← Back to home

Google API Services Disclosure

Last Updated: 14 August 2026

This disclosure describes how TravelCS accesses, uses, stores, shares and deletes information received from Google API Services (including Gmail and Google Workspace). It supplements the TravelCS Privacy Policy and applies specifically to data obtained through Google APIs after explicit user authorization.

1. Google API Services Disclosure

TravelCS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2. What Google Data We Access

TravelCS accesses Google Workspace data only after the authenticated user explicitly authorizes the connection through Google's OAuth consent screen. Only the minimum permissions required to deliver the requested functionality are requested.

The categories of Google Workspace data that may be accessed include:

3. Google Permissions Used

The application requests exactly two Gmail scopes, plus one identity scope:

https://www.googleapis.com/auth/gmail.readonly

Used to:

https://www.googleapis.com/auth/gmail.send

Used only when an operator explicitly sends or approves an outgoing email from TravelCS. TravelCS never sends emails automatically.

https://www.googleapis.com/auth/userinfo.email

Used only to identify which Google account was connected, so the connected mailbox address can be displayed in TravelCS settings.

Scopes TravelCS never requests

TravelCS does not request gmail.modify, gmail.compose, gmail.insert, gmail.labels, gmail.metadata, any gmail.settings.* scope, the full-access https://mail.google.com/ scope, or any Google Drive or Google Calendar scope. TravelCS performs no Gmail writes other than sending an operator-approved email.

Sign-in with Google (when used to log in to TravelCS) additionally uses the standard openid, email and profile identity scopes to create or match your TravelCS account. These are identity scopes only and grant no access to Google Workspace data.

3.1 What TravelCS Does With These Permissions

TravelCS performs no Gmail writes other than sending an operator-approved email. It does not change read/unread state or labels, does not create Gmail drafts, does not archive, delete or trash emails, does not manage folders or mailbox organization, and does not access Gmail settings.

Every permission supports functionality that the operator can see and control inside TravelCS.

3.2 Trust & Transparency — Principle of Least Privilege

TravelCS follows the Principle of Least Privilege. Gmail permissions are limited to what is strictly necessary for the Inbox feature, and they are reduced whenever functionality no longer requires broader access. When a scope stops being needed, it is removed from the consent request rather than kept "just in case". Connections that Google grants only partially are rejected at connect time instead of being silently downgraded.

4. Artificial Intelligence

5. What We Never Do

6. Limited Use Compliance

Google Workspace data obtained through Google APIs is used exclusively to provide user-facing functionality requested by the authenticated user. TravelCS complies with Google's Limited Use requirements: data is not sold, not shared with advertisers, and not transferred to third parties except to the sub-processors strictly required to operate the requested feature, or where required by law.

7. Data Sharing

Google Workspace data is processed only by the trusted infrastructure providers required to operate TravelCS — cloud hosting, authentication, secure database infrastructure and backups — each bound by a written data-processing agreement. The current list is published at /sub-processors. Google Workspace data is never sold and never shared with advertisers.

8. Data Retention

Google Workspace data is retained only while required to provide the requested services. Users may at any time:

Revoking TravelCS's access, either inside TravelCS or from your Google Account, stops all further access to your Google Workspace data and removes the stored authorization credentials. It does not by itself delete Gmail content already imported into your TravelCS workspace; that content stays in your conversation history until the workspace is deleted or you request its deletion. When a workspace is deleted, its data is removed from our live systems and a recovery backup is retained for the documented restore window (see /retention) before being permanently purged, unless a longer period is legally required.

9. Security

10. Contact

For privacy questions, Google API questions, or data deletion requests:


This disclosure supplements the TravelCS Privacy Policy and applies specifically to information received through Google API Services.