workspace admin signs in with Google and approves access once, on Google’s own consent screen.
- We use that access to pull in your team directory and to read and write the signature field in Gmail settings — nothing else.
- Employees don’t sign in, install anything, or grant any access themselves.
Want the exact permission names Google shows on the consent screen? See Technical details.
What we store
Nothing beyond what the product needs to run:
- Your team directory (name, email, title, phone, photo), pulled in once you connect.
- Signature designs and any per-person overrides you set up.
- The Google OAuth tokens we need to actually write signatures into Gmail.
- Billing details — handled by Stripe directly. We never see or store card numbers.
Full breakdown in the Privacy Policy.
What happens when you disconnect
We revoke our Google access right away and delete your directory data, signature designs, and OAuth tokens from our systems.
Signatures already written to Gmail aren’t touched. They stay exactly as they are, same as any other Gmail setting, until someone in your workspace changes them again.
Technical details
For IT and security reviewers — the exact scopes, encryption model, and infrastructure providers behind the summary above.
Exact permissions requested
This is what shows up on Google’s own consent screen when you connect — not our summary of it, the real thing.
Directory user data, read only (admin.directory.user.readonly)
Google describes this as “See info about users on your domain.”
Used to build your team list: names, titles, email addresses and photos.
Gmail settings (gmail.settings.basic)
Google describes this as “See, edit, create, or change your email settings and filters in Gmail.”
We use it only to read and write the signature field on each mailbox.
Basic account identity (openid, email, profile)
To identify the admin who connects.
We do not request:
- No scope for reading message content.
- No scope for sending email.
- No email routed or processed through MailSignatures.io.
- No browser extension, and nothing installed on employee devices.
Encryption & token handling
Everything moving to and from MailSignatures.io is encrypted in transit (HTTPS/TLS).
Your Google OAuth tokens are encrypted at rest with AES-256-GCM, and only get decrypted in memory, for as long as a single request needs them.
Trusted infrastructure
We rely on established providers for hosting and the database (Vercel, Neon Postgres), payments (Stripe), transactional email (Resend), and uploaded logos and photos (Vercel Blob). That’s the whole list — analytics tools are called out separately in the Privacy Policy.
None of these providers can read your Gmail content, because we can’t either — we never asked for that access.
Report a security issue
Found something that looks like a problem? Email support@mailsignatures.io and a real person will read it.