Gmail
gmail.send
Send only the email explicitly composed or triggered by the user. PALINGA does not read or synchronize Gmail mailboxes.
Google API Services User Data
Last updated: September 7, 2026. This app-specific privacy policy supplements the PALINGA general privacy policy and describes how the production application accesses, uses, stores, protects, shares, retains and deletes Google API user data.
PALINGA’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Google Data Manager is not enabled in the production consent flow and PALINGA does not request the datamanager scope while provider eligibility remains pending. Its isolated integration can be activated only after external approval and a complete production demonstration are available.
PALINGA uses incremental authorization: each consent transaction requests only the products and access level explicitly selected by the user. The Google Cloud project is configured with the union of the exact strings below so every production request remains an exact subset of the reviewed scope set.
openidemailprofilehttps://www.googleapis.com/auth/gmail.sendhttps://www.googleapis.com/auth/calendar.eventshttps://www.googleapis.com/auth/adwordshttps://www.googleapis.com/auth/contenthttps://www.googleapis.com/auth/business.managehttps://www.googleapis.com/auth/analytics.readonlyhttps://www.googleapis.com/auth/analytics.edithttps://www.googleapis.com/auth/tagmanager.readonlyhttps://www.googleapis.com/auth/tagmanager.edit.containershttps://www.googleapis.com/auth/tagmanager.edit.containerversionshttps://www.googleapis.com/auth/tagmanager.publishhttps://www.googleapis.com/auth/webmasters.readonlyhttps://www.googleapis.com/auth/webmastershttps://www.googleapis.com/auth/youtube.readonlyhttps://www.googleapis.com/auth/yt-analytics.readonlyhttps://www.googleapis.com/auth/youtube.uploadhttps://www.googleapis.com/auth/youtube.force-sslExplicitly excluded from production authorization:
https://www.googleapis.com/auth/datamanagerhttps://www.googleapis.com/auth/tagmanager.manage.usershttps://www.googleapis.com/auth/gmail.modifyhttps://www.googleapis.com/auth/gmail.readonlygmail.send
Send only the email explicitly composed or triggered by the user. PALINGA does not read or synchronize Gmail mailboxes.
calendar.events
Display accessible calendars and events and create or update only the events explicitly managed by the user in PALINGA.
adwords
Read campaign performance and change an enabled/paused campaign after independent approval.
content
Read Merchant inventory and issues and manage bounded product sources, offers, promotions, and ingestion requested by the user.
business.manage
Read locations, reviews, posts, media, attributes and performance; perform an approved visible mutation and read the result back from Google.
analytics.readonly · analytics.edit
Read reports and Admin inventory; create or delete an explicitly selected custom key event and read the result back.
tagmanager.readonly · tagmanager.edit.containers · tagmanager.edit.containerversions · tagmanager.publish
Read containers and workspaces; create bounded ecommerce resources and versions; preview or publish an explicitly confirmed audited release. PALINGA does not request tagmanager.manage.users.
webmasters.readonly · webmasters
Read properties, performance and sitemaps; submit or delete an explicitly selected sitemap and read the provider state back.
youtube.readonly · yt-analytics.readonly · youtube.upload · youtube.force-ssl
Read channel inventory and analytics; upload user-selected videos; manage playlists, metadata, thumbnails and comments after preflight and confirmation.
https://www.googleapis.com/auth/youtube.readonly
PALINGA uses this scope to identify and display the YouTube channel selected by the user and to read its provider-owned inventory, including channel, video, playlist and comment identifiers and metadata needed by the visible social-account and publishing interfaces. PALINGA also reads the affected resource back from YouTube after a confirmed operation so the user can verify the resulting provider state. This scope is never used to modify YouTube data.
https://www.googleapis.com/auth/youtube.force-ssl
PALINGA uses this scope only when an authorized user requests a visible YouTube management action. Supported actions include managing playlists and playlist items, updating user-selected video metadata or thumbnails, moderating a selected comment, and permanently deleting a selected video after an additional explicit confirmation. PALINGA shows a preflight of the intended change, records auditable evidence, executes only the confirmed action and reloads the provider state. It does not perform undisclosed or background YouTube mutations.
Encryption in transit and at rest: PALINGA requires HTTPS and TLS for communications between users, PALINGA and Google APIs. Production databases and backups are encrypted at rest. OAuth access and refresh tokens receive an additional application-level AES-256-GCM authenticated encryption layer before they are stored.
Secret protection: OAuth client secrets and token-encryption keys are held outside source code in restricted production secret storage. Raw OAuth tokens are not returned by PALINGA APIs, displayed in the user interface or included in application audit records.
Access control and tenant isolation: Google connections and synchronized records are isolated by PALINGA tenant. Authenticated role and permission checks restrict access to authorized users and to the specific connected account. Administrative access is limited by least privilege, logged and reserved for the support, security or legal cases described in the PALINGA privacy policy.
