About Sigil
What Sigil is, in plain language
Sigil is a credential-management application for personal AI assistants. It lets a user
securely connect their AI tools — including Claude Desktop, OpenClaw, Cursor, and ChatGPT —
to their Google account and other services, without giving those AI tools direct access
to the user's Google data.
When a user connects a Google account to Sigil, Sigil acts as a permission layer between
the user's Google data and the user's AI assistants. The user grants narrow,
time-bound permissions through Sigil — for example, allowing an AI to send a single
email on the user's behalf, rather than granting the AI read access to the
user's entire inbox.
Every action a user's AI takes through Sigil is recorded in an audit log accessible
to the user in real time. Sigil itself does not access, store, or process Google data
on its own behalf — every API call is initiated by a user-authorised AI assistant at the
user's direction.
Why Sigil requests each Google OAuth scope
-
https://www.googleapis.com/auth/gmail.send — to allow a user's AI assistant to send emails on the user's behalf when the user has explicitly granted that permission. Sigil never requests Gmail read or modify scopes.
-
https://www.googleapis.com/auth/calendar.events — to allow a user's AI assistant to read upcoming events from the user's primary Google Calendar and to create new events when the user has granted that permission. Sigil does not request the broader
calendar scope.
-
https://www.googleapis.com/auth/drive.readonly — to allow a user's AI assistant to search the user's Google Drive and read the content of documents the user has specifically directed it to. Read-only.
-
https://www.googleapis.com/auth/drive.file — to allow a user's AI assistant to create files in the user's Google Drive, scoped to files the integration itself creates or opens.
-
https://www.googleapis.com/auth/spreadsheets — to allow a user's AI assistant to read cell values from Google Sheets the user has directed it to, and to append rows to those sheets when the user has granted write permission.
Sigil's data handling, retention, and deletion practices are described in detail
in our Privacy Policy
(https://joinsigil.com/privacy).
Sigil's security model — including how user OAuth tokens are encrypted, who can
decrypt them, and what to do if you find a flaw — is documented in our
Security Policy
(https://joinsigil.com/security).
Sigil's
Terms of Service
are at https://joinsigil.com/terms.