Klaviyo data and permissions reference
See exactly which Klaviyo data Email Donut reads, which assets it can create, and which permissions are explicitly excluded.
Email Donut requests 20 of the 42 Klaviyo permissions considered for the integration. The permission set is limited to a named reporting, analysis, audience-context, brand-asset, content-creation, targeting, or scheduling capability.
New capabilities that need additional permissions require reauthorization. Existing Klaviyo installations keep their previously granted access until they reconnect.

Read permissions
Email Donut requests 14 read permissions:

- accounts:read — Identify the connected account and use plan or usage context for cost analysis.
- campaigns:read — Read email and SMS campaign performance.
- catalogs:read — Use product information in reports and generated content.
- events:read — Analyze orders and engagement for retention, lifetime value, cohorts, and product journeys.
- flows:read — Read flow configuration and performance.
- forms:read — Measure signup-form performance and list growth.
- images:read — Reuse existing brand assets in generated email content.
- lists:read — Measure list growth and let users choose an audience.
- metrics:read — Find conversion metrics and run performance aggregates.
- profiles:read — Add audience context to events and reporting.
- segments:read — Measure segment reach and audience size.
- subscriptions:read — Read consent state for reach and SMS compliance analysis.
- tags:read — Match the account's existing Klaviyo tag taxonomy.
- templates:read — Learn from existing templates and match brand styling.
Read access lets Email Donut analyze and present data. It does not permit Email Donut to edit the underlying Klaviyo records.
Write permissions
Email Donut requests 6 write permissions for content creation, targeting, and scheduling workflows that are shipped or being built:
- campaigns:write — Create and schedule campaigns. Klaviyo does not provide a separate scheduling permission.
- flows:write — Build and update flows created through Email Donut workflows.
- images:write — Upload creative used by generated emails.
- segments:write — Create targeting and Email Reach segments.
- tags:write — Keep campaigns and flows created by Email Donut organized and findable.
- templates:write — Save generated email content as a Klaviyo template.
A granted permission defines the maximum operation Klaviyo will allow; it does not mean Email Donut performs every possible operation in that category. For example, the current template integration creates a new, non-sending draft template and does not update or delete an existing Klaviyo template.
Explicitly excluded permissions
Email Donut does not request the following 22 permissions:
- profiles:write
- coupons:read and coupons:write
- coupon-codes:read and coupon-codes:write
- forms:write
- lists:write
- metrics:write
- events:write
- catalogs:write
- subscriptions:write
- data-privacy:read and data-privacy:write
- tracking-settings:read and tracking-settings:write
- conversations:read and conversations:write
- push-tokens:read and push-tokens:write
- web-feeds:read and web-feeds:write
- reviews:read

Actions Email Donut never takes
- Email Donut never changes a person's consent or subscription state.
- Email Donut never handles or modifies deletion or data-privacy requests.
- Email Donut never alters the Klaviyo account's tracking settings.
Data synchronized to Email Donut
The connection is scoped to an Email Donut brand. During setup, Email Donut stores the connected Klaviyo account identity, the granted scope list, available metrics, the selected revenue metric, and the date the connection was updated.
Email Donut imports campaign metadata and performance for reporting and content analysis. Campaign history can look back up to 25 months. Order and engagement events are prepared for retention, lifetime-value, cohort, customer-segment, and product-journey reports. Older order history may continue importing after recent report data becomes available.
Campaign, flow, reach, and event data are refreshed on scheduled background jobs so reports can stay current without a manual export. The settings and report pages show when data is preparing, available, or needs the Klaviyo account to be reconnected.

Authorization rules
Klaviyo grants the intersection of two lists: the permissions Email Donut requests during OAuth and the permissions enabled for Email Donut in Klaviyo's developer configuration. A permission present in only one list is not granted.

Email Donut checks for the core permissions required to complete setup. If Klaviyo does not grant them, setup stops and asks the user to reconnect after the app configuration is corrected.