Permissions
Last updated 1 September 2026
Core5 asks for a permission only when a feature you can see depends on it, and this page says which feature. If a line here does not justify itself, the permission should not exist.
Core5 asks for these when you connect a Google account. You can connect several, and each one chooses which modules it feeds — a work account that only fills the calendar never has its mail read.
| Permission | What it allows | Why Core5 needs it |
|---|---|---|
Google Calendarcalendar | Read and write your events | Drawing your week, and letting you create, move, delete and colour events from Core5. Without writing, the calendar would be a picture of your diary rather than your diary. |
Gmailgmail.modify | Read, send, and change labels | Showing your inbox, sending your replies, and archiving, flagging or marking read — which in Gmail's model are label changes. Core5 never deletes permanently: it moves to your bin, where you have thirty days to change your mind. |
Google Taskstasks | Read and write your tasks | Two-way sync, so a task you tick on your phone is ticked here and the other way round. |
Your Google profileuserinfo.profile · email | Your name and email address | Naming the account in the app and labelling which of your addresses a message arrived at. It is also how Core5 shows your own name correctly instead of guessing it from your address. |
The keys stay on your device. Your Google tokens are held in the system keychain on your own Apple devices — synced between them through your iCloud Keychain if you use it, and never sent to our servers. Your mail and calendar travel between your device and Google directly. They are not copied to us, which is why we could not read them even if we wanted to.
Core5's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Taking it back
Disconnect the account in Settings → Account, and the tokens are destroyed on the spot. You can also revoke Core5 from Google's own side at myaccount.google.com/permissions.
The optional connections
None of these are needed to use Core5, and none are on unless you turn them on.
Slack
Send a task or a summary to a channel, and turn any Slack message into a Core5 task with a right-click. Core5 reads nothing else in your workspace.
Notion
File work into a Notion page or database when a rule you wrote says so.
HubSpot
Read contacts, companies and deals so an open email can tell you who is writing to you. Read-only.
Claude
Connect Core5 as an MCP connector and ask Claude about your own work. It sees exactly what you see — the request carries your session, and the database applies your permissions, not ours.
Why these three keep their tokens on the server, and Google does not. Slack, Notion and HubSpot act while the app is closed — a rule that files a task has to run whether or not your Mac is awake. So their tokens are stored encrypted on our servers. Google's are not, because Google is read on your device and its key opens your entire mailbox. They are different risks, so they get different answers.
What Core5 never asks for
- Your contacts. The addresses Core5 suggests are learned from your own mail, on your device.
- Your location, except the place you type into an event yourself.
- Your camera, microphone or photos, unless you attach a file.
- Anything at all for advertising or analytics. There is none of either.