Minimization and monitored operations: PALINGA requests only the scopes required for the Google product and access level selected by the user. Sensitive YouTube writes require a visible user action, a provider-state preflight and audit evidence; destructive video deletion requires an additional confirmation phrase. Security and operational logs exclude OAuth credentials and are used to detect and investigate failures or unauthorized activity.
No sale or advertising disclosure: PALINGA does not sell, rent or disclose Google user data to data brokers, information resellers, advertising networks or other third parties for targeted, personalized, retargeted or interest-based advertising, creditworthiness, lending, or generalized AI/ML model training.
Authorized tenant users: Google user data is displayed only to authenticated users of the same PALINGA tenant who have the permissions required for the connected Google account and feature. A tenant administrator may manage the connection under the tenant's role and access-control rules.
Google: PALINGA sends data to the applicable Google API only to authenticate the connection, retrieve the user-selected resources, execute the user-requested operation and verify the resulting Google account state.
Amazon Web Services: PALINGA uses Amazon Web Services as its production infrastructure processor for application hosting, encrypted storage, backups, networking, secret storage, monitoring and security operations. AWS processes Google user data only to provide this infrastructure to PALINGA and not for its own advertising or model-training purposes.
OpenAI API Platform: PALINGA may transfer only the minimum Google Calendar context required when a user explicitly invokes a PALINGA AI feature that needs that context. PALINGA does not transfer OAuth credentials, Gmail mailbox content, or Google Ads, Merchant Center, Analytics, Tag Manager, Search Console, Business Profile or YouTube payloads to OpenAI. Requests use the paid API Platform with store=false; PALINGA does not opt in to model-training data sharing.
PALINGA personnel and legal disclosures: Access by PALINGA support, security or operations personnel is limited to personnel with a documented need, least-privilege access and audit logging. PALINGA may disclose data to a competent authority only when required by applicable law or a binding legal process, or when necessary to protect users, the service or the public from fraud, abuse or security threats.
No other recipients: PALINGA does not share, transfer or disclose Google user data to any other third party except with the user's explicit consent or when necessary to provide or improve the user-facing feature the user requested, subject to the Google API Services User Data Policy and its Limited Use requirements.
PALINGA stores encrypted OAuth tokens and the minimum connection identifiers, selected resource metadata and audit evidence needed to maintain the connection, provide the requested user-facing features, secure the service and demonstrate authorized actions. Google provider content is fetched only for the connected tenant and is not used to build unrelated databases, advertising profiles or generalized AI models.
Google connection data is retained only while needed for the active integration and under the tenant's applicable retention settings, except where security evidence or law requires a longer period. Disconnecting the integration stops new Google API access and removes the active local token references; the user can also revoke PALINGA directly from their Google Account. Users may request deletion of associated PALINGA data at contact@palinga.com or follow the data deletion instructions.
Provider and plan: OpenAI API Platform, paid pay-as-you-go organization and project. PALINGA does not use a consumer ChatGPT Free, Plus, Pro, Business, Enterprise or Edu workspace to process application data.
No model hub: PALINGA does not use an AI aggregator, multi-model gateway, or downstream model hub for Google Workspace or Photos data.
Workspace-interacting model: gpt-5.4-mini, called directly through the OpenAI Responses API, is the only configured model on application routes that can receive explicitly requested Google Calendar context. PALINGA does not read Gmail mailbox content; the Gmail integration is outbound-only.
Other isolated OpenAI models: gpt-5.6-luna, gpt-5, gpt-5-mini, gpt-4.1-mini, gpt-image-2, and gpt-4o-mini-transcribe support non-Workspace product features and do not receive Google Workspace or Google Photos API payloads.
No generalized training: PALINGA does not create, train, or improve a foundational or generalized AI/ML model with raw, aggregated, anonymized, or derived Google user data. PALINGA does not opt in to provider model-training data sharing.
Request storage: PALINGA enforces store=false on OpenAI text requests, including when a caller attempts to request storage. Standard API abuse-monitoring retention may still apply under the provider’s terms. PALINGA does not claim Zero Data Retention unless it has been separately approved and contractually activated.
Minimization and telemetry: Google Workspace information is transmitted only when the user explicitly requests an AI feature that needs it, and only to the extent necessary for that feature. Usage telemetry contains model, token counts, duration, status, tenant and correlation identifiers; it excludes prompts, messages, request bodies, content, outputs and responses.
Photos: PALINGA does not request Google Photos API scopes.
Provider policy verification: OpenAI states that API Platform inputs and outputs are not used to train its models by default unless the organization explicitly opts in. See the OpenAI enterprise privacy commitments and OpenAI API data controls.
Users can disconnect a Google integration in PALINGA and revoke it from their Google Account at any time. For access or deletion requests, contact contact@palinga.com.
See also the PALINGA privacy policy and data deletion instructions.