# LinkedIn and email access

Whose accounts send, what we ask for, how it is protected, and how to revoke it.

Outreach goes out from your own accounts, because that is what works. Prospects see your name, your email, and your LinkedIn profile. This page explains exactly what access we ask for, how it is protected, and how to take it back.

## Email

Connect the Gmail or Outlook account outreach should come from. This is a standard Google or Microsoft sign in; Starlight never sees your email password. We use the connection to send messages and to read replies to those messages. You can disconnect from Connectors at any time, or from your Google or Microsoft account.

## Calendar

Connect Google Calendar or Outlook Calendar so booked meetings land where you will see them, and so we never offer a time you are busy.

## LinkedIn

LinkedIn has no equivalent sign in for a service like ours, so you share your LinkedIn login with Starlight the same way you would hand it to a consultant running your LinkedIn. You enter it once, in onboarding or later from Connectors, and Spencer signs in to your LinkedIn from his own browser and runs the outreach there.

- Only Spencer uses it. Nobody else at Starlight signs in to your account
- Your login is encrypted the moment you save it and is never shown back in the portal. Spencer reveals it only when he needs to sign in, and every reveal is written to an audit log
- Once he is signed in, the browser session is saved encrypted too, so he does not need to sign in again each time and LinkedIn does not see a new device every week
- Change or revoke access any time from Connectors. Revoking deletes the stored login and session right away. Changing your LinkedIn password has the same effect

## Verification codes

The first time Spencer signs in from a new device, LinkedIn may email you a verification code. If the email comes to the inbox you connected, Spencer can read just that code from his side, so you usually do not have to do anything. If LinkedIn texts you instead, send it the way you agreed at kickoff. It usually happens once.

## Two factor authentication

If you have two factor authentication on your LinkedIn account, pick one of two options in onboarding: turn it off before we go live, or add Spencer's authenticator app to your account. There is a notes field for anything we should know, and both are shown to Spencer alongside your login.

> **Info:** Sending stays within LinkedIn's normal limits for one person. We never sign out of your LinkedIn in the browser, and we never post, comment, or connect on your behalf beyond the outreach we are running for you. The formal wording is in the [Privacy Policy](/privacy).
