Skip to content

How Trupeo accesses and protects your mailbox

Understand the difference between Google or Microsoft authorization and IMAP credentials, what Trupeo stores, and how to remove access.

Updated on July 24, 2026

Trupeo needs access to the shared mailbox so it can show conversations, keep their state in step, and send your team’s replies. The way that access works depends on the mailbox provider.

Google and Microsoft keep the mailbox password

Gmail, Google Workspace, Outlook, and Microsoft 365 use provider authorization, also called OAuth. Trupeo sends the account owner to Google or Microsoft’s own sign-in page. The owner enters the password there, not in Trupeo, and approves the access shown by the provider.

That access lets Trupeo:

  • read and organize mail so the shared inbox stays synchronized;
  • send mail from the connected address;
  • identify the Microsoft account that was authorized and keep the connection active without a new sign-in every day.

The resulting connection token is stored in encrypted form. It can be revoked from the provider account or removed by deleting the mailbox from Trupeo.

For the exact Google screens and checks, see Connect a Gmail mailbox.

IMAP needs a connection secret

Providers outside Google and Microsoft connect through IMAP for receiving and SMTP for sending. Their form asks for server details, a username, and a password because those protocols do not provide the same Google or Microsoft sign-in page.

Use an application password when your provider offers one. It is dedicated to Trupeo and can be revoked without changing the mailbox’s normal password. Trupeo stores IMAP and SMTP usernames and passwords in encrypted form before they are saved.

The complete setup is in Connect an IMAP mailbox.

What is stored for the shared inbox

Trupeo stores the mailbox address, the technical connection information, and the message data needed to provide the shared inbox. Message bodies are encrypted before storage. Attachments are kept in protected storage in the European Union, as described in the privacy policy.

Each teammate uses their own Trupeo account. Access to a shared mailbox comes from mailbox membership and role, so the team does not need to circulate one mailbox password for everyday work.

Remove access or delete the mailbox

A mailbox owner can delete the mailbox from Trupeo settings. The mailbox record and its database data are removed, provider notifications are cancelled when possible, and stored message bodies and attachments are queued for purge. The privacy policy explains the separate backup-retention period.

Deleting the Trupeo mailbox does not delete the original mailbox at Google, Microsoft, or the IMAP provider.

What not to send to support

Never send us a mailbox password, application password, or provider token. We do not need those secrets to investigate a connection problem. Send the mailbox address, the provider name, and the exact error message instead.

To start safely, follow Connect your first mailbox. If something still looks wrong, contact us. A person reads every message.