Audio By Carbonatix
Google has confirmed that private emails sent and received by Gmail users can sometimes be read by third-party app developers, not just machines.
People who have connected third-party apps to their accounts may have unwittingly given human staff permission to read their messages.
One company told the Wall Street Journal that the practice was "common" and a "dirty secret".
Google indicated that the practice was not against its policies.
One security expert said it was "surprising" that Google allowed it.
Gmail is the world's most popular email service with 1.4 billion users.
Google lets people connect their account to third-party email management tools, or services such as travel planning and price comparisons.
When linking an account to an external service, people are asked to grant certain permissions - which often include the ability to "read, send, delete and manage your email".

According to the Wall Street Journal, this permission sometimes allows employees of third-party apps to read users' emails.
'Not asked permission'
While messages are typically processed by computer algorithms, the newspaper spoke to several companies where employees had read "thousands" of email messages.
Edison Software told the newspaper it had reviewed the emails of hundreds of users to build a new software feature.
Another firm - eDataSource Inc - said engineers had previously reviewed emails to improve its algorithms.
The companies said they had not asked users for specific permission to read their Gmail messages, because the practice was covered by their user agreements.
"You can spend weeks of your life reading terms and conditions," said Prof Alan Woodward from the University of Surrey.
"It might well be mentioned in there, but it's not what you would think of as reasonable, for a human being in a third-party company to be able to read your emails."
Google said only companies that had been vetted could access messages, and only if users had "explicitly granted permission to access email".
It pointed the BBC to its developer policies, which state: "There should be no surprises for Google users: hidden features, services, or actions that are inconsistent with the marketed purpose of your application may lead Google to suspend your ability to access Google API Services."
It said Gmail users could visit the Security Check-up page to see which apps they had linked to their account, and revoke any they no longer wanted to share data with.
Latest Stories
-
Mr President, Ghana was mentioned at the UN; why aren’t we talking about it?
2 hours -
Accra to convene Africa’s regulators and markets on tokenisation at AVAS 2026
2 hours -
The Paradox of Plenty — When every smartphone becomes a newsroom
2 hours -
GTA sensitises taxi drivers in ‘Know Ghana’ tourism campaign
3 hours -
Archbishop Agyinasare calls for responsible speech amid growing social media abuse
4 hours -
‘It will be inexcusable for gov’t not to honour payment of teachers’ arrears by 30th October’ – Haruna Iddrisu
4 hours -
Forbes’ World’s Best Employers 2026: No Ghanaian firm ranked among 900 companies
4 hours -
Electronic processing of teachers’ data: ‘The decision is the Controller’s’ – GES boss
4 hours -
Teachers’ Strike: Haruna Iddrisu questions paper-based processing of promoted teachers’ data
4 hours -
Savannah Region: Kunfusi bridge collapses again, leaving nearly 4,000 residents cut off
4 hours -
Teachers’ strike: GES targets Monday deadline to submit promotion data to Controller
4 hours -
Inflation to average 11.3% in 2027 – Fitch Solutions
5 hours -
‘I didn’t campaign for NDC to come and do this nonsense’ – Kpebu on EOCO’s conduct
5 hours -
Fitch Solutions maintains policy rate forecast of 14% by December 2026
5 hours -
Diaspora Nasara Caucus congratulates Mohammed Ali Suraj, new NPP executives
6 hours