Gmail Data, Disconnect, and Deletion
How connected Gmail account access, disconnect, and deletion work in LeadStream.
Effective: August 12, 2026
Connected Gmail accounts
LeadStream users may connect personal Gmail accounts so they can view their own mailbox, send manual one-to-one emails and replies, update mailbox state, and link selected threads to leads.
A connected Gmail mailbox is private to the user who connected it. Other workspace users cannot browse that mailbox.
Lead-linked threads
When a user manually links a Gmail thread to a lead, the linked thread history is visible read-only to users who can view that lead.
Lead-linked viewers cannot send, reply, archive, trash, star, mark read or unread, or otherwise mutate the connected Gmail mailbox unless they are the Gmail account owner.
Disconnect Gmail
Disconnecting Gmail revokes Google access when Google accepts the revoke request, deletes stored OAuth token material, stops Gmail sync and watch renewal, and deletes unlinked private mailbox cache from LeadStream.
Users can also review and revoke LeadStream access from their Google Account security settings.
Delete Gmail data
Unlinked private mailbox cache is retained for a rolling 90 days while Gmail remains connected and is deleted immediately when the Gmail account is disconnected.
Google OAuth tokens are retained only while Gmail remains connected and are permanently deleted from LeadStream on disconnect. Attachment bytes are fetched on demand and are not stored by default.
Linked lead email snapshots remain CRM history after disconnect for as long as the linked snapshot remains in the workspace. The Gmail account owner can end this retention by unlinking the thread from the lead or deleting the linked snapshot.
Who receives Google data
Unlinked Gmail mailbox data is available only to the connected Gmail account owner. A linked thread is disclosed only to authenticated users in the same LeadStream workspace who are authorized to view the selected lead.
LeadStream infrastructure providers may process Google Workspace API data only as needed to host, store, secure, log, or monitor the service under contractual confidentiality and security obligations. LeadStream does not transfer Google Workspace API data to advertisers, data brokers, information resellers, or AI model providers.
Security audit records
LeadStream writes redacted append-only audit records for Gmail connect, disconnect, manual send, mailbox action, and lead-link actions so the service can support security review and incident investigation.
These audit records do not store Gmail subjects, bodies, recipients, attachment filenames, raw headers, OAuth tokens, token ciphertext, raw provider payloads, or authorization codes.
Redacted audit records are retained as security and compliance evidence even when Gmail is disconnected, because they document service actions without retaining Gmail message content.
Limited Use
LeadStream uses Google Workspace API data only for visible Gmail product features: private mailbox viewing, manual sending and replies, user-controlled lead linking, linked lead read-only history, mailbox actions, sync status, and attachment access requested by the user.
LeadStream does not sell Google Workspace API data, does not use it for advertising or retargeting, does not use it to determine creditworthiness or lending decisions, and does not use it to train generalized AI or machine learning models.