Trust

Google API Disclosure for OrgOrg

Last Modified: August 20, 2026
OrgOrg's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Scopes

OrgOrg requests access to the following Google API scopes, depending on which features you choose to enable:

Authentication (required)

  • openid - Verify your identity
  • userinfo.email - View your email address
  • userinfo.profile - View your basic profile information

Google Calendar (optional, if enabled)

  • calendar - View and manage your calendar events for the team calendar feature

Google Contacts (optional, if enabled)

  • contacts.readonly - Enrich CRM records from your own address book

Gmail (optional, if enabled)

  • gmail.metadata - Show your email activity with CRM contacts: subjects, senders, recipients, dates, and labels only. Message bodies and attachments are never accessible with this scope.
  • gmail.readonly - Read the messages and attachments of conversations that match a CRM record: threads you file to a CRM box, and messages exchanged with a saved CRM contact or company domain. This powers the contact timeline, the filed-thread view, and the CRM assistance you ask for. Mail that matches no CRM record is not read and not stored.
  • gmail.send - Send a reply or a new message you composed and approved in the CRM, from your own mailbox. Requested only when you turn on sending for a mailbox, never on first connection. OrgOrg does not modify, label, or delete mail.

Google Groups (optional, if enabled)

  • admin.directory.group, admin.directory.group.member - Sync Google Groups for team management
  • cloud-identity.groups - Access Cloud Identity groups

Google Drive (optional, if enabled)

  • drive.file - Access only the files OrgOrg creates or that you open with OrgOrg (goal exports, Snipit captures); Google Docs and Drawings exports use this scope
  • spreadsheets - Create and edit spreadsheets (goal check-in exports)
  • presentations - Create and edit presentations

Google Tasks (optional, if enabled)

  • tasks - Show, check off, and add your Google Tasks on the OrgOrg new tab

Google Workspace Directory (optional, if enabled)

  • admin.directory.user.readonly - Read user directory information for syncing your organization's user list
  • admin.directory.user - Read and update user directory information when you enable bidirectional (write-back) directory sync
  • admin.directory.orgunit.readonly - Read organizational unit structure
  • admin.directory.customer.readonly - Read your Google Workspace account details to identify your organization

Data Use and Limited Use Compliance

OrgOrg uses data obtained from Google APIs solely for the purpose of providing and improving the OrgOrg features you have enabled. We do not use Google API data for advertising, and we do not allow humans to read your data unless:

  • You have given us explicit, affirmative consent
  • It is necessary for security purposes (e.g., investigating a bug or abuse)
  • It is required by law
  • The data is aggregated and anonymized for internal operational purposes

AI and machine learning. We do not use Google API data, whether raw, aggregated, anonymized, or derived, to develop, improve, or train generalized or foundational machine learning or AI models, our own or anyone else's. Where a feature sends Google API data to an AI model in order to do what you asked, that model is Google Gemini, reached through Google's own API. OrgOrg uses other AI providers for features that do not involve Google API data, and they are listed on our Subprocessors page. We route Google API data only to a provider whose terms prohibit using customer inputs and outputs to train generalized models.

Data Retention

Data obtained from Google APIs is retained for as long as your account is active and you have the corresponding feature enabled. When you disconnect a Google integration (e.g., Google Calendar or Workspace Directory), we stop accessing your Google data and remove cached copies within 30 days. You may also request immediate deletion by contacting privacy@orgorg.com.

Data Transfers

OrgOrg does not transfer information received from Google APIs to any other apps, with the exclusion of our subprocessors for app functionality and support. All data is stored and processed in the United States. See our Privacy Policy for more information about data transfers and applicable safeguards.