Google API Disclosure for OrgOrg
Google API Scopes
OrgOrg requests access to the following Google API scopes, depending on which features you choose to enable:
Authentication (required)
openid- Verify your identityuserinfo.email- View your email addressuserinfo.profile- View your basic profile information
Google Calendar (optional, if enabled)
calendar- View and manage your calendar events for the team calendar feature
Google Contacts (optional, if enabled)
contacts.readonly- Enrich CRM records from your own address book
Gmail (optional, if enabled)
gmail.metadata- Show your email activity with CRM contacts: subjects, senders, recipients, dates, and labels only. Message bodies and attachments are never accessible with this scope.gmail.readonly- Read the messages and attachments of conversations that match a CRM record: threads you file to a CRM box, and messages exchanged with a saved CRM contact or company domain. This powers the contact timeline, the filed-thread view, and the CRM assistance you ask for. Mail that matches no CRM record is not read and not stored.gmail.send- Send a reply or a new message you composed and approved in the CRM, from your own mailbox. Requested only when you turn on sending for a mailbox, never on first connection. OrgOrg does not modify, label, or delete mail.
Google Groups (optional, if enabled)
admin.directory.group,admin.directory.group.member- Sync Google Groups for team managementcloud-identity.groups- Access Cloud Identity groups
Google Drive (optional, if enabled)
drive.file- Access only the files OrgOrg creates or that you open with OrgOrg (goal exports, Snipit captures); Google Docs and Drawings exports use this scopespreadsheets- Create and edit spreadsheets (goal check-in exports)presentations- Create and edit presentations
Google Tasks (optional, if enabled)
tasks- Show, check off, and add your Google Tasks on the OrgOrg new tab
Google Workspace Directory (optional, if enabled)
admin.directory.user.readonly- Read user directory information for syncing your organization's user listadmin.directory.user- Read and update user directory information when you enable bidirectional (write-back) directory syncadmin.directory.orgunit.readonly- Read organizational unit structureadmin.directory.customer.readonly- Read your Google Workspace account details to identify your organization
Data Use and Limited Use Compliance
OrgOrg uses data obtained from Google APIs solely for the purpose of providing and improving the OrgOrg features you have enabled. We do not use Google API data for advertising, and we do not allow humans to read your data unless:
- You have given us explicit, affirmative consent
- It is necessary for security purposes (e.g., investigating a bug or abuse)
- It is required by law
- The data is aggregated and anonymized for internal operational purposes
AI and machine learning. We do not use Google API data, whether raw, aggregated, anonymized, or derived, to develop, improve, or train generalized or foundational machine learning or AI models, our own or anyone else's. Where a feature sends Google API data to an AI model in order to do what you asked, that model is Google Gemini, reached through Google's own API. OrgOrg uses other AI providers for features that do not involve Google API data, and they are listed on our Subprocessors page. We route Google API data only to a provider whose terms prohibit using customer inputs and outputs to train generalized models.
Data Retention
Data obtained from Google APIs is retained for as long as your account is active and you have the corresponding feature enabled. When you disconnect a Google integration (e.g., Google Calendar or Workspace Directory), we stop accessing your Google data and remove cached copies within 30 days. You may also request immediate deletion by contacting privacy@orgorg.com.
Data Transfers
OrgOrg does not transfer information received from Google APIs to any other apps, with the exclusion of our subprocessors for app functionality and support. All data is stored and processed in the United States. See our Privacy Policy for more information about data transfers and applicable safeguards.