01What Redeep is
Redeep is a desktop application for macOS, published by Slideform, Inc. It is a workspace for organizing your work with AI coworkers: you create a board, write a card describing a task, and hand that card to an agent that carries it out.
The tasks people give Redeep are ordinary knowledge work — research, writing, analysis, operations, and coding. Several agents can work at the same time, each in its own isolated workspace, and each result comes back to you for review before it goes anywhere. Redeep runs on your own Mac using a model provider key you supply; there is no Redeep account, and no server of ours sits between you and the services you connect.
- ApplicationRedeep
- PublisherSlideform, Inc.
- PlatformmacOS 14 or later, distributed at redeep.app
- Homepagehttps://redeep.app
- Privacy policyhttps://redeep.app/privacy
- Contactjames@slideform.co
02Why Redeep asks for access
A great deal of real work lives in mail and a calendar, so the tasks people hand to Redeep often need them. For example:
- “Summarize this week’s thread with the client and list what they’re waiting on.”
- “Pull the totals out of the invoices sitting in my inbox.”
- “Draft a reply to this message for me to review and send.”
- “When am I free on Thursday, across both of my calendars?”
- “Put the design review on the calendar with these three people.”
None of that is possible unless Redeep can reach the Google account you choose. So Redeep asks you to connect that account and approve a set of permissions on Google’s own consent screen. Redeep uses that access for one purpose: carrying out the tasks you assign inside the app. It is not used for advertising, profiling, or training models, and your Google data is never sold or transferred to anyone for those purposes.
Connecting Google is optional. Redeep works without it. The mail and calendar features are simply unavailable until you connect an account, and you can disconnect at any time.
03What each permission is for
These are the permissions Redeep requests when you connect an account, and the specific job each one does. You approve them on Google’s consent screen, and you can review or revoke them at any time from your Google Account.
| Permission | Google scope | What Redeep does with it |
|---|---|---|
| Sign-in identity | openid, email |
Identifies which Google account you connected, so Redeep can label it in Settings and send a task to the right account. Nothing else. |
| Read Gmail | gmail.readonly |
Lets a task read the mail it needs to do its job — the thread you asked it to summarize, the receipts you asked it to total, the search you asked it to run. |
| Manage Gmail drafts | gmail.compose |
Writes a reply into your Drafts folder for you to read and send yourself, and deletes a draft after you approve that exact deletion. Redeep has no send-mail step, so it cannot send mail on your behalf. |
| List your calendars | calendar.calendarlist.readonly |
Sees which calendars exist on the account, so a task reads the right ones instead of guessing. |
| Read availability | calendar.events.freebusy |
Answers “when am I free?” and proposes meeting times that actually work, including across two connected accounts. |
| Read and manage events | calendar.events |
Reads events to answer schedule questions, and creates, edits, cancels, or RSVPs to an event after you approve that exact change. |
| Drive, Docs, Sheets, and Slides files | drive.file |
Reads and edits only files you choose in Google’s official Picker or that Redeep creates, including documents, spreadsheets, and presentations. Redeep receives only selected file IDs and cannot browse or search the rest of your Drive. |
Redeep requests these permissions at connection time and asks for nothing beyond them.
Google Picker may repeat the existing drive.file consent while you choose files;
it does not add a broader Drive permission. If a grant is missing a permission a task needs,
the task stops and tells you to reconnect rather than working around it. If an existing Drive
file has not been opened through the Picker, the task asks you to open it there first.
04What waits for your approval
Reading happens inside the task you assigned. Anything that creates or changes data stops and asks you first.
- Reads run as part of the task. When you assign work that needs mail or calendar, the agent reads what that job needs — you already asked for it. Every request and every result is written into the task’s transcript, which stays on your Mac, so you can see exactly what was read.
- Changes show you the exact change first. Creating a draft, creating or editing an event, cancelling one, or sending an RSVP stops and presents a summary: the account, the calendar, the time, the attendees, and the specific fields that would change. Nothing is written until you approve that summary.
- Your approval covers the version you saw. For an edit or a cancellation, Redeep checks that the event has not changed since you approved it. If someone else moved or edited it in the meantime, the action stops and asks you to look again instead of overwriting their change.
- Redeep never sends email. The only thing it can write to Gmail is a draft, which sits in your Drafts folder until you send it yourself.
- Named agents need an explicit grant. If you set up a standing agent, Google access is a per-agent setting you turn on deliberately. An agent you did not grant it to cannot reach your Google account at all.
05Connecting & disconnecting
- Open Redeep on your Mac and go to Settings → Connections.
- Click Authorize Google Workspace. Redeep opens Google’s own sign-in and consent screen in your browser, where you pick the account and approve the permissions. Redeep never sees your Google password.
- Google returns keys for the account you chose, and Redeep stores them in your Mac’s Keychain. The account then appears in Settings with the services it granted.
More than one account
You can connect several Google accounts — a work identity and a personal one, for example. Each connected account is listed separately with its own permissions, can be given a label, and one of them is the default that a task uses unless you name a different one. Google’s account chooser is always shown when you add an account, so a new connection can never quietly replace an existing one. A task that spans both accounts — “find a time that works on both my calendars” — reads each one under its own grant and tells you which account each result came from.
Disconnecting
Disconnect any single account from the same screen. Redeep asks Google to revoke that account’s grant and deletes its stored keys from your Mac, leaving your other accounts connected. You can also revoke access at any time from your Google Account permissions page. Either way, access ends immediately.
06Where your data goes
- Requests go from your Mac straight to Google. Redeep is a desktop app, not a hosted service. Slideform, Inc. runs no server in that path and receives no copy of your mail, your calendar, or your files.
- Your keys stay in the macOS Keychain. The long-lived key that keeps the connection alive never leaves it; a running task gets only a short-lived access key for the account you picked. Neither is ever written into a project file or a configuration file.
- What an agent reads goes to the model you chose. If you ask an agent to summarize a thread, that thread’s content is sent to the model provider whose key you connected — that is how the summary gets written. Choose the model provider you are comfortable handing that content to.
- Redeep keeps no copy of its own. What was read is recorded in the task transcript on your own disk, and deleting the session deletes it.
Limited Use. Redeep’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used for one purpose — providing the features you asked for in the app — and for no other. It is not used for advertising of any kind, never sold or transferred to advertising platforms, data brokers, or information resellers, never used for credit or lending decisions, and never used or transferred to develop, improve, or train generalized or non-personalized AI or machine-learning models. Nobody at Slideform reads it; it never reaches us.
How it is protected. Requests travel over HTTPS/TLS straight from your Mac to Google. You authorize on Google’s own screen with OAuth 2.0 and PKCE, so Redeep never sees your password, and the keys Google issues are stored in the macOS Keychain — encrypted by macOS, unreadable until you unlock your Mac, never synced to iCloud, and never written into a project or configuration file. Redeep asks for the narrowest permission that does the job, a standing agent gets access only if you grant it, and every change to your account waits for your approval.
The full detail — the permission-by-permission purposes, the security mechanisms, what stays on your Mac, and how long anything is kept — is in the Google user data and data protection sections of the Redeep privacy policy.
07Questions
If anything here is unclear, or you want a permission explained in more detail, write to us:
- Slideform, Inc.
- james@slideform.co
For how Redeep works day to day — boards, agents, sandboxing, and the review step — see the documentation or the Redeep homepage.
Redeep