An app wants your email password so it can do something useful — print your orders, back up your mail, file your invoices. And you hesitate, because your email account is the master key to everything else you own.
You are right to hesitate. Here is what you are actually being asked for, what it does and does not allow, and the questions worth asking before you type anything.
What an app password is, and is not
If your provider is any of the major ones, you will not be handing over your real password. You will generate an app password — a separate, randomly generated credential that exists alongside your real one.
What it grants: the ability to sign in to your mailbox and read mail, as that app.
What it does not grant, and this is the part worth internalising:
- It cannot change your account password, or your recovery phone, or your security settings.
- It cannot be used to log in to the website. Try it and it fails.
- It does not unlock anything else connected to that account — no documents, no photos, no other services.
- You can revoke it on its own, at any time, without changing your real password or disturbing anything else you use.
That last point is the important one. An app password is revocable in a way your real password is not. Handing an app a password you can cancel in ten seconds is a genuinely different risk from handing it the keys.
The question that actually matters
Not “is this app trustworthy”. You cannot verify that. The useful question is narrower and answerable:
Where does the password go?
There are two architectures, and the difference is not a detail.
The app sends it to a server. The company’s system signs into your mailbox on your behalf, usually so it can keep working while your device is off. Your credential now lives on their infrastructure. That may be perfectly well run — but you are trusting their storage, their staff, their backups and their breach response, not just their app.
The app keeps it on your device. The password stays in your phone’s encrypted storage and is used from your phone to talk to your mailbox directly. There is no copy anywhere else, because there is nowhere else.
Both can be honest. But they fail differently: the first has a single place where a breach exposes many people’s mailboxes at once, and the second does not. When a company is breached, it is the accumulated credentials that make the news.
Five questions to ask any app that wants mailbox access
- Is there a server involved at all? If there is no account to create, that is a strong hint the answer is no. An app that never asks you to sign up has nowhere to store your data.
- Does it ask for an app password, or your real one? An app that insists on your actual account password either has not thought about this or does not care. Both are reasons to walk away.
- What does its privacy policy say it collects? Not the reassuring summary — the list. If the list is long for an app that only needs to read one mailbox, ask why.
- What happens when you uninstall it? If everything it held was on your device, uninstalling ends the relationship. If it was on a server, uninstalling may change nothing at all.
- Can you revoke access without disrupting everything else? With an app password, yes, always. That is the safety net.
Two things you can do that cost nothing
Use a mailbox that only receives orders. Point your shop’s notifications at an address used for nothing else and give the app that one. Now the worst case is not “someone read my email” but “someone saw my order confirmations” — which are, in most shops, less sensitive than the rest of your inbox by a wide margin. It also makes revoking trivial: delete the mailbox and you are done.
Write down what you gave access to. App passwords accumulate silently. Every provider has a page listing the ones you have generated, and most people have several from apps they stopped using years ago. Have a look at yours — it takes two minutes and it is usually a bit revealing.
Where we stand
We build OrderPrint, so treat this as the interested party’s answer.
There is no OrderPrint server. Not “we don’t look at your data” — there is nowhere to look. Your email address, your app password and your customers’ orders stay on your phone. The password sits in Android’s encrypted storage and is used for exactly one thing: signing in to your mailbox to read new orders. There is no account to create, no analytics, no adverts, no tracking.
That is not generosity. It is the consequence of a design decision made early: on-device polling meant no infrastructure to run, no hosting bill, and no ops — and it happens to mean that the question “what if you get breached” has an unusually short answer.
It has a real trade-off, and we should say it. Because everything runs on your phone, the phone has to be on. There is no server quietly catching orders while it is charging in a drawer. Cloud-based competitors genuinely beat us on that, and if it matters more to you than where your credentials live, they are the better choice.
That trade is the whole design. We think it is the right one for a shop with a phone by the till. It is worth knowing it exists rather than discovering it later.
Our full privacy terms are on the terms and privacy page, and the app-password walkthrough for each provider is on the help page.
