Privacy and security

A plain-language guide to the permissions Dotless uses and the controls available to workspace owners.

August 2, 2026

August 2, 2026

Permission boundaries

Connection

Access used by Dotless

Access not requested

Gmail

Basic account identity and email sending.

Mailbox reading, reply monitoring, deletion, or message management.

Outlook

Basic Microsoft identity, offline access, and email sending.

Mail.Read or Mail.ReadWrite.

SMTP

Sender configuration supplied by the workspace owner.

Access to unrelated provider account data.

CRM integrations

The record scopes described in each provider guide.

Importing the whole CRM or syncing CRM-side edits back into Dotless.

Lead and prospect data

Dotless is designed around business information and publicly available business or professional contact data. Availability does not make every use lawful or appropriate. You are responsible for the purpose, audience, message, opt-out handling, and applicable rules.

Locked email and phone values remain excluded from CRM sync until a user chooses to unlock them.

Connection control

  • Only the workspace owner can create or remove supported CRM connections.

  • Disconnecting removes stored CRM authorization and pending sync work from Dotless.

  • Existing records in an external CRM are not deleted automatically.

  • OAuth access can also be revoked from the provider’s connected-app settings.

  • Never share provider secrets, access tokens, refresh tokens, or passwords with support.

Policies and requests

  • Privacy Policy

  • Prospect Privacy

  • Data Processing Addendum

  • Subprocessors

  • Security and vulnerability reporting

  • Terms of Use