Google API Services User Data Policy Disclosure
- Last updated:
- Effective:
This disclosure explains how Atlas Task Manager accesses, uses, stores, and shares information obtained from Google APIs. Our use adheres to the Google API Services User Data Policy, including the Limited Use requirements.
1. Overview
Atlas Task Manager offers optional integrations with Google services: signing in with your Google account, seeing your Google Calendar events and Google Tasks alongside your Atlas Task Manager work, turning Gmail messages into tasks, and attaching Google Drive files to your projects.
Each of these is opt-in and separate. Nothing is connected until you explicitly authorize it through Google's OAuth consent screen, each connector requests only its own scopes at the moment you enable it, and every one can be disconnected at any time from your account settings or revoked directly from your Google account.
2. Google APIs and OAuth scopes we use
The table below is the complete set of scopes Atlas Task Manager requests. It is generated from the same list the application sends to Google's authorization endpoint, so it cannot drift out of step with what you are actually asked to approve.
| API | Scope | Sensitivity | Why we need it |
|---|---|---|---|
| Google Identity (OpenID Connect) | openid | Basic | Establish that the Google account completing the flow is the one that authorized it. |
| Google Identity (OpenID Connect) | email | Basic | Match the Google account to your Atlas account and address service email to you. |
| Google Identity (OpenID Connect) | profile | Basic | Populate your Atlas display name and avatar so teammates can recognize you. |
| Google Calendar API | https://www.googleapis.com/auth/calendar.readonly | Sensitive | Show your existing Google Calendar events beside your Atlas tasks so you can plan against real availability. |
| Google Calendar API | https://www.googleapis.com/auth/calendar.events | Sensitive | Create, update, or remove a calendar event when you explicitly schedule one from Atlas (for example "add to calendar" on a task). |
| Google Tasks API | https://www.googleapis.com/auth/tasks.readonly | Sensitive | Surface your existing Google Tasks in your Atlas work list so nothing is tracked in two places. |
| Gmail API | https://www.googleapis.com/auth/gmail.readonly | Restricted | Let the Gmail connector turn a message into an Atlas task or contact activity, preserving the original subject, sender, and body for context. |
| Gmail API | https://www.googleapis.com/auth/gmail.modify | Restricted | Apply or remove the labels you configure when a message is processed into Atlas, and mark handled mail as read. |
| Gmail API | https://www.googleapis.com/auth/gmail.send | Sensitive | Send a reply or outbound message from your own address when you explicitly compose or send it from Atlas. |
| Google Drive API | https://www.googleapis.com/auth/drive.readonly | Restricted | Let you browse and attach existing Drive files to Atlas tasks, projects, and documents, and export a file when you request it. |
| Google Drive API | https://www.googleapis.com/auth/drive.metadata.readonly | Restricted | Show file names, owners, types, and modified dates in the Drive picker without reading file contents. |
| Google Drive API | https://www.googleapis.com/auth/drive.file | Recommended | Create folders and upload files that Atlas itself generates, such as exported documents and reports. |
Scopes marked Restricted are Google's most tightly governed tier, because they can reach the contents of your mail and files. Atlas Task Manager holds them only to power the Gmail and Google Drive connectors, and only for the account you connect. They carry additional obligations that we meet, described in Limited Use compliance below, including an independent annual security assessment of the systems that handle this data.
Connecting your Google account does not switch these on. Each connector is enabled separately and asks for its own consent, so if you never connect Gmail, Atlas Task Manager never holds Gmail access.
We request only the narrowest scope necessary for each feature - for example, drive.file for documents Atlas Task Manager creates itself, rather than broad access to your whole Drive. If a feature later requires a different scope, you will be prompted to re-consent, and this page will list it before that happens.
