← Back to home

Google API Services Disclosure

Last Updated: 27 July 2026

This disclosure describes how TravelCS accesses, uses, stores, shares and deletes information received from Google API Services (including Gmail and Google Workspace). It supplements the TravelCS Privacy Policy and applies specifically to data obtained through Google APIs after explicit user authorization.

1. Google API Services Disclosure

TravelCS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

2. What Google Data We Access

TravelCS accesses Google Workspace data only after the authenticated user explicitly authorizes the connection through Google's OAuth consent screen. Only the minimum permissions required to deliver the requested functionality are requested.

The categories of Google Workspace data that may be accessed include:

3. Gmail Permissions Used

The application requests exactly three Gmail scopes:

https://www.googleapis.com/auth/gmail.readonly

Used to:

https://www.googleapis.com/auth/gmail.send

Used only when an operator explicitly sends or approves an outgoing email from TravelCS. TravelCS never sends emails automatically.

https://www.googleapis.com/auth/gmail.modify

Used only after a successful reply has been sent. TravelCS removes the Gmail UNREAD label from that specific thread so Gmail reflects that the conversation has already been handled. No other mailbox modifications are performed.

TravelCS does not request gmail.compose, gmail.insert, gmail.labels, gmail.metadata or any gmail.settings.* scope.

3.1 What TravelCS Does With These Permissions

TravelCS does not create Gmail drafts, archive emails, delete emails, move emails to Trash, apply custom Gmail labels, manage folders, modify mailbox organization, or access Gmail settings.

Every permission supports functionality that the operator can see and control inside TravelCS.

3.2 Trust & Transparency — Principle of Least Privilege

TravelCS follows the Principle of Least Privilege. Gmail permissions are limited to what is strictly necessary for the Inbox feature, and they are reduced whenever functionality no longer requires broader access. When a scope stops being needed, it is removed from the consent request rather than kept "just in case". Connections that Google grants only partially are rejected at connect time instead of being silently downgraded.

4. Artificial Intelligence

5. What We Never Do

6. Limited Use Compliance

Google Workspace data obtained through Google APIs is used exclusively to provide user-facing functionality requested by the authenticated user. TravelCS complies with Google's Limited Use requirements: data is not sold, not shared with advertisers, and not transferred to third parties except to the sub-processors strictly required to operate the requested feature, or where required by law.

7. Data Sharing

Google Workspace data is processed only by the trusted infrastructure providers required to operate TravelCS — cloud hosting, authentication, secure database infrastructure and backups — each bound by a written data-processing agreement. The current list is published at /sub-processors. Google Workspace data is never sold and never shared with advertisers.

8. Data Retention

Google Workspace data is retained only while required to provide the requested services. Users may at any time:

Upon account deletion or revocation of access, Google Workspace data is permanently removed according to TravelCS retention policies, unless retention is legally required.

9. Security

10. Contact

For privacy questions, Google API questions, or data deletion requests:


This disclosure supplements the TravelCS Privacy Policy and applies specifically to information received through Google API Services.