Security and your data
What access Submole asks for, what it stores, what it never touches, and how to disconnect your mailbox at any time.
The access we ask for
Submole requests read only access to Gmail. Read only means exactly that: the connection cannot send, delete, label or modify anything in your mailbox. You grant it on Google's own permission screen and you can revoke it from your Google account or from the Submole dashboard whenever you like.
What we store
- The vendor name, category and the amount exactly as printed on the invoice
- The currency and billing period stated on the invoice
- The seat count where the invoice states one
- The charge date, so renewals can be predicted
- The subject line and sender of the source email, so you can verify any figure
What we never do
- We never store the body of your emails
- We never read messages that are not billing related
- We never send email from your account, and we cannot
- We never sell, share or rent your data to anyone
- We never ask for your Google password. Access is granted on Google's own screen
How it is protected
- Connection credentials are stored encrypted, never in plain text.
- Your account data is isolated at the database level, so one account can never read another's rows.
- All traffic is served over HTTPS.
- Payments are handled by our payment provider. We never see or store card details.
Disconnecting and deletion
The Disconnect button on your dashboard ends mailbox access immediately. If you want your account and everything in it deleted, write to support@submole.com and we will remove it. See the privacy policy and terms for the full detail.
Connect it, look at the numbers, disconnect if you want
Read only access, revocable in one click, and a seven day trial that never asks for a card.
Start 7 day free trial