Connector · Google Workspace

Gmail and Drive for your AI assistant, without handing it your inbox.

PrivacyFence connects an AI assistant to Gmail, Google Drive, Docs, Sheets, Calendar, Contacts, Tasks and Apps Script through one Google sign-in that stays with PrivacyFence. The assistant can search and list straight away. It sees an email, a document or an event's details only after you have looked at them, and nothing in your Google account changes until you approve it.

What the assistant can do

Six Google connectors, each tool with a fixed gate.

What runs straight away, what is reviewed before the result is released, and what needs your approval before it happens. The Tools reference lists every tool.

Gmail

Without a card
Searching messages and threads (subject, sender, date, snippet), labels, filters, and attachment names.
Reviewed before release
A message, a whole thread, or an attachment's content.
Needs your approval
Drafts and reply drafts, with or without attachments; adding and removing labels; archiving; creating and changing filters.

No tool sends an email: the assistant can only prepare drafts for you to send.

Drive, Docs and Sheets

Without a card
File search and metadata, folder listings, shared drives, a spreadsheet's tabs, and creating a new blank file or spreadsheet.
Reviewed before release
A file's content, a download, and spreadsheet cell values.
Needs your approval
Writing or editing a document, writing and formatting spreadsheet ranges, adding, renaming and resizing tabs, uploads, moves and comments.

Calendar

Without a card
Your calendars, event lists (title and time), colleagues' free/busy, meeting rooms, colours and an event's visibility.
Reviewed before release
An event's full details: attendees, description, conferencing links and attachments.
Needs your approval
Creating, changing and deleting events, out-of-office entries, working location, and an event's colour or visibility.

Contacts

Without a card
Listing, searching and reading contacts.
Needs your approval
Creating and changing contacts, and adding or removing labels. Out of the box, an edit that changes no email address or phone number runs without a card.

Tasks

Without a card
Task lists and the tasks in them.
Needs your approval
Creating and changing tasks, completing or reopening them, and moving them between lists.

Apps Script

Without a card
The list of your script projects.
Reviewed before release
A project's source, and the result of a run you started yourself.
Needs your approval
Writing new source to a project.

PrivacyFence never runs a script.

Personal data

Checked on your machine before a card is shown.

Before a reviewed read reaches its card, PrivacyFence scans the content locally for likely personal data in English, German and Hungarian: IBANs, card numbers, ID and tax numbers, salary information and similar. What it scans for each Google connector:

  • Gmail: the message body, every body in a thread. The From, To, Subject and Date headers are not scanned.
  • Drive: a document's text, all of what the assistant would receive (at most 100 KB), and the first 50 rows of a sheet read.
  • Calendar: the event description.
  • Attachments, downloads and uploads: the text PrivacyFence can extract, up to 20,000 characters. Files over 5 MB are not scanned, and images are not read.

A match sends the read to a card even when an always-allow rule covers it, highlights what was found, and asks for a second confirmation. The audit log records the category, never the matched text. Writes are not held by the check, except a Drive upload, which may be a file the assistant never read.

The privacy filter, separately, decides what may leave PrivacyFence at all. Out of the box it blocks Gmail attachments and the notes on contacts and tasks until you allow them in Settings → Privacy Filter.

How the PII check works →
PrivacyFence approval card for reading a Gmail thread: the requesting AI system marked Not verified, its stated reason, a possible-PII warning listing a personal data reference, an IBAN and salary information, the matches highlighted in the message text, and what will be provided to the AI system
Reading a Gmail thread: the PII check's findings are highlighted before anything is released. Example data only.

Changes

You see the change before it happens.

A write card names the file, its owner and exactly what will change. For a spreadsheet write it shows the values and formulas as a table, and says that every cell in the range is overwritten. Nothing is written to Google until you approve, and on a packaged install approving a write asks for your passkey.

A draft's card shows its recipients and text exactly as it will be saved, including your Gmail signature if you have turned that setting on. Sending stays with you, in Gmail.

A write, step by step →
PrivacyFence approval card for writing a spreadsheet range: the spreadsheet, its owner, the range and the effect of the write, the AI system's stated reason, an informational financial-figures note, and a preview table of the values to be written
A spreadsheet write, before anything is written. Example data only.

Routine requests

Let the routine run without a card.

An always-allow rule lets matching requests run without asking you, and each one is still audited. Rules are narrow on purpose. For Google, a rule can trust, for example:

Mail from a domain

Reading messages from your own company's sender domain, or messages carrying a label you choose.

A Drive folder

Reading or writing the files directly in one folder, files you own, or files PrivacyFence created in this session.

Your own events

Reading or changing events you organize, or anything on one calendar.

A task list

Changing and moving tasks within the lists you name.

Likely personal data in a read still goes to a card. Every scope and condition is in the scope catalogue.

Set it up

One Google Cloud app, then each person signs in.

  1. An administrator creates an OAuth client in a Google Cloud project once, enables the APIs of the connectors you want to offer, and packages the client into an organization config bundle. With a Workspace account, an Internal app needs no Google verification.
  2. Each person installs the bundle, then connects each Google connector from PrivacyFence's Settings page and signs in to Google in the browser.
  3. The connector's tools appear to the assistant. The Google sign-in stays with PrivacyFence and is never given to the AI client.

Set it up Connecting a service

Next

Try it with your own Google account.

Install PrivacyFence on macOS, Windows or Linux and approve your first Gmail read.