Gmail Connect — a widget for the Corsair XENEON EDGE. Last updated 11 September 2026.
Gmail Connect shows your Gmail on the touchscreen of a Corsair XENEON EDGE and lets you
read, reply to, and organise it there. This policy explains exactly what it touches.
The short version. Your mail goes from Google to your own screen and nowhere
else. We operate no mail server, no analytics, and no account system. We cannot read
your mail, and we hold nothing that would let us.
What Gmail Connect accesses
With your permission, Gmail Connect uses one Google API scope:
https://www.googleapis.com/auth/gmail.modify — read your messages,
change their labels (read/unread, starred, archived, spam, bin), and send mail you
compose in the widget.
It does not request permission to delete your account's data permanently, to read your
contacts, your calendar, your Drive, or your profile beyond the email address of the
mailbox you connect.
Where your mail goes
The widget calls Google's Gmail API directly from your device over HTTPS. Message
content, subjects, senders and attachments travel between Google and your XENEON EDGE and
are not routed through us or through any third party. Nothing is copied to a server of
ours, because there is no such server.
Mail is held only in the widget's memory while it is on screen. It is not written to
disk except for whatever caching the device's browser engine performs on its own.
What is stored, and where
On your device. The key for the mailbox you connected — a Google refresh token,
or, if you signed in with your own Google script, that script's address and the secret it
issued — plus your display preferences and any unsent draft, all in the widget's local
browser storage. Pressing Disconnect in the widget erases them and asks Google to
revoke the token, or tells your script to forget its secret.
In your own Google account, if you chose that route. Signing in with your own
Google script puts a small Apps Script project in your Google Drive. It belongs to you,
runs as you, and only ever hands your widget a one-hour access token. We have no access to
it.
During sign-in only, for at most ten minutes. Signing in happens in a real
browser, which then has to hand the key to your EDGE. It does so through a small
database record. That record is encrypted before it leaves the browser, with a
key derived from a one-time secret that exists only on your EDGE's screen and in the
device that scanned it. The record is deleted the moment your widget collects it, and
expires automatically after ten minutes either way. We cannot decrypt it: the key is
never sent to us.
What we never do
We do not sell, rent or share your data with anyone.
We do not use your data for advertising, and show no ads.
We do not use your data to train machine-learning or AI models.
No human at Gmail Connect reads your mail. No mechanism exists that would allow it.
We run no analytics, tracking pixels or third-party scripts on the sign-in page.
Remote images in messages are blocked by default, so senders are not told when you
open their mail.
Limited Use disclosure
Gmail Connect's use and transfer of information received from Google APIs to any other app
will adhere to the
Google
API Services User Data Policy, including the Limited Use requirements.
Withdrawing access
You can disconnect at any time, in either of two places:
In the widget: Settings → Disconnect. This forgets the key and asks Google to
revoke it.