Security and data
Closive works with personal information, so clear boundaries matter. Here is how access and approval work today.
Effective 7 October 2026
Signing in and connecting Google
Closive uses Google sign-in to identify your account. You enter your password with Google, not Closive. Your account information and work are kept separate from other Closive accounts.
Sign-in verifies your Google identity. Gmail, Calendar and Drive reading, sending email, changing events and writing Google documents are optional. Start with what you share in Chat or voice, or connect Gmail and choose to let Closive find open loops. If a task needs access you have not granted, Closive can ask you to enable it. Connecting Gmail alone does not enable broad email discovery. You choose what to investigate or track; finding new work across your email is a separate choice. Google’s permission covers your mailbox, while Closive limits its reads to those requests and choices. Enabling access does not itself send an email, change an event or write a document.
What each permission is for
- Gmail reading: find relevant work items and the context needed to help.
- Gmail sending: send approved emails to others, or email results to yourself when you explicitly ask.
- Calendar reading: read events, including invitations, on your primary calendar for preparation and follow-through.
- Calendar changes: create an event on your calendar, including any invitations, update or cancel an event you organize, or remove an invitation from your own calendar after you approve the exact change.
- Drive reading: read specific files needed for your work, search for requested files, explore selected folders and capture selected files for approved email drafts. Closive does not automatically index or synchronize your whole Drive.
- Document writing: create Google Docs and Sheets and make supported edits to app-created files after you approve the exact change. This optional permission does not grant editing access to your whole Drive. Selecting other existing files for editing is not available in this rollout.
An explicit request to email results to yourself authorizes delivery to your verified account address without another draft approval. Chat self-email uses your Gmail. Scheduled email results come from Closive through Resend and do not need Gmail sending access. Connecting an account alone never authorizes a send.
You approve external actions
Closive can prepare drafts, guides and meeting work in the background. It asks you to review and approve an email to someone else before sending it or an event before creating, changing or removing it. Google document creation and edits also require approval of the exact proposed change. Permission to access your account is separate from approval of that action.
Protecting access
Connections to the hosted application use HTTPS to encrypt data in transit. Browser session cookies are marked Secure and HttpOnly: they are sent over HTTPS and cannot be read by page JavaScript. The server checks the signed-in account before allowing access to that account’s stored work.
Google access credentials stay on the server in account-specific files with restricted filesystem permissions. They are not sent to the browser or included in AI conversations or application logs. When you reconnect Google, Closive verifies that the Google identity matches your account before replacing its saved credentials. This public website is separate from the application and does not receive your connected account content or access credentials.
Relevant information is processed by third-party services to provide AI assistance, voice and hosting. See our Privacy policy and data retention policy for how information is used, shared and kept.
Signing out, disconnecting and deleting
Signing out ends that Closive sign-in; it does not stop background work or disconnect Google. Account and privacy lets you withdraw AI-processing consent, disconnect Google, or request account deletion. Disconnect stops processing while retaining saved history; reconnect to use it again. Deletion immediately blocks processing, sign-ins and push. We complete active-data cleanup and email confirmation within 7 days; recovery copies are removed within 90 days of the request. You can also revoke access in your Google account permissions. See Support for help.
Our current stage
Closive is an early hosted alpha operated by a small team. We have not obtained security certifications or commissioned an independent security audit or penetration test.
If you find a security problem, write to manpreet@closive.ai and we will respond directly.