Point does not have the password to your mailbox. It was never asked for and it is not held. What Point holds is a grant you made at your provider’s own sign-in: a key issued in Point’s name, bounded by what you allowed, kept in a guarded store, and yours to cancel from outside Point entirely.
- The thing most people picture, a password sitting in somebody’s database, is not what happened. A mailbox is connected by authorising it, not by handing the password over.
- What does exist is a grant with a name on it, a list of what it covers, and an end. Those three properties are the whole subject.
- It is the only control in this collection whose off switch sits outside Point, in a provider account you had before any of this.
- Cancelling it stops everything after that moment and reaches nothing before it, which is a different question from what can be put back.
The password nobody asked you for
Ask where your credentials are kept and the picture behind the question is usually a password, sitting in a file on a server belonging to a company you met last month. It is a reasonable thing to worry about. It is also not what happened when you connected your mailbox.
The connection is made on your provider’s own sign-in page, the one you have seen a thousand times, and the password goes where it always goes. Nothing about that step involves typing it into Point. What comes back to Point afterwards is a different object altogether: an authorisation, issued because you asked your provider to issue it.
That distinction earns its place because of what a password actually is. It is a universal key. It has no name on it, so anything holding it is indistinguishable from you. It has no list attached, so it covers everything the account can do rather than the part you meant. And it has no end, so taking it back means changing it, which breaks your phone, your accountant’s portal and every other thing that had it, all in the same afternoon. Handing one to a piece of software gives away all three of those properties at once.
Which gives a test worth carrying around, and it costs nothing to apply. A product that wants your mailbox password typed into a form of its own is asking for the universal key, and it is asking for it to do a job a grant would have done more narrowly. There is no version of that trade where you come out ahead.
It also explains a message that sends a lot of people looking for this page in the first place. When something tells you the correct credentials are needed for your email, the trouble is rarely a forgotten password. It is almost always a grant that has lapsed, and the answer is to authorise again rather than to remember something.
What a grant actually says
Three things, and each of them is what a password is not.
A name. The authorisation is issued to Point specifically. Your provider knows which of its keys is which, and so do you, because your account lists them by the company they were issued to. That named quality is also why a separate account of what your assistant did is possible at all, though which record answers which question is the activity log behind every action rather than anything settled here.
A list. A grant covers named things: reading your mail, writing to it, seeing your calendar, sending on your behalf. It is bounded by that list rather than by good intentions, and the screen where the list is shown to you at the moment of connecting is the one point in this whole arrangement where a boundary is being set by you instead of described to you afterwards. Almost nobody reads it. It is the shortest piece of reading with the largest reach in the entire setup.
An end. A grant can lapse on its own, and it can be withdrawn by you without disturbing anything else you own. Nothing has to be changed, reissued or told to everyone. The thing simply stops working, for one company, on purpose.
Worth being plain about the size of this, because it is the largest permission anywhere in this collection and it was the first one you gave. Every dial position, every held action and every row in the record operates inside it. None of those settings can reach past the edge the grant drew, and none of them widened it. What the grant decides is what is possible. What the settings decide is how much of that gets used, and mixing the two is the most common misreading on this subject, in both directions at once: some people expect the connection by itself to hold Point back, and others expect it to have handed everything over already.
Where the key is held
On Point’s side, in a store built for the purpose rather than in a configuration file somebody forgot about. Point’s own description of it is that the connections to your email are kept under lock, not left lying around where they could leak, and the security section of the privacy policy names the measures around them: encryption in transit and at rest where supported, least privilege, access controls, credential and token handling controls, and limits on which humans can reach anything at all.
One figure there is load-bearing and worth reading closely. Point’s privacy policy, checked 19 August 2026, puts the retention of connected-account tokens at until the account is disconnected, the authorisation expires, the account is deleted, or security or law requires otherwise. What that is evidence of is more useful than the sentence itself: the life of the key is pinned to the life of the connection. It is not sitting on a retention schedule that outlives your relationship with the company, and ending the connection is the same act as ending the reason to keep it.
Past that, though, the honest answer is that “where” stops being something you can read off a screen. Which region, whose cloud, who inside the company could reach the store on a bad day, and what you would be told and when if any of it went wrong are questions for a supplier rather than for a settings page. They deserve asking in as many words, and questions to ask any AI tool about your data is the list to put, along with what to accept as an answer.
Here is why that unanswered part does not have to hold you up, and it is the argument this page exists to make. You are not being asked to settle the storage question in order to hold the control, because the control is not in the store.
The one switch that is not in Point
Look at the rest of this collection and notice what every control has in common. The dial, the queue of things waiting on your yes, the record of what happened, the line between two businesses, the button that puts something back. All of them are Point’s own surfaces. Each works because Point works, and each is available to you on the condition that you can sign in and that the company is having a normal day.
The grant is not like that. It lives in the provider account you had before Point existed, it is listed there beside every other key you have ever issued, and you can cancel it there. No signing into Point, nobody to ask, no cooperation required from the company whose access you are ending. The same job can be done from inside Point by disconnecting the account, which is often the more convenient handle, but the point is that there are two handles and only one of them belongs to the vendor.
That asymmetry is the whole reason to understand this rather than merely to be reassured about it. A control you can only use with a company’s cooperation is a promise, and a promise is worth precisely what the company is worth. A control you hold from outside is a fact, and it stays a fact on the day you have stopped believing the promise. Everything else on this page is Point describing its own behaviour, which you are entitled to weigh exactly as sceptically as you weigh any vendor describing itself. This one you can go and look at today, in an account of your own, and see the entry with Point’s name on it sitting there.
