ChatGPT Connectors: What They Can See in Your Drive and Inbox

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for ChatGPT Connectors: What They Can See in Your Drive and Inbox.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for ChatGPT Connectors: What They Can See in Your Drive and Inbox.

Anything the connected account can already open. ChatGPT's apps (formerly connectors) for Google Drive, Gmail, Outlook and SharePoint search and read the files and messages your own login can reach, including folders colleagues have shared with you, and by default they read without asking each time. What that account can't open, ChatGPT can't see.

In a small business that boundary is wider than it sounds, because the owner's account can usually open everything: payroll sheets, the accountant's shared folder, years of customer emails. Connect that account and ChatGPT gets a search box over all of it. What happens to the data afterwards depends on two separate settings: model training, which is off by default on business plans, and Memory, which can keep details from a connected inbox for later chats.

Follow me on Instagram@sagnikteaches

Connectors are now apps: what each one can reach

OpenAI renamed connectors to apps, and the help pages now describe them as connected apps. You add one from the Apps area (called Plugins in some versions), sign in to your Google or Microsoft account, and approve the permissions screen that follows. Once Gmail is enabled, ChatGPT pulls from it automatically when a question seems relevant, without you choosing it each time. Here is what OpenAI's help pages say each of the four main apps can reach, as checked in September 2026:

Connect on LinkedInSagnik Bhattacharya
AppWhat ChatGPT can seeWhat it can do beyond reading
Google DriveFiles and folders the connected Google account can open, including Docs, Sheets and SlidesDocs, Sheets and Slides actions, where your workspace allows them
GmailMessages in the connected mailbox, searched when relevant to your requestSend email from ChatGPT on the web (Plus, Pro, Business and Enterprise); event-triggered tasks in ChatGPT Work that respond to new messages
Outlook EmailMessages in the signed-in mailbox: subject, sender, recipients, timestamps and plain-text body, with full message text for search resultsLook up people, use contact actions when enabled, send email on the web
SharePointSharePoint content, and work OneDrive content, that the user can already openSearch and reference; some Microsoft actions need an admin to grant permissions first

Two details in that table surprise people. The Outlook app returns the whole text of a matching email, not a snippet, so a vague question can pull a long thread into the chat. And the Gmail and Outlook apps can now send, which turns a reading tool into one that can act in your name. The permission settings further down decide whether ChatGPT asks first.

Subscribe on YouTube@codingliquids

Setting these up in the first place, and choosing between ChatGPT and Claude for it, is the subject of connecting ChatGPT or Claude to your business apps. The rest of this page is about the reach, and about narrowing it.

The rule underneath: your login is the boundary

These apps use the sign-in you approve, so they inherit that account's access and nothing more. OpenAI's help pages put it as ChatGPT only being able to use content the connected account can open. That cuts both ways.

  • It won't see what you can't. A receptionist who connects her own Google account can't use ChatGPT to read the owner's payroll folder, because her account can't open it.
  • It will see everything you can. That includes files others have shared with you, shared drives you belong to, and, in Microsoft 365, SharePoint sites you were added to years ago and forgot.
  • Two people asking the same question get different answers. OpenAI notes this for business workspaces: each person's results reflect their own permissions.

I haven't found a setting in OpenAI's help pages that limits a personal Drive connection to chosen folders, so plan as if the whole account is in scope. On eligible managed workspaces an admin can instead set up an indexed knowledge source through administrator-managed sync, which still respects each file's permissions; personal and individual accounts can't configure Drive sync at all.

A picture framer's Drive, before and after an access check

Take an illustrative four-person framing shop on Google Workspace. The owner wanted to ask ChatGPT things like "what did we charge for float mounts last spring?" and was about to connect his own account. A 25-minute check first showed what that would expose.

