Some Third-Party Email Apps Let Employees Read User Emails

Some third-party email providers that work with services like Gmail are letting their employees read customer emails to create new and optimized software tools, according to an article warning about third-party email apps and services published today by The Wall Street Journal.

Return Path, a service for email marketers that has 163 app partners, two years ago allowed its employees to read approximately 8,000 full customer emails to train the company's software.

Similarly, Edison Software, a company that makes the Edison Mail app for iOS, had employees read the emails of hundreds of users to craft a new "smart replies" feature.

According to The Wall Street Journal, neither company asked users for specific permission to read their emails, but have said the practice is covered in their user agreements. Employees who read the emails were governed by "strict protocols," and in Edison's case, user information was redacted.

Edison, Return Path, and other third-party email services also use computer scanning to analyze emails, a common practice. For its article, The Wall Street Journal interviewed over two dozen current and former employees from email and data companies.

Google no longer scans the inboxes of Gmail users itself as of last year for privacy reasons, but it continues to allow third-party software developers to do so. Other email services, like Yahoo and Microsoft, are similarly impacted, providing access with user consent.

Return Path, Edison, and other developers of apps that work with Gmail and similar email services don't appear to have misused customer information, but many customers are likely to be concerned about the fact that employees at some email companies are reading their emails. Many customers are also likely unaware they're consenting to such practices when signing up for a third-party email app.

In a written statement, Google said that it provides data to outside developers who have been vetted and who have been granted permission by users to access their email. Google says its own employees read emails only in "very specific cases where you ask us to and give consent, or where we need to for security purposes, such as investigating a bug or abuse."

As The Wall Street Journal points out, customers should be wary of email apps because Google does not have strong consumer protections in place when it comes to email. It's a simple process to build an app that connects to Gmail accounts, and with permission to access the Gmail inbox granted, a developer can see the entire contents of the inbox. It's not just large corporations that are able to get to this data - Google also gives permission to one-person startups, and data privacy protections can vary.

Customers concerned with how their emails are handled by third-party apps should stick with first-party apps such as Gmail or Inbox by Gmail for Gmail users and/or take a close look at the app's privacy policies and ask further questions about data usage.

Top Rated Comments

(View all)

18 months ago
This is why I switched back to Apple's own Mail application..
Rating: 37 Votes
18 months ago
This is real scary and completely irresponsible for Google to allow this.
Rating: 30 Votes
18 months ago
I'm honestly surprised this isn't exploited more. Consumers are dumb and will grant access to anything.
Rating: 23 Votes
18 months ago

Thanks for the article, Juli.

Welcome. I don't want to fear monger or defame good email apps who are using this data for legitimate feature purposes like Edison seems to be doing, but read privacy policies and approach all apps like this that potentially have access to swathes of data with caution. Ask questions. Demand answers.
Rating: 13 Votes
18 months ago
When I was a child I was taught the following:
"Things and services that are free, often come with the highest cost."
Rating: 12 Votes
18 months ago
This is WHY my primary email is on
Rating: 11 Votes
18 months ago
This is why I gave up on just about all third party clients. They all want to mine you to death.
Rating: 10 Votes
18 months ago
Ruh-roh! This is something that should be highlighted when a user registers. The classic response of “It’s in the user agreement” just comes across as tone deaf. I wonder how long before we get the usual, “We’re sorry we weren’t up-front about this. We promise to move in a new direction in the future and will always make you fully aware how we use your personal information.”
Rating: 7 Votes
18 months ago
Goodbye Edison! What a shame!
Rating: 7 Votes
18 months ago
Anything you send via email can be intercepted and read by people in the middle. Which app you use doesn't matter. Neither POP nor IMAP are particularly secure. SMTP security is laughable. Exchange might be, but if you're using Exchange, somebody is paying for it.
Rating: 7 Votes

[ Read All Comments ]