What cancelling does is end the capability, cleanly and from that moment. Nothing further is read, sorted, drafted, scheduled or sent, because there is no longer a door. What it does not do is travel backwards, and the instrument for that is a different one with its own limits, set out in undoing what Point did.
The other credential
There are two keys in play and they are different objects, which is worth ten minutes now and saves a confused hour later.
One is the grant on your mailbox. The other is how you get into Point at all, and that one is not a password either: a link arrives at your address and lets you in, so there is no second password for anyone on your team to manage, reuse or lose. Two doors, and neither of them is guarded by something you have to invent and remember.
The exact part matters more than the reassuring part. Someone who got into your Point account would be inside Point. They could see what Point sees and act through the surfaces Point offers, at whatever the settings for each kind of work happen to be. What they would not come away with is the password to your mailbox, because it is not there to take, and they could not carry the connection off to use somewhere else, because a grant is issued to a company rather than typed into one. “They cannot get my password” and “they could not do anything” are two sentences, and only the first is true.
Which gives the response its shape, if it ever happens. Cancel the grant from the provider side, where the switch does not depend on the compromised account, and then read what was done from the record. Both halves are necessary, and the second is the activity log behind every action.
Where a connection stops
It does not decide how far Point goes. A fully connected mailbox with every kind of work sitting at review is a mailbox where things get prepared and then wait for you. Out of the box that is where the settings are. Capability and autonomy are separate questions, and the second is setting how much your inbox does on its own.
It does not reach backwards. Withdrawing access ends what happens next. The work already done stays done and its record stays with it, and taking one action back is a narrower thing that runs out where a message has already reached somebody else’s server.
It is one mailbox, in one business. A second business you operate connects its own mailbox under its own grant, and neither one inherits the other. The same line runs through every other control on this page, and it is drawn in keeping one business isolated from another.
It is not a record. A grant says what is permitted. It says nothing whatsoever about what was done, and reading a live connection as evidence of activity, or an absent one as evidence of none, gets both jobs wrong.
It is not an answer about the company. Storage, regions, subprocessors, deletion, breach notice and what happens to any of it when you leave are answered by a supplier in writing, not by anything you can see while connecting.
None of this is an argument for connecting anything. If what brought you here is that putting a tool on your mailbox still feels like a step too far, why Point never needs your email password covers the same ground from the worried end rather than the reference end. What Point does once a mailbox is connected, feature by feature, sits on the benefits page.
Common questions
Does Point need my Gmail password?
No. The connection is made at Google’s own sign-in, where the password stays and where it has always stayed, and what returns to Point is a grant in Point’s name covering the things you allowed. The reason to care about that distinction rather than just accepting the reassurance is the difference in shape: a password is one universal key with no name, no list and no end, so anything holding it can do everything, indefinitely, and is indistinguishable from you while doing it. A grant fails all three of those tests on purpose.
Something told me the correct credentials are needed for my email. What does that actually mean?
Almost always that a grant has lapsed rather than that a password is wrong, which is why trying to remember a password gets you nowhere. Authorisations expire, get withdrawn, or stop covering something they used to, and the fix for all three is the same: authorise again at your provider and a fresh grant is issued, with the password untouched throughout. One caution that follows from everything above. If a message of that kind arrives as an email carrying a link, treat the link as you would any other, because a sentence about credentials needing attention is a phishing favourite for exactly the reason this page opens with, which is that most people picture a password and hurry.
Where exactly are my credentials stored?
In a guarded store on Point’s side, kept for as long as the connection lives. Point’s privacy policy, checked 19 August 2026, puts the retention of connected-account tokens at until the account is disconnected, the authorisation expires, the account is deleted, or security or law requires it, and names token handling controls, least privilege and encryption at rest where supported among the measures around them. Past that, “exactly” becomes a question for the company rather than something visible to you, and the reason it does not have to be settled before you connect is that the thing being stored is a bounded grant you can cancel from outside rather than a password you would have to change.
If I disconnect, does Point lose everything it already did?
No, and separating the two halves is the useful part. Withdrawing access ends the capability from that moment, so nothing further is read, drafted or sent. What happened while the grant was live still happened, and the record of it is still the account of your inbox for that period. Putting one particular action back is a different instrument with a different reach, which is undoing what Point did, and no cancellation reaches into somebody else’s mail server to retrieve a message that has already landed there.
Do I have to connect each business separately?
Yes, and the second one is a decision you make rather than a gap somebody left in the design. A grant is made for one mailbox, and a mailbox sits inside one of the businesses you operate, so the second business is authorised deliberately or it is not authorised at all. Nothing you allowed in the practice is allowed in the property company, which is exactly what you would want the day you sold one of them: ending a grant on one side leaves the other side untouched, because they were never the same key.
The short version
The word credentials makes people picture a password, and the password is the one thing that never left your provider. What exists instead is a grant: issued in Point’s name, bounded by a list you were shown, kept under lock while the connection lasts, and endable by you from either side. That grant sets the outer edge of what is possible, and the settings inside Point decide how much of it gets used, which are two questions people routinely merge into one. Its best property is not where it is stored. It is that the switch sits in an account of your own, so this is the one control here that does not rest on anybody’s word. Point is what you would be connecting to.