Google API Services User Data

Google API data and AI Limited Use disclosure

Last updated: August 12, 2026. This public notice supplements the PALINGA privacy policy and describes the maximum user-facing use of every Google authorization requested by the production application.

Affirmative Limited Use statement

PALINGA’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google Data Manager is not enabled in the production consent flow and PALINGA does not request the datamanager scope while provider eligibility remains pending. Its isolated integration can be activated only after external approval and a complete production demonstration are available.

Authoritative production OAuth scope manifest

PALINGA uses incremental authorization: each consent transaction requests only the products and access level explicitly selected by the user. The Google Cloud project is configured with the union of the exact strings below so every production request remains an exact subset of the reviewed scope set.

  • Google identityopenid
  • Google identityemail
  • Google identityprofile
  • Gmailhttps://www.googleapis.com/auth/gmail.send
  • Google Calendarhttps://www.googleapis.com/auth/calendar.events
  • Google Adshttps://www.googleapis.com/auth/adwords
  • Merchant Centerhttps://www.googleapis.com/auth/content
  • Google Business Profilehttps://www.googleapis.com/auth/business.manage
  • Google Analytics 4https://www.googleapis.com/auth/analytics.readonly
  • Google Analytics 4https://www.googleapis.com/auth/analytics.edit
  • Google Tag Managerhttps://www.googleapis.com/auth/tagmanager.readonly
  • Google Tag Managerhttps://www.googleapis.com/auth/tagmanager.edit.containers
  • Google Tag Managerhttps://www.googleapis.com/auth/tagmanager.edit.containerversions
  • Google Tag Managerhttps://www.googleapis.com/auth/tagmanager.publish
  • Google Search Consolehttps://www.googleapis.com/auth/webmasters.readonly
  • Google Search Consolehttps://www.googleapis.com/auth/webmasters
  • YouTubehttps://www.googleapis.com/auth/youtube.readonly
  • YouTube Analyticshttps://www.googleapis.com/auth/yt-analytics.readonly
  • YouTubehttps://www.googleapis.com/auth/youtube.upload
  • YouTubehttps://www.googleapis.com/auth/youtube.force-ssl

Explicitly excluded from production authorization:

  • https://www.googleapis.com/auth/datamanager
  • https://www.googleapis.com/auth/tagmanager.manage.users
  • https://www.googleapis.com/auth/gmail.modify
  • https://www.googleapis.com/auth/gmail.readonly

Google services and least-privilege purpose

Gmail

gmail.send

Send only the email explicitly composed or triggered by the user. PALINGA does not read or synchronize Gmail mailboxes.

Google Calendar

calendar.events

Display accessible calendars and events and create or update only the events explicitly managed by the user in PALINGA.

Google Ads

adwords

Read campaign performance and change an enabled/paused campaign after independent approval.

Merchant Center

content

Read Merchant inventory and issues and manage bounded product sources, offers, promotions, and ingestion requested by the user.

Google Business Profile

business.manage

Read locations, reviews, posts, media, attributes and performance; perform an approved visible mutation and read the result back from Google.

Google Analytics 4

analytics.readonly · analytics.edit

Read reports and Admin inventory; create or delete an explicitly selected custom key event and read the result back.

Google Tag Manager

tagmanager.readonly · tagmanager.edit.containers · tagmanager.edit.containerversions · tagmanager.publish

Read containers and workspaces; create bounded ecommerce resources and versions; preview or publish an explicitly confirmed audited release. PALINGA does not request tagmanager.manage.users.

Google Search Console

webmasters.readonly · webmasters

Read properties, performance and sitemaps; submit or delete an explicitly selected sitemap and read the provider state back.

YouTube

youtube.readonly · yt-analytics.readonly · youtube.upload · youtube.force-ssl

Read channel inventory and analytics; upload user-selected videos; manage playlists, metadata, thumbnails and comments after preflight and confirmation.

AI provider and data controls

Provider and plan: OpenAI API Platform, paid pay-as-you-go organization and project. PALINGA does not use a consumer ChatGPT Free, Plus, Pro, Business, Enterprise or Edu workspace to process application data.

No model hub: PALINGA does not use an AI aggregator, multi-model gateway, or downstream model hub for Google Workspace or Photos data.

Workspace-interacting model: gpt-5.4-mini, called directly through the OpenAI Responses API, is the only configured model on application routes that can receive explicitly requested Google Calendar context. PALINGA does not read Gmail mailbox content; the Gmail integration is outbound-only.

Other isolated OpenAI models: gpt-5.6-luna, gpt-5, gpt-5-mini, gpt-4.1-mini, gpt-image-2, and gpt-4o-mini-transcribe support non-Workspace product features and do not receive Google Workspace or Google Photos API payloads.

No generalized training: PALINGA does not create, train, or improve a foundational or generalized AI/ML model with raw, aggregated, anonymized, or derived Google user data. PALINGA does not opt in to provider model-training data sharing.

Request storage: PALINGA enforces store=false on OpenAI text requests, including when a caller attempts to request storage. Standard API abuse-monitoring retention may still apply under the provider’s terms. PALINGA does not claim Zero Data Retention unless it has been separately approved and contractually activated.

Minimization and telemetry: Google Workspace information is transmitted only when the user explicitly requests an AI feature that needs it, and only to the extent necessary for that feature. Usage telemetry contains model, token counts, duration, status, tenant and correlation identifiers; it excludes prompts, messages, request bodies, content, outputs and responses.

Photos: PALINGA does not request Google Photos API scopes.

Provider policy verification: OpenAI states that API Platform inputs and outputs are not used to train its models by default unless the organization explicitly opts in. See the OpenAI enterprise privacy commitments and OpenAI API data controls.

Users can disconnect a Google integration in PALINGA and revoke it from their Google Account at any time. For access or deletion requests, contact contact@palinga.com.

See also the PALINGA privacy policy and data deletion instructions.