What the account could openOwner's accountShop manager's account
Files the account owns1,850620
Files shared by staff640410
Files shared by outsiders (accountant, suppliers, landlord)41070
Total in reach2,9001,100
Sensitive files in reach (payroll, contracts, year-end folder, customer list)811

The owner's account could open 12 payroll spreadsheets, 8 staff contracts, the accountant's 60-file year-end folder and the customer address list. The manager's account held the price lists, supplier catalogues and job sheets that the everyday questions actually needed, plus the customer list, which the shop uses for collection reminders. So the shop connected the manager's account for day-to-day questions and left the owner's unconnected. Files in reach dropped from 2,900 to 1,100, and sensitive files from 81 to 1. They also removed "anyone with the link" sharing from the customer list while they were there.

The first real question showed why the check paid off in another way too. The prompt was:

Find our current price list for float mounts and box frames and tell me
what changed from the previous version.

An illustrative first answer:

Your float mount prices rose by about 8% between the two versions: a 30 x 40 cm float mount went from $64 to $69. Box frames are unchanged at $85 for the standard depth.

What was wrong with it: the "current" file ChatGPT used was a 2024 draft someone had duplicated, not the live price list. The fix was a better prompt, "list the files you used, with owner and last-modified date, before comparing", which exposed the draft straight away. Asking for file names and dates is worth making a habit, because Drive searches match on content, and old copies match as well as current ones.

What one Gmail question pulls into the chat

Inboxes hold more personal detail than Drive does, and a broad question sweeps it all in. Here is an illustrative case from a self-employed music teacher who connected Gmail to ChatGPT Plus:

Which parents have emailed about autumn term fees this month,
and what did each one say about paying?

I found 9 emails from 7 parents. [First name]'s mother says she will pay on the 15th. [First name]'s father asks to move Tuesday lessons because his son has hospital appointments through October and says he'll pay after that. Two parents asked for the bank details again. I can't confirm payment status, because payments aren't recorded in Gmail.

The answer is useful, and it also carried a child's medical detail into the chat, simply because it sat in a matching email. Three things follow from that. If Memory is on, ChatGPT may remember relevant information it read from an app unless the app restricts it. On Free, Go, Plus and Pro plans, OpenAI says information accessed through apps may be used for training when "Improve the model for everyone" is on, although its Google app FAQ says data accessed directly from connected Google apps isn't used to train its general models. And the chat itself now holds that detail until someone deletes it.

What to fix: narrow the question so fewer emails match ("emails with 'autumn fees' in the subject since 1 September, payment dates only"), switch Memory off while doing inbox work of this kind, and delete the conversation once the job is done. The underlying settings are explained in how ChatGPT's memory settings work for business.

Outlook users have a sharper tool for the same job. OpenAI says the Outlook Email app understands structured searches, such as from:, subject: and date filters, and returns the full text of whatever matches. A garden centre buyer checking a delivery dispute could ask:

Search my Outlook for from:orders@[supplier domain] subject:compost
received after 1 September. List each email's date and the delivery
date it mentions. Don't quote anything else from the messages.

That pulls in perhaps four emails instead of every thread that ever mentioned compost, including the one where a customer complained about a staff member by name. The final instruction doesn't stop ChatGPT reading the matching emails, but it keeps unrelated detail out of the answer you might forward to someone else.

Training, memory and what stays after you disconnect

QuestionFree, Go, Plus and ProBusiness and Enterprise
Can data read through apps train OpenAI's models?Yes, if "Improve the model for everyone" is on, with the Google-apps exception aboveNot by default
Can ChatGPT remember what it read?Yes, if Memory is on and the app doesn't restrict itWhere Memory is available in the workspace, the same rule applies
What does disconnecting do?Stops future access. Past chats, saved files and memories stay until you delete them.

The last row is the one people get wrong. OpenAI's help pages say disconnecting an app doesn't delete existing or archived conversations, saved files or memories; to remove the data, you delete the conversations that referenced it and any related saved memories. If a staff member used a connected inbox for months, disconnecting on their last day leaves all of that in place. How the plans differ on training is set out in whether ChatGPT trains on client data on business and free plans.

