Google Workspace Marketplace Compliance

Privacy Policy & Google API Limited Use Disclosure

Effective Date: October 10, 2026

Mandatory Google API Services User Data Policy (Limited Use Disclosure)

WorkspaceGuard's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, WorkspaceGuard never requests `gmail.readonly` or full mailbox content scopes. We never read, store, index, or transmit email message bodies, subject lines, or attachments, and we never use Google Workspace data for advertising or training AI/ML models.

1. Exact OAuth Scopes Requested & Justification

Google OAuth Scope Strict Purpose & Data Accessed
gmail.settings.basic Reads inbox configuration metadata only (`autoForwarding`, `filters`, `forwardingAddresses`, `delegates`, `pop`, `sendAs`) to detect unauthorized external email forwarding. Cannot read email messages.
gmail.settings.sharing Used only when a Super Admin explicitly clicks "Revoke" to remove an unauthorized forwarding address or inbox delegate.
admin.directory.user Lists organizational users, departments, and suspended status; attaches free email aliases when reclaiming dormant seats.
admin.reports.usage.readonly & audit.readonly Reads last login/activity timestamps and setting-change audit events.
apps.licensing & admin.datatransfer Inspects assigned license SKUs and transfers Drive/Calendar ownership to the user's manager prior to seat reclamation.

2. Data Storage, Encryption & Deletion

All tenant configuration and audit metadata is stored in isolated Google Cloud Firestore collections encrypted at rest (AES-256) and in transit (TLS 1.3). Upon subscription cancellation or request to contact@novabytelab.in, all tenant records are permanently purged within 24 hours.