Could they not do this?
Saturday, January 31st, 2009It seems clear to me that it is easy for your IT department to read your email by dumping the tcp traffic from your machine. Unless told otherwise Gmail uses http. Http is not secure or encrypted. You need https for that.
I also believe that it would be very simple to copy the C:\Documents and Settings\\Local Settings\Application Data\Google\Chrome\User Data\Default\Plugin Data\Google Gears\mail.google.com or the C:\Documents and Settings\\Local Settings\Application Data\Mozilla\Firefox\Profiles\74d61f9f.Default User\Google Gears for Firefox\mail.google.com to another machine and open the browser and perform the sync. I may try this later, but I doubt you are prompted for a password. Am I mistaken?
http://www.appscout.com/2009/01/is_it_safe_to_use_gmail_offlin.php