Security

Last reviewed: July 21, 2026 · Markdown version

Zen Inbox Cleaner asks for access to something deeply personal — your inbox. This page explains, in plain language, how that access is protected: an independent security audit, Google's own verification process, and an architecture designed so your email never leaves your device.

Independently audited — CASA Tier 2

Zen Inbox Cleaner has completed the Cloud Application Security Assessment (CASA) — the independent security assessment framework created by the App Defense Alliance and required by Google for applications that access Gmail data through restricted API scopes. The Tier 2 assessment was performed by TAC Security, an independent security lab authorized by the App Defense Alliance.

The assessment covers authentication, session management, access control, cryptography, data validation and sanitization, and secure configuration. And it is not a one-time exercise: to keep its Gmail access, the app must renew the assessment annually.

Verified through Google's OAuth review

Separately from CASA, the app has completed Google's own verification process for restricted Gmail scopes. Both its data access (exactly which permissions it requests, and what it does with the data) and its branding (that the app is who it says it is) have been reviewed and verified. This is the process behind the consent screen you see when you sign in with Google.

No servers to breach

The strongest security control in Zen Inbox Cleaner is architectural: there is nothing on our side to attack. The app operates no servers, databases, or cloud infrastructure that touch user data. Your device talks directly to Google's Gmail API over HTTPS (TLS 1.2 or higher), and all processing happens on-device. Your email data exists in exactly two places: your Google account and your own device.

How data is protected on your device

Minimal permissions

The app requests exactly three Google OAuth scopes — the minimum for its features:

No profile scopes are requested — the app cannot see your name or photo. The optional Zen Pro purchase is handled entirely by the App Store or Google Play and needs no additional Google permission. The exact scope strings and their use are documented in the Privacy Policy.

You stay in control

Report a security issue

If you believe you have found a security vulnerability in Zen Inbox Cleaner, email support@zeninboxcleaner.com with "security" in the subject line. We usually respond within 2 business days. Please never include email contents or passwords in your report.

For the complete picture of what data is accessed, stored, and deleted, read the Privacy Policy.