For school IT teams
Gloss is a planner app for university students. A student signs in with their school Google or Microsoft account so Gloss can find deadlines and schedule changes in their email. This page has what you need to decide whether to allow it.
Gloss is published by Standby Ops LLC (District of Columbia). It is not affiliated with any university. Questions: support@joingloss.app. Security reports: security@joingloss.app.
What Gloss accesses
- Read only access to the student's own mailbox, granted by the student signing in on Google's or Microsoft's own page. Gloss never sees or stores the password.
- No write access. Gloss cannot send, delete, move, label or change email. It requests no calendar, contacts, files or directory permissions.
- No forwarding. Gloss never asks students to set up forwarding rules, and there is no forwarding option in the product.
- Only the student who signed in. Gloss never asks for admin or organization wide data access to read mail.
Exact scopes
| Provider | Scope | Why |
|---|---|---|
https://www.googleapis.com/auth/gmail.readonly | Read messages to find deadlines, exam changes and events | |
openid, email | Know which school address was connected | |
| Microsoft Graph | Mail.Read (delegated) | Read messages to find deadlines, exam changes and events |
| Microsoft | offline_access, openid, email | Keep syncing without asking the student to sign in every hour; know which address was connected |
Sign in to the Gloss account itself (Sign in with Apple, Google sign in, or an email code) is separate and asks only for basic profile information. Google's review of Gloss's Gmail access, including the independent CASA security assessment, is in progress; until it passes, Gmail connections are limited to 100 students in total.
How Gloss handles the data
- Rules sort mail first. Newsletters, promotions and automated mail are not sent to AI.
- Mail that matches sensitive words or senders (health, counseling, disability, Title IX, conduct, financial aid, visa office) is set aside before AI and is never sent to AI. The match is by keywords, so it can miss a message. It never appears in notifications, on the lock screen, in widgets, in calendar export or in the AI app connector.
- Other mail (sender, subject, sent time and up to 6,000 characters of the body) is read by Anthropic's Claude. The app asks the student's permission on a screen that names Anthropic before it connects their email, and the server checks that permission before any message goes to AI. The student can turn AI reading off at any time in Settings; it stops at once. Anthropic's commercial terms bar it from training models on Gloss data. Email text is treated as data, never as instructions, and the output must fit a strict format.
- Only the inbox is read. Attachments and To and Cc lists are not stored. The subject and body of each message are deleted 30 days after Gloss fetched it; the sender, dates, a link to open it and a one line summary stay until the student disconnects or deletes their account. Disconnecting also deletes the deadlines and events found only in that mailbox.
- OAuth tokens and stored email subjects and bodies are encrypted (AES-256-GCM) with a key unique to each student, held outside the database; deleting the account destroys it. Calendar feed links are encrypted with a separate key, also held outside the database.
- Each student's data is isolated by row level security in the database, with automated tests on every change that try to read another student's data and must fail.
- Email text is not written to logs. Error reports from the iPhone app, the desktop app and the servers, and server logs, are scrubbed of email content, addresses, tokens and links. No one at Gloss reads a student's email unless that student asks about a specific item.
- Disconnecting in Gloss stops reading at once and deletes the stored tokens and email; for Google it also stops the Gmail watch and revokes the token at Google, and for Microsoft it deletes the Graph subscription. Deleting the account does the same before the student's key is destroyed. You can revoke Gloss centrally at any time (below).
- No ads, no data sales, no trackers. Email data is used only to show the student their own deadlines.
Full details: privacy policy (draft for legal review), vendors that receive student data, security.
Google Workspace: approve or block Gloss
In the Google Admin console, go to Security, then Access and data control, then API controls, then Manage App Access (older consoles say Manage Third-Party App Access).
- Under Configured apps, click Configure new app and search for Gloss or for Gloss's OAuth client ID (listed below once Google's review is complete).
- Pick the organizational units it applies to.
- Choose the access level:
- Specific Google data with
gmail.readonlyplus the sign in scopes (openid,email): allows exactly what Gloss needs. Recommended. - Trusted: allows Gloss, including restricted services.
- Blocked: Gloss can't access any Google data for those users.
- Specific Google data with
If your domain uses Don't allow users to access any third-party apps for unconfigured apps, or marks Gmail as a restricted service, students see "Your school needs to approve Gloss" until Gloss is configured as above. Workspace for Education domains can set different rules for users designated under 18. Google's guide: Control which apps access Google Workspace data.
Microsoft Entra: approve or block Gloss
Many tenants, including every tenant on Microsoft's managed default consent settings, don't let students consent to Mail.Read themselves. Those students see a request for admin approval. To approve Gloss for your tenant:
- Open the admin consent link below as a Privileged Role Administrator, Cloud Application Administrator or Application Administrator, or approve the student's request in Enterprise applications, then Admin consent requests.
- Review the permissions (
Mail.Read,offline_access,openid,email) and accept for your organization. - Optional: restrict to specific students under Enterprise applications, Gloss, Properties, Assignment required.
Admin consent link (shape; the client ID is filled in when Microsoft publisher verification completes):
https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=01e691ed-477b-4041-bdc3-387cabc792e8&scope=https://graph.microsoft.com/Mail.Read offline_access openid email&redirect_uri=https://joingloss.app/it/consented/
To block Gloss: Enterprise applications, Gloss, Properties, set Enabled for users to sign-in? to No. This stops all tokens being issued to Gloss in your tenant. Microsoft's guides: Grant tenant-wide admin consent and Disable user sign-in for an application.
Without email access
If you don't approve Gloss, students can still use it with their course site calendar link, their class schedule and their syllabi. Nothing in Gloss requires email access.
Contact
For questions, a security questionnaire or a data processing agreement, email support@joingloss.app. To report a vulnerability, see Security.