Skip to main content

Google tells lawmakers it allows other apps access to your Gmail

how to change your gmail picture
Aleksey Boldin/123rf

Even though Google has ceased the practice of scanning user’s Gmail accounts to serve ads, the search giant admitted in a letter to lawmakers that — with user consent — it still allows third-party apps access to your messages. Google’s letter will likely set the tone for what lawmakers will discuss at a congressional hearing scheduled for September 26 on digital privacy with technology companies, including Amazon, Apple, AT&T, Charter Communications, Google, and Twitter.

Google defended its policy in the letter, stating that it makes its privacy policy easily accessible to users to review before granting access to third-party developers, and that developers may also share the data gleaned from emails obtained from Gmail users with other service providers. “Developers may share data with third parties so long as they are transparent with the users about how they are using the data,” Google Vice President of Public Policy and Government Affairs for the Americas Susan Molinari wrote in the letter that was sent in July to lawmakers and obtained by CNNMoney.

Recommended Videos

Before any non-Google app can access your data, Google will display a permissions screen to show what data the app is requesting and how the app intends on using such data. “We strongly encourage you to review the permissions screen before granting access to any non-Google application,” Google wrote in a blog post. Business users on G Suite can also control how their data is accessed by non-Google services through whitelisting. The company claims to have a vetting process in place, and that apps that misrepresent themselves to obtain data will have their access revoked.

Typically, the types of apps that request permission to access your email include trip planners, customer relationship manager software, and shopping and discount apps. A trip planner app, for example, can scan your email to pull and compile all your travel information, reservations, and itineraries in one place, so you don’t have to manage your hotel, airline, and other reservations manually. Shopping apps, like Earny, can also scan your emails for online orders. If the service detects a price drop, it will request a refund for the price difference less a commission fee. While Earny and travel apps are useful tools that save consumers a lot of time — and money — lawmakers may be concerned that malicious apps may abuse the system to access personal and sensitive information from Gmail users. Given that there are more than 1.4 billion Gmail users worldwide, that is a lot of data that could fall into the wrong hands.

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
You can now live your developer dream with Google’s free Gemini Code Assist access
Google gemini code assist graphic.

Google has made a free version of its Gemini Code Assist tool available worldwide starting February 25. The generative AI model, previously aimed at businesses, is powered by Gemini 2.0 and integrates with IDEs like Visual Studio Code.

This means you can access Code Assist's features directly from the environment you're working in. It will auto-complete code as you're typing it, and you can also work through problems in the chat or generate code snippets.

Read more
Google will replace unsafe Gmail SMS codes with QR scan verification
Receiving two-step security code via SMS.

Ever since Google enabled two-step verification for Gmail and other tied authentication protocols in its ecosystem, SMS codes have been a mainstay. But according to security analyses, SMS codes are notoriously unsafe, especially when the communication channel is not encrypted. That is finally about to change, as SMS codes will soon be replaced with QR codes for Gmail authentication.

When it comes to account security, SMS is not the most reliable choice for receiving sensitive verification codes, or one-time passwords (OTP) on phones. That is why, over the past few years, Google has steadily developed password alternatives such as on-device Google prompts, authenticator apps, hardware security keys, and the Passkey system to minimize the risks such as SMS phishing.

Read more
Google’s AI can now tell you what to do with your life
Career dreamer results

Got a degree and no idea what to do with it? Google's newest AI feature can help. The company announced on Wednesday the release of Career Dreamer, an AI tool that can recommend careers that best suit you based on your experience, education, skills, and interests.

Grow with Google | Career Dreamer

Read more