3. What Google user data we access
- Google Identity (OpenID Connect) (
openid): A stable Google account identifier (the OIDC subject claim). - Google Identity (OpenID Connect) (
email): Your primary Google email address and whether it is verified. - Google Identity (OpenID Connect) (
profile): Your display name, given/family name, locale, and profile picture URL. - Google Calendar API (
https://www.googleapis.com/auth/calendar.readonly): Event titles, start and end times, locations, descriptions, attendee lists, and reminders on the calendars you choose to sync. - Google Calendar API (
https://www.googleapis.com/auth/calendar.events): Events Atlas creates on your behalf, plus the events you ask Atlas to update or delete. - Google Tasks API (
https://www.googleapis.com/auth/tasks.readonly): Task list names, task titles, notes, due dates, and completion state. - Gmail API (
https://www.googleapis.com/auth/gmail.readonly): Message headers, subjects, bodies, attachment metadata, labels, and thread structure for the mailbox you connect. - Gmail API (
https://www.googleapis.com/auth/gmail.modify): Label assignments and read/unread state on messages you route through Atlas. - Gmail API (
https://www.googleapis.com/auth/gmail.send): The content of messages you compose in Atlas and choose to send. - Google Drive API (
https://www.googleapis.com/auth/drive.readonly): File names, contents, and folder structure for the Drive files you browse or attach. - Google Drive API (
https://www.googleapis.com/auth/drive.metadata.readonly): File and folder metadata only - names, MIME types, owners, and timestamps. - Google Drive API (
https://www.googleapis.com/auth/drive.file): Only the files and folders Atlas creates or that you explicitly open with Atlas. - OAuth tokens: short-lived access tokens and long-lived refresh tokens, stored encrypted at rest.
4. How we use Google user data
- To authenticate you and link your Atlas Task Manager account.
- To display your Google Calendar events alongside your Atlas Task Manager tasks, so you can plan against your real availability.
- To surface your existing Google Tasks in your Atlas Task Manager work list, so the same commitment is not tracked in two places.
- To create or update a calendar event when you explicitly schedule one from Atlas Task Manager.
- To turn a Gmail message you select into an Atlas Task Manager task or contact activity, to apply the labels you configure to mailAtlas Task Manager has processed, and to send a message from your address when you compose and send it yourself.
- To let you browse and attach Google Drive files to Atlas Task Manager work, and to store documents Atlas Task Manager generates for you back into Drive.
- For security, abuse prevention, and to comply with legal obligations.
Atlas Task Manager writes to your Google account only as the direct result of an action you take - scheduling an event, sending a message, uploading a file, or applying a label rule you configured. It never alters your Google data on its own initiative, and it never touches data outside the account and connectors you have connected.
We do not use Google user data to serve advertisements, to target users, for retargeting, or for any personalized advertising purpose.
5. Transfers to third parties
We transfer Google user data to third parties only as strictly necessary to provide or improve user-facing features of Atlas Task Manager, to comply with applicable law, or as part of a merger, acquisition, or asset sale (in which case the recipient is bound by commitments equivalent to this disclosure). Our infrastructure sub-processors are listed on the Sub-processors page.
We do not sell Google user data. We do not transfer Google user data for advertising purposes.
6. Limited Use compliance
Atlas Task Manager's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve user-facing features that are prominent in the Atlas Task Manager application.
- We do not transfer Google user data except as necessary to provide or improve those features, comply with applicable law, or as part of a merger, acquisition, or sale of assets.
- We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data except (a) with your affirmative agreement for specific messages, (b) when necessary for security purposes (such as investigating abuse), (c) when necessary to comply with applicable law, or (d) when the data has been aggregated and anonymized for internal operations in accordance with the policy.
Because Atlas Task Manager requests scopes in Google's restricted tier for the Gmail and Google Drive connectors, we are additionally subject to Google's restricted scope requirements. These oblige us to handle Gmail and Drive content only in service of the features described above, to meet Google's minimum security standards for the systems that store and process that content, and to complete an independent security assessment by a Google-designated assessor, repeated annually.
7. No use for AI / ML model training
We do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models. When you use AI features of Atlas Task Manager, we do not include raw Google Calendar content in any training pipeline, and our contract with our third-party AI provider provides that prompts and completions are not used to train their models.
8. Retention and deletion
We retain Google user data only for as long as your integration is connected and as needed to operate the feature you requested. When you disconnect the integration, delete your account, or revoke access via Google Account permissions, we delete cached Google user data and OAuth tokens within 30 days, subject to the backup-retention windows disclosed in our Privacy Policy.
9. Your control
- Disconnect the integration in Atlas Task Manager account settings.
- Revoke access at myaccount.google.com/permissions.
- Request deletion of stored Google user data by writing to privacy@wrxstack.com.
10. Contact
Questions about our Google API usage: hello@wrxstack.com. Privacy officer: dpo@khanxlabs.com.