Connecting Stakari to your Gmail inbox is optional, but it is how the product works best. Receipts, invoices, and subscription renewal notices live in your inbox. Getting to them automatically means you never have to forward emails or upload CSVs. But we understand that asking for inbox access is a significant trust decision, and we want to be precise about what that means in practice.
The Exact Permission We Request
Stakari requests the Gmail read-only scope: https://www.googleapis.com/auth/gmail.readonly. That is the narrowest scope available for reading email. It gives us the ability to list and read messages in your inbox. It does not allow us to send email, delete messages, modify labels, or make any changes to your account whatsoever.
We request the minimum permission required to do the job. Read-only means exactly that: we can look, never touch.
How We Filter for Financial Emails
We do not read every email in your inbox. When a new message arrives, our pipeline runs a classification step before any content is processed. Only messages that match financial patterns proceed further. Everything else is ignored completely and never stored.
The signals we look for include:
- Subject lines containing words like "receipt", "invoice", "order confirmation", "payment", "subscription", or "renewal"
- Sender domains matching known vendors, payment processors, or billing systems
- Structured data patterns in the email body, such as currency amounts, line items, or order numbers
- Standard financial email formats from Stripe, Paddle, Shopify, AWS, and similar platforms
What We Extract
For emails that pass the financial filter, we extract a small set of structured fields: vendor name, transaction amount, currency, date, and a category label. We store these fields, not the raw email content. The original message body is discarded after extraction.
What We Never Read or Store
- Personal emails, social messages, newsletters, or anything non-financial
- Email attachments of any kind
- Messages in your Sent, Drafts, or Spam folders
- Any email where the financial classifier returns a low-confidence result
- Raw email bodies after the extraction step is complete
You Stay in Control
You can revoke Stakari's Gmail access at any time from your Google account security settings at myaccount.google.com/permissions. Revoking access stops all future email processing immediately. You can also delete your Stakari account and all associated extracted data from the account settings page.
“We built Stakari on the premise that financial visibility should never come at the cost of privacy. That is not a marketing position. It is a design constraint.”
Ndifoin Hilary
Founder