OAuth Disclosure
Rosetta Conta uses two separate OAuth flows: a login flow that authenticates who you are, and a mailbox flow that connects an authorized email account for invoice processing. Connecting a mailbox is optional and always initiated by you.
| Provider | Purpose | Scopes | Data accessed | User control |
|---|---|---|---|---|
| Login and Gmail invoice mailbox |
| Invoice-related emails and attachments; send invoice documents (XML, PDF, Hacienda responses). | Disconnect the mailbox from the app or revoke in your Google account. | |
| Microsoft | Login and Outlook/Microsoft 365 invoice mailbox |
| Basic profile; read invoice-related mail; send invoice documents. | Disconnect from the app or revoke in your Microsoft account. |
| Zoho | Zoho Mail invoice mailbox |
| Account identity; read invoice-related messages; send invoice documents. | Disconnect from the app or revoke in your Zoho account. |
Key points
- The login OAuth flow and the mailbox OAuth flow are separate.
- You can disconnect a connected mailbox from within the app at any time.
- The app only operates on accounts you have explicitly authorized.
