← Help

Communications

Connect a primary Gmail or Outlook inbox

Product documentation · Reviewed

Inbox → Inbox connections lets the workspace owner connect a primary Gmail or Outlook mailbox. Only full-access business operators can read copied mail. Couples, guests, shared-wedding participants and limited collaborators do not receive access to this private inbox.

Connection setup remains part of coordinated launch activation. The development adapters and tests do not authorize provider accounts or send real messages.

Choose the boundary before copying email

Connect the original primary mailbox and review its email address. Choose up to ten labels or folders, the earliest message date in UTC, and whether synchronization should run. Mail from other labels or folders is not copied. Drafts, trash and spam are not offered as import destinations.

Google and Microsoft grant mailbox-level API permissions; the selected labels, folders and dates are additional application boundaries. Google uses read-only access plus sending. Microsoft requires mail read/write permission to create the specific drafts you approve; this integration does not edit or move your existing mail.

Enable sending separately. Connecting a mailbox does not replace studio email, your workspace contact address, consultation confirmations, workflow messages, scheduled follow-up sequences or gallery campaigns. Those retain their existing studio email route. Delegated Gmail aliases, shared Exchange mailboxes, multi-recipient composing and provider-wide mailbox organization are outside this connection.

The worker copies one page at a time with its saved cursor. Check selected folders now advances the selected folders by one page; a long initial history continues on later worker runs. Each account shows its last synchronization time and folder errors. Expired Gmail history or Outlook delta cursors restart the selected folder scan without duplicating saved messages. Invalid or unsupported provider messages can hold a page for review; an error is shown rather than silently declaring that page complete.

Outlook date checks happen on message metadata before older message bodies are fetched. This avoids the provider’s 5,000-message limit for filtered delta queries. Pagination uses immutable message IDs and a validated continuation for the same folder.

Keep the original business history

Open Private inbox to read messages as plain text. Remote HTML, images, scripts and tracking pixels do not execute. The imported From address identifies what the mailbox reported; it does not independently authenticate the person. Verify unexpected requests for payments, documents or account changes in the original provider.

A copied message keeps its original content. Later provider edits are flagged; they do not silently rewrite the record. Messages removed at the provider, messages outside a subsequently narrowed boundary, and messages from a disconnected account remain in the private business history. Disconnecting does not delete those copies.

Use Link to a private conversation to select and review an existing lead whose email is a thread participant. Importing mail does not automatically create, merge or adopt clients. After linking, messages matching that lead’s current email appear in its conversation. Other participants’ messages stay in the inbox thread. A thread cannot be silently moved to another client, and reviewed outgoing messages retain their original conversation.

New linked inbound replies reopen the conversation and stop active follow-ups for review. Older imported replies do not cancel a follow-up approved after those messages arrived. Stopping a follow-up is a conservative response to mail arriving, not proof of sender authentication.

Keep mailbox history out of AI sources

Conversations containing linked Gmail or Outlook messages are held from assistant source retrieval while provider-policy and data-sharing review is pending. The assistant source picker shows which connected provider was found where available. The server also enforces the hold before reserving model usage or sending a request, including for API callers and mail received after a source was selected. Disconnecting does not turn copied mailbox content into ordinary studio data.

This restriction covers both imported messages and messages sent through a connected mailbox. You can still read them in the private inbox. Do not paste the content into another AI input to bypass the hold. Any future support needs specific source disclosure, explicit sharing approval and reviewed provider data handling before activation.

Review a message from the connected sender

Open the linked conversation. In Send from, deliberately select the connected primary email; the default remains studio email. Choose New message or an explicitly linked reply context, then review the recipient, subject, body and files. Gmail replies must keep the original subject. Only the selected lead receives the composed message; there are no hidden recipients or automatic reply-all actions.

Approving creates a durable outbox record with the exact account generation, sender, recipient and content. A future send time uses your device’s timezone. If the lead’s email, mailbox connection, operator’s permission, approved files or conversation pause state changes before delivery, sending is held. A request interrupted while saving can be checked again with the same reviewed contents.

Gmail sends a MIME message with a unique saved marker and message ID. Outlook first creates an app-authored MIME draft, verifies its recipient, content and file fingerprints, then sends that same immutable draft. Editing the draft in Outlook makes the app hold it for review. The integration never deletes a provider draft automatically.

Sent means the provider’s sent copy matches the approved message. It does not mean the recipient received or opened it. Microsoft’s send acknowledgement alone is not treated as sent. Bounces and delivery receipts from these mailbox providers are not automatically interpreted as trusted delivery events in this release.

Recover an interrupted provider request

If a send or draft request may have succeeded but its response is lost, the outbox shows UNCERTAIN. Use Check original mailbox status to look for the saved marker and verify the original copy. The worker also checks again while that connection remains active.

A matching Sent Items copy resolves the original record without a second send. A known Outlook draft can continue only if sending was never attempted and its reviewed content still matches. If a send was already attempted, a remaining draft or missing copy stays held; the app does not infer failure and resend.

After disconnecting or replacing authorization, inspect unresolved attempts in the original mailbox. Reconnecting does not transfer old send approval to the new account generation. Messages already accepted by the provider cannot be recalled by pausing or disconnecting locally.

Save private attachments

Use Save private attachment to copy a PDF, JPG, PNG, WebP, text or CSV file up to 10 MB into workspace-private storage. Repeated saves recover the same stored artifact. Provider file IDs, declared size and original metadata are checked; attachment changes during a save prevent linking the file to a different message description.

Downloads use short-lived private links. Composing supports up to ten files and 10 MB total for Gmail; Outlook’s current draft flow caps the total at 2 MB. Unsupported formats or larger files remain in the original mailbox. This flow does not claim malware scanning or end-to-end email encryption.

Disconnect and activate deliberately

Disconnecting stops new synchronization and new sends and removes usable local access credentials. Google revocation is attempted and a failed revocation remains visible for retry. Use a dedicated inbox OAuth client so revoking its Google grant does not affect a separate Calendar integration.

Microsoft disconnect clears local credentials. To revoke the provider grant as well, remove the application permission from the Microsoft account or organization settings; the local disconnect screen says so explicitly. Imported private history remains available to authorized operators.

Before launch, rehearse OAuth state binding, consent scopes, encrypted refresh rotation, selected-folder/date boundaries, real MIME response shapes, attachments, sent-copy recovery after dropped responses, revocation, and connection changes during work in approved sandbox accounts. Verify Google restricted-scope requirements and Microsoft tenant consent policies. Enable the provider flags only in the coordinated activation phase.

Implementation references: Gmail synchronization, Outlook immutable identifiers, Microsoft folder delta queries, Create a Graph message, and Send a Graph message.

Email open signals

When the configured studio email provider reports an open event, private web and native conversations can show Provider open signal · readership unverified. Image blocking can hide a real open, and privacy services or security scanners can trigger a signal automatically. It is separate from delivery and from a client reply; it never changes a booking, approval, payment or automated follow-up.

Only signed, matching provider events are accepted, and repeat callbacks retain one first observation. Gmail and Outlook synchronization do not infer this studio-email signal. Provider tracking is optional and configured during coordinated activation; no provider setting or previously approved email is changed automatically.