YAO LifeOS Owner Admin Preview Gmail readonly demo

This public demo shows the user-initiated Gmail readonly workflow for Google OAuth verification. It uses sanitized UI examples only and does not include real Gmail message bodies, OAuth tokens, client secrets, or private account data.

No-login reviewer access

This page is the public reviewer packet for the submitted Gmail readonly OAuth review flow. It does not require Cloudflare Access, a one-time PIN, a shared password, or reviewer credentials. The protected Owner/Admin app remains available for owner operation, but the scope explanation, message-body processing explanation, source-account impact explanation, demo video, and direct MP4 fallback are available here without login.

The live browser-only reviewer surface is also available at /oauth-live/. It lets Google reviewers use their own Google test account to complete the OAuth consent flow and run a real Gmail readonly API readback without LifeOS login credentials, Cloudflare Access, one-time PIN, phone verification, or credit-card steps.

Requested Gmail scope

The Gmail readonly review flow requests https://www.googleapis.com/auth/gmail.readonly. The app uses this scope only for user-started, bounded read-only workflows that read a selected Gmail thread or one user-provided counterparty thread, derive a sanitized LifeOS source-pointer preview, and return readback counts.

Maximum user-facing feature enabled by this scope: after a user opens the Gmail readonly review surface and starts the OAuth flow, the app can read metadata, headers, labels, thread membership, and message body content for the bounded Gmail item the user selects or provides. The app then displays a sanitized project-context preview/source pointer so the user can decide whether the email exchange should inform a LifeOS project. It does not perform background mailbox monitoring, broad mailbox export, or automated ingestion outside that user-started review action.

A narrower Gmail metadata-only scope is not sufficient for this feature because headers and snippets cannot substantiate or summarize the body of the Gmail exchange that the user selected. The app must read message body content transiently to generate the user-requested project-context preview and sanitized source pointer. The app does not use this flow to send, modify, archive, trash, or delete Gmail messages.

Message body processing

The submitted flow reads Gmail body content only during a user-started bounded review action. Body content is used transiently to create a sanitized body summary, source pointer, and readback metrics for the selected or user-provided Gmail thread. Raw Gmail bodies are not returned in public output, not committed to Git, not written to ordinary database records, and not used for generalized AI/ML model training.

Limited Use and AI/ML disclosure

YAO LifeOS adheres to the Google User Data Policy, including the Limited Use requirements. Raw, aggregated, anonymized, or derived Google Workspace API user data is not used to develop, improve, or train generalized or non-personalized AI/ML models.

The submitted Gmail readonly review flow does not transfer raw Gmail bodies to third-party AI services for generalized model training or model improvement. Current and planned LifeOS AI processing is backend controlled and must use providers and configurations that do not train generalized models on API payloads unless the user explicitly opts in outside this submitted review flow. See the Privacy Notice for the provider disclosure.

Source account impact

Because the submitted flow is readonly, the expected Gmail source account impact is no Gmail state mutation. The demo shows the synthetic source message before the LifeOS action, performs the in-app Gmail readonly readback action, and then shows the same Gmail source account after the action with the message still visible and unchanged. No read/unread, archive, star, trash, send, modify, or delete operation is part of this submitted scope.

Scope alignment

The submitted Gmail readonly OAuth review flow is expected to match the Google Cloud Console Data Access configuration exactly: https://www.googleapis.com/auth/gmail.readonly. The review path starts Google OAuth with scope_profile=gmail_readonly and a clean consent request, so the authorization URI for this review flow contains this Gmail readonly scope and does not depend on a broader Gmail send, modify, or Calendar scope.

Reviewer navigation

  1. Open this public review packet: https://google-oauth.mojage.club/oauth-demo/.
  2. Review the requested scope, maximum user-facing feature, message body processing, Limited Use disclosure, and source account impact sections on this page.
  3. Open the live reviewer surface: https://google-oauth.mojage.club/oauth-live/.
  4. Click Start Gmail readonly OAuth, use a Google reviewer account, and expand the consent details if needed to confirm that https://www.googleapis.com/auth/gmail.readonly is visible.
  5. Confirm that the live readback fetches Gmail data and returns sanitized source-pointer preview metrics only.
  6. Open the YouTube demo video or the direct MP4 fallback on this page for the recorded walkthrough.
  7. Confirm that the shown Gmail readonly readback returns sanitized source-pointer preview output without raw Gmail bodies, OAuth tokens, client secrets, raw provider IDs, or raw email addresses.
  8. Confirm that the Gmail source message remains visible and unchanged after the readonly action because send, modify, archive, trash, and delete operations are outside the submitted flow.

YouTube demo video: https://youtu.be/Ixq-3ecX4Ik