Trust

Google API Disclosure for OrgOrg

Last Modified: September 11, 2026
OrgOrg's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Scopes

OrgOrg requests access to the following Google API scopes, depending on which features you choose to enable:

Authentication (required)

  • openid - Verify your identity
  • userinfo.email - View your email address
  • userinfo.profile - View your basic profile information

Google Calendar (optional, if enabled)

  • calendar - View and manage your calendar events for the team calendar feature

Google Contacts (optional, if enabled)

  • contacts.readonly - Enrich CRM records from your own address book

Gmail (optional, if enabled)

  • gmail.metadata - Show your email activity with CRM contacts: subjects, senders, recipients, dates, and labels only. Message bodies and attachments are never accessible with this scope.
  • gmail.readonly - Read the messages and attachments of conversations that match a CRM record: threads you file to a CRM box, and messages exchanged with a saved CRM contact or company domain. This powers the contact timeline, the filed-thread view, and the CRM assistance you ask for. Mail that matches no CRM record is not read and not stored.
  • gmail.send - Send a reply or a new message you composed and approved in the CRM, from your own mailbox. OrgOrg never sends unattended mail, apart from sequence steps you armed yourself, and never from another person's mailbox.
  • gmail.modify - Put OrgOrg's own label on a thread you file to a CRM record, naming the pipeline and the stage, for example OrgOrg/Fundraise/Pitched. The label moves when the deal moves stage, and it is removed when you unfile the thread, so a deal's state is visible in Gmail itself, including the Gmail mobile apps. OrgOrg adds and removes labels only under its own OrgOrg/ root, and only on threads you filed. It never deletes a message, never moves one to trash, and never alters message content. Labels you created yourself are never added, removed, renamed, or recoloured.

Sending and labelling share a single approval, requested only when you turn them on and never on first connection. Each keeps its own off switch, so you can stop one and keep the other. Where an administrator has delegated mailbox access for your domain, that path can never send or label: both refuse delegation, so only your own grant can write to your mailbox.

Google Groups (optional, if enabled)

  • admin.directory.group, admin.directory.group.member - Sync Google Groups for team management
  • cloud-identity.groups - Access Cloud Identity groups

Google Drive (optional, if enabled)

  • drive.file - Access only the files OrgOrg creates or that you open with OrgOrg (goal exports, Snipit captures); Google Docs and Drawings exports use this scope
  • spreadsheets - Create and edit spreadsheets (goal check-in exports)
  • presentations - Create and edit presentations

Google Tasks (optional, if enabled)

  • tasks - Show, check off, and add your Google Tasks on the OrgOrg new tab

Google Workspace Directory (optional, if enabled)

  • admin.directory.user.readonly - Read user directory information for syncing your organization's user list
  • admin.directory.user - Read and update user directory information when you enable bidirectional (write-back) directory sync
  • admin.directory.orgunit.readonly - Read organizational unit structure
  • admin.directory.customer.readonly - Read your Google Workspace account details to identify your organization

OrgOrg CRM for Gmail add-on (optional, if installed)

  • gmail.addons.execute - Run the OrgOrg card inside Gmail
  • gmail.addons.current.message.readonly - Read the message you have open, so the card can show CRM context for the people on the thread and the record it is filed to
  • gmail.addons.current.message.metadata - Read the recipients of the draft you have open, for the compose-time card
  • gmail.addons.current.action.compose - Required by the compose-time card

These scopes work only while the card is running on a message or draft you opened. The add-on cannot search your mailbox and reads nothing in the background. Its only write is filing the open thread to a CRM record.

Data Use and Limited Use Compliance

OrgOrg uses data obtained from Google APIs solely for the purpose of providing and improving the OrgOrg features you have enabled. We do not use Google API data for advertising, and we do not allow humans to read your data unless:

  • You have given us explicit, affirmative consent
  • It is necessary for security purposes (e.g., investigating a bug or abuse)
  • It is required by law
  • The data is aggregated and anonymized for internal operational purposes

AI and machine learning. We do not use Google API data, whether raw, aggregated, anonymized, or derived, to develop, improve, or train generalized or foundational machine learning or AI models, our own or anyone else's. Where a feature sends Google API data to an AI model in order to do what you asked, that model is Google Gemini, reached through Google's own API.

Looking things up. Some features look up public information to fill in a CRM record, such as a company's details or a person's public profile. Where that lookup starts from something we learned through a Google API, we send only the identifier it needs, such as a company domain or a person's name. We never send the content of your mail, your calendar, or your files.

OrgOrg uses other providers for features that do not involve Google API data, and every provider is listed on our Subprocessors page. We route Google API data only to providers whose terms prohibit using customer inputs and outputs to train generalized models.

Data Retention

Data obtained from Google APIs is retained for as long as your account is active and you have the corresponding feature enabled. When you disconnect a Google integration (e.g., Google Calendar or Workspace Directory), we stop accessing your Google data and remove cached copies within 30 days. You may also request immediate deletion by contacting privacy@orgorg.com.

Data Transfers

OrgOrg does not transfer information received from Google APIs to any other apps, with the exclusion of our subprocessors for app functionality and support. All data is stored and processed in the United States. See our Privacy Policy for more information about data transfers and applicable safeguards.

Trademarks

Google, Google Workspace, Gmail, Google Calendar, Google Contacts, Google Tasks, Google Drive, Google Sheets, Google Slides, Google Docs and Google Groups are trademarks of Google LLC. OrgOrg is not endorsed by or affiliated with Google. We name these products only to say which service a feature connects to.