Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI’s Astra Just Crossed a Line No AI Model Has Crossed Before. It Found Two Zero Days on Its Own.

    September 3, 2026

    The Pentagon Had to Confirm the Bombing Never Happened. The Video Came From the President’s Account.

    September 3, 2026

    Sonos Built Headphones You Can Actually Repair, and They Cost $100 Less Than AirPods Max

    September 3, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»How-To Guides»Check Which Apps Can Read Your Gmail, and Cut Them Off in 60 Seconds
    How-To Guides

    Check Which Apps Can Read Your Gmail, and Cut Them Off in 60 Seconds

    Ethan CaldwellBy Ethan CaldwellSeptember 3, 20269 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Close up of a smartphone screen showing a group of Google app icons
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Every app you have ever signed into with your Google account is listed on one page, and most people have never opened it. Go to myaccount.google.com/connections and you will find a list that typically runs to dozens of entries, some of them from services you stopped using years ago, a few of them still holding permission to read your entire mailbox.

    Quick answerOpen myaccount.google.com/connections, or go to your Google Account, choose Security, and scroll to “Your connections to third party apps and services”. Click any app, choose “See details”, then “Remove access”. The app loses its token immediately. Changing your password does not do this for you, which is exactly why this page matters.

    That last point is the reason to spend five minutes here rather than five months from now. When an attacker tricks you into approving an app rather than stealing your password, resetting the password fixes nothing at all. The FBI issued a warning about precisely this pattern, and the fix lives on this page and nowhere else. We covered the alert in detail when it landed: no password was stolen, so changing yours will not help.

    The 60 second check

    Do this on a desktop browser if you can. The mobile layout works but buries the detail you actually want to read.

    1. Open myaccount.google.com/connections. If you prefer the long route, go to myaccount.google.com, select Security in the left menu, and scroll to Your connections to third party apps and services.

    2. Read the list top to bottom. Google groups entries by connection type, and the type is the single most important thing on the screen. It tells you whether an app can merely identify you or can read your files.

    3. Click an app, then See details. Google shows the specific permissions granted and the date you granted them. A line reading “Read, compose, send and permanently delete all your email from Gmail” is not the same as “See your primary Google Account email address”, and they sit next to each other in the same list.

    4. For anything you do not recognize or no longer use, click Remove access and confirm. There is no undo, but there is also no damage: if you still need the app, you sign in again and grant it access.

    The three kinds of connection, and why only one is dangerous

    Google separates connections into three categories with different buttons and different consequences. Most guides collapse them into one list, which is why people either panic about harmless entries or ignore genuinely risky ones.

    TypeWhat the app can doButton to remove it
    Sign in with GoogleIdentify you and read basic profile details such as name, email address and pictureStop using Sign in with Google
    Linked accountExchange data both ways with a service you connected on purpose, for example a smart speaker or a fitness trackerDelete link
    Access to your Google AccountReach the actual contents of Gmail, Drive, Calendar, Contacts or Photos, up to and including deleting themRemove access

    Recommended for you:

    How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)
    How-To Guides·Sep 3, 2026

    How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

    The third row is the one to audit properly. A shopping site that uses Sign in with Google to save you from inventing another password is doing nothing you should worry about. A four year old email productivity tool that still holds full Gmail scope is a live liability, because whoever owns that company today inherited your mailbox permission along with the source code.

    Which permissions actually matter

    When you click through to the details, Google spells out each granted scope in plain English. These are the phrasings worth stopping on.

    What you will seeRisk if the app is compromised
    Read, compose, send and permanently delete all your emailTotal. Mailbox access is also password reset access to most of your other accounts
    See, edit, create and delete all of your Google Drive filesVery high. Includes anything shared with you by an employer or client
    See and download your contactsHigh. This is the raw material for spear phishing everyone you know
    See, edit, share and permanently delete all calendarsModerate to high. Meeting titles and attendees leak a lot about a company
    See your primary Google Account email addressLow. This is ordinary Sign in with Google behavior
    WarningRemoving access stops future access. It does not retrieve what the app already copied. If a tool has been reading your mail for two years, that archive sits on its servers and revoking the token does not touch it. To get it deleted you have to contact the developer directly and, depending on where you live, cite a data protection right when you do.

    Do the same check on Android and iPhone

    The account is the same, so revoking on one device revokes everywhere. The path differs slightly.

    On Android, open Settings, tap Google, then Manage your Google Account, swipe to the Security tab and scroll to the same connections section. On an iPhone, open the Gmail or Google app, tap your profile picture, choose Manage your Google Account and follow the identical path. Both open the same web view you would see on a desktop.

    These three URLs are worth bookmarking. Together they cover apps, sessions and devices, which is the whole surface area of an account takeover.

    # Apps and services holding permission on your account
    https://myaccount.google.com/connections
    
    # Google's own guided audit, including recent security events
    https://myaccount.google.com/security-checkup
    
    # Every device currently signed in, with location and last activity
    https://myaccount.google.com/device-activity
    
    # Workspace administrators only
    Admin console > Security > Access and data control > API controls
    
    TipDo the device activity page in the same sitting. An attacker who got in through a consent screen usually also has a signed in session somewhere. Revoking the app without ending the session leaves half the door open. Sign out of every device you do not recognize, then change your password, in that order.

    If you run a Google Workspace domain

    Individual users clicking through consent screens is not a policy. Workspace gives administrators a control that decides the question centrally, and most domains leave it wide open by default.