Admin switches on ChatGPT Business worth changing today

On ChatGPT Business, apps are enabled by default (Enterprise and Edu start with them off), so a new workspace lets every member connect Drive and Gmail on day one. Four controls narrow that, all under Workspace settings:

  1. Turn off apps you don't use. In Workspace settings, Apps, disable anything the team has no reason to connect.
  2. Limit who can use each app. From an app's menu, User access lets you choose which roles can use it. Inbox apps for managers only is a reasonable start.
  3. Allow reading only. Where an app supports action control, you can allow all actions, only read actions, or a custom set, and choose whether actions added later are switched on, read-only, or off. "Only read actions" stops ChatGPT sending, moving or renaming anything.
  4. Decide when ChatGPT asks. App permissions offer Always ask, Any changes and Important actions, as a workspace default and per app. The default, Important actions, reads automatically and asks before things like sending or editing an email, deleting content, uploading, moving or renaming files, changing sharing settings or passing sensitive personal information to an app.

Two other admins may be involved. A Google Workspace admin separately decides whether OpenAI's app is trusted for the Google permissions its actions need, and some Outlook and SharePoint actions need a Microsoft Entra admin to grant permissions for the organisation. That approval doesn't connect anyone's account by itself; each person still signs in. OpenAI's admin controls page has the detail.

Before and after, for an illustrative dry cleaner with five staff on ChatGPT Business. Before: Drive, Gmail and Outlook enabled for everyone, all actions allowed, permission left at Important actions. After: Gmail enabled for the manager role only, read actions only, and Always ask set on Gmail because it's the shared customer inbox; Drive left on for everyone at Important actions, since the shared drive holds only price lists and rotas. Ten minutes of clicking, and the one inbox full of customer addresses and complaint details can no longer be read or answered from ChatGPT without a person approving each step.

An over-shared SharePoint site, and how it surfaced

An illustrative optician's practice connected the SharePoint app for all nine staff so they could ask about policies. The practice's HR site had been shared with an all-staff group years earlier "so people can find the handbook". Nobody remembered that the same site also held sickness records and a disciplinary file.

It surfaced when a receptionist asked ChatGPT to summarise the sickness absence policy and the answer cited a document about a named colleague's case alongside the handbook. ChatGPT hadn't broken any permission: the receptionist's account had been able to open that file all along, and search simply made it findable. The fix was in SharePoint, not ChatGPT: move the handbook to its own site, remove the all-staff group from the HR site, and check who else had access. Cleaning up SharePoint permissions walks through that check, and it applies to ChatGPT's app exactly as it does to Copilot.

A ten-minute check before anyone connects an inbox

Run this for each person before they connect Gmail, Outlook or Drive. Here it is filled in for an illustrative pet shop's manager:

CheckAnswer for the pet shop manager
Which account will connect?The shop's own Google account used by the manager, not the owner's
What can it open?740 Drive files; about 11,200 emails going back several years
Anything in reach that shouldn't be?Three staff sickness notes in Gmail, now moved to the owner's account
Plan and training defaultChatGPT Business, no training on business data by default
Memory during inbox workOff while working through customer emails
Actions allowedRead only
When ChatGPT asksAlways ask, for Gmail
Who reviews connected apps, and how oftenOwner, first Monday of each month
Exit planOn leaving: disconnect the app, delete chats that used inbox data, check saved memories

The monthly review in that table is the easy one to drop, so pair it with the wider check in seeing which apps can access your business accounts. Your Google or Microsoft admin page lists every outside app with access, ChatGPT included, and the removal button sits right beside each one.

Further reads

Sources: OpenAI help pages (Connected apps in ChatGPT; Google Drive app and setup; Google app data controls FAQ; Outlook Email and Calendar apps; SharePoint app and setup; ChatGPT apps with sync; Managing app permissions; Connecting and managing app accounts; Admin controls, security, and compliance for plugins and apps), checked September 2026.

Want ChatGPT's apps connected without over-sharing?

On a 1:1 call we'll check what your team's accounts can reach, decide which apps are worth connecting, and set the admin and permission switches before anyone links an inbox.

Book a 1:1 call with me