── DAYCHIEF GOOGLE API USE
Google API Disclosure
DayChief can connect to Google services only when a user explicitly signs in with Google or links a Google account. Google API data is used to provide user-requested workflows, prepare drafts, show approval context, and execute user-approved actions.
Google Data Used by DayChief
The exact Google data DayChief can access depends on the permissions the user selects before connecting. DayChief starts with no Google Workspace service access and requests only the permissions for workflows the user enables:
- Identity (
openid,email, andprofile): DayChief uses the Google account identifier and email address to identify and display the connected account. - Gmail read (
gmail.readonly): DayChief can list and search messages and drafts and read message and draft metadata and content, including sender and recipient fields, dates, subjects, snippets, labels, and body text. DayChief uses this access only for user-requested inbox, search, reading, and summarization workflows. - Gmail compose (
gmail.compose): DayChief can create, read, update, and send drafts. DayChief uses this access only for draft workflows requested by the user; creating, updating, or sending a draft requires the user's approval in DayChief. - Calendar read (
calendar.events.readonlyandcalendar.calendarlist.readonly): DayChief can read the user's calendar list and event details, including titles, descriptions, times, recurrence, locations, attendees, and meeting links, for user-requested schedule workflows. - Calendar write (
calendar.eventsandcalendar.calendarlist.readonly): DayChief can read events and can create, update, or delete events only after the user approves the action. Calendar-list access remains read-only and is used to let the user choose which calendars DayChief may use. - Drive read (
drive.readonly): DayChief can search files and shared drives; read file identifiers, names, types, dates, sizes, and links; and retrieve or export the content of supported files. DayChief uses this access only for Drive searches and research requested by the user.
How Google Data Is Processed and Shared
Google Workspace data is processed only to provide a feature the user requests. Relevant content may pass through FXA Digital's Google Cloud infrastructure and be sent to OpenAI's API to interpret the request or produce the requested answer, summary, email draft, event proposal, Drive research result, or action preview. Google data is otherwise sent back only to Google when DayChief performs an API operation the user requested and, for writes, approved.
FXA Digital does not sell Google user data or use it for advertising, credit decisions, surveillance, or unrelated analytics. DayChief does not permit Google Workspace data to be used to train generalized AI or machine-learning models. DayChief does not create or use aggregated or anonymized datasets derived from Gmail, Calendar, or Drive content for advertising, analytics, product development, or model training. DayChief may aggregate non-content operational measurements such as request counts, timing, success status, and error rates to operate and secure the service.
Storage, Retention, and Deletion
- DayChief stores the connected account identifier and email address, the scopes and app permissions selected, an encrypted OAuth refresh token, selected-calendar settings, and limited cached connector metadata while the account is connected.
- Google content is retrieved as needed and is not maintained as a separate permanent mirror. Content, excerpts, summaries, or action details included in a DayChief conversation or approval record are retained with the user's DayChief account until account deletion.
- Disconnecting Google in DayChief deletes the stored OAuth token and cached Google connector metadata and attempts to revoke access with Google. It does not remove an email draft, sent message, or calendar event already written to Google, and it does not delete content already included in DayChief conversation or approval history.
- Deleting the DayChief account from Settings removes the Firebase authentication user and active user-scoped backend data, including connector tokens and metadata, conversations, transcripts, voice-session records, local tasks, and pending approvals.
- Production application logs are retained for 30 days and are designed to include operational identifiers, status, timing, and redacted errors rather than Google message bodies, file contents, or credentials.
Security and Human Access
DayChief uses HTTPS/TLS in transit and Google Cloud encryption at rest. In production, OAuth refresh tokens are additionally encrypted with Google Cloud KMS. Access is restricted through authenticated user boundaries and least-privilege service identities, and application logging is designed to redact credentials and connected-service content.
FXA Digital does not routinely inspect Google Workspace content. Authorized personnel may access it only to the minimum extent necessary when the user explicitly requests support, to investigate security or abuse, to maintain service integrity, or to comply with law. Service providers may process Google data only to provide their contracted service and not for their own advertising or generalized model training.
Limited Use
DayChief's use and transfer to any other app of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
User Control
Before OAuth, users independently choose Gmail read, Gmail compose, Calendar, and Drive access; a service left at No Access is not requested. Users can later disconnect Google in DayChief Settings or revoke DayChief from their Google Account permissions. After access is revoked, DayChief can no longer call Google APIs for that account. Users can also delete their DayChief account and associated app data directly from Settings in the app.
Google Cloud Speech and Infrastructure
DayChief may also use Google Cloud infrastructure, including speech processing, as part of hosted voice or BYOA Voice features. That processing is separate from optional Google Workspace connector access and does not grant DayChief access to a user's Google Workspace data unless the user separately links a Google account.
Contact
For questions about DayChief's Google API use, contact FXA Digital Solutions LLC at [email protected].