    In the Admin console go to Security, then Access and data control, then API controls, then Manage Third Party App Access. Every app that touches your domain’s data can be marked Trusted, Limited or Blocked, and you can set a default that stops unconfigured apps from getting access at all. Since December 2024 you can also configure an app by individual API scope rather than all or nothing, so a tool that genuinely needs calendar access does not automatically get Drive as well.

    The setting that changes the most, fastest, is switching the default for unconfigured third party apps to blocked. Expect a week of access requests from staff. That is the point: you find out what your organization was actually connected to.

    Troubleshooting

    An app I removed is back on the list

    You signed in with it again, usually without noticing, because the app prompted and you clicked through. Check the grant date shown in the details view. If it is today, that is what happened. If the date is old and you are certain you removed it, treat it as a compromise and run the security checkup.

    Removing access broke something I use

    Expected and reversible. Open the app, sign in with Google again, and approve the consent screen. Read it this time. If the app asks for more than it plausibly needs, that is useful information and a good reason to look for a different tool.

    I cannot find the connections section at all

    You are probably signed into a Workspace account where an administrator has restricted the page, or you are looking at a Google product connection rather than a third party one. Use the filter at the top of the connections list to switch between “Google product” and “Other account access”.

    The list is empty but I know I have connected apps

    You are signed into a different Google account than you think. Check the avatar in the top right corner. Multiple account sign in makes this a very common mistake, and it is the reason people conclude their account is clean when it is not.

    Frequently asked questions

    Does changing my Google password revoke app access?

    No. An OAuth token granted to a third party app is a separate credential from your password and survives a password change. This is the whole mechanism behind consent phishing, and it is why security advice that stops at “change your password” leaves the attacker connected.

    Recommended for you:

    Can Your Employer See Your ChatGPT Chats? What IT Actually Logs
    How-To Guides·Sep 3, 2026

    Can Your Employer See Your ChatGPT Chats? What IT Actually Logs

    How often should I check this page?

    Twice a year is enough for most people, plus immediately after any phishing scare or any news about a breach at a service you use. Put it in the same slot as reviewing your saved passwords and it stops being a task you forget.

    Is Sign in with Google safe to keep using?

    Yes, and it is usually safer than creating another password. It grants only basic profile information and gives you one place to cut off every service at once. The risk is not the sign in method, it is the separate full data permissions some apps request alongside it.

    Can I see what an app actually did with my data?

    Not from this page. Google shows what was granted, not what was used. For Workspace domains, the audit and investigation tool in the Admin console records API activity. For personal accounts, the security checkup lists recent security events but not per app usage logs.

    What about app passwords and less secure app access?

    Google removed less secure app access for consumer accounts, so anything still working through it has already broken. App passwords, where they still exist for older mail clients, are listed separately under Security and should be revoked with the same suspicion you apply to app connections.

    The bottom line

    The connections page is the shortest security win available on a Google account, and almost nobody opens it. Five minutes of reading and a few clicks removes every abandoned service that still holds a live key to your mailbox, and it is the only action that actually stops a consent phishing attack once it has succeeded.

    Pair it with two other habits and your account is in genuinely good shape: a password manager and unique passwords, covered in our guide to strong passwords, and a working eye for the consent screens and scam pages that get people here in the first place, which our walkthrough on spotting online scams covers. The browser is worth a pass too: extensions ask for the same kind of sweeping permission, and they can turn malicious in an update long after you install them.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleCan Your Employer See Your ChatGPT Chats? What IT Actually Logs
    Next Article How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)
    Ethan Caldwell

      Ethan Caldwell is GeekBlog's resident Apple specialist, covering the entire Apple ecosystem - iPhone, iPad, Mac, Apple Watch, AirPods and the software that ties them together. A longtime iOS user and gadget collector, Ethan tracks Cupertino's every move, breaking down Apple keynotes, A- and M-series chip benchmarks, iOS feature updates and the rumor mill into clear, practical takes that help readers decide whether the latest Apple hardware is worth the upgrade.

      Related Posts

      11 Mins Read

      How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

      11 Mins Read

      Can Your Employer See Your ChatGPT Chats? What IT Actually Logs

      13 Mins Read

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      8 Mins Read

      Why Is My Phone Lagging All of a Sudden? (Fixes)

      7 Mins Read

      How to Block Twitch Ads With uBlock Origin (2026)

      8 Mins Read

      How to Clear Cache on Android (Any Phone)

      Top Posts

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20263 Views

      How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

      September 3, 20262 Views

      Check Which Apps Can Read Your Gmail, and Cut Them Off in 60 Seconds

      September 3, 20262 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      Best Stores for Buying MP3 and Digital Music You Can Keep Forever (2026)

      August 2, 2025932 Views

      Discord will require a face scan or ID for full access next month

      February 9, 2026770 Views

      Trade in your old phone and get up to $1,100 off a new iPhone 17 at AT&T – here’s how

      September 10, 2025383 Views
      Our Picks

      OpenAI’s Astra Just Crossed a Line No AI Model Has Crossed Before. It Found Two Zero Days on Its Own.

      September 3, 2026

      The Pentagon Had to Confirm the Bombing Never Happened. The Video Came From the President’s Account.

      September 3, 2026

      Sonos Built Headphones You Can Actually Repair, and They Cost $100 Less Than AirPods Max

      September 3, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.