WrenchPilot Technologies Inc.
Google API Services User Data Policy
Public statement of compliance with the Google API Services User Data Policy, including Limited Use requirements, for Google Workspace / Gmail API data used by WrenchPilot.
Last updated: September 18, 2026
Limited Use attestation
The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace API Data and Artificial Intelligence
The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, WrenchPilot may request https://www.googleapis.com/auth/gmail.send to send user-initiated business communications (such as invoices, estimates, payment links, service updates, and related messages) through your connected Gmail account, and https://www.googleapis.com/auth/gmail.readonly so you can view that mailbox inside WrenchPilot (for example, an in-app inbox on authorized shop dashboards). WrenchPilot also requests the Google account email address (userinfo.email) solely to identify which Google account is connected. WrenchPilot does not request or use the https://mail.google.com/ scope.
Access and use: WrenchPilot accesses Gmail only after you grant OAuth consent. Send scope is used to transmit user-initiated messages via the Gmail API. Readonly scope is used to retrieve message metadata and content for display in WrenchPilot so you can read and manage that mailbox in-app. We do not use Google Workspace data for advertising, sale, or unrelated profiling.
Storage: WrenchPilot stores OAuth credentials (such as refresh and access tokens) and the connected Gmail address associated with your shop so the connection can operate. Message bodies retrieved for the in-app inbox are processed to display the mailbox and are not retained as a separate long-term Gmail archive in WrenchPilot. Tokens are stored with the shop record and are accessible only to authorized backend components for that shop.
Sharing: Google Workspace / Gmail API data is not sold. It is not shared with advertising networks. It is not transmitted to OpenRouter or other third-party artificial intelligence providers. Limited service providers that host or operate WrenchPilot infrastructure may process encrypted application data under contract; they are not authorized to use Gmail API data for their own purposes.
Deletion / disconnect: Disconnecting Gmail under Settings revokes the Google grant where possible and deletes stored Gmail OAuth tokens and the connected Gmail address from that shop’s email configuration. Further Gmail API access for that connection stops. Separate account-closure or data-deletion requests are handled under our general retention and deletion practices described in this Privacy Policy.
WrenchPilot uses third-party artificial intelligence services, including OpenRouter and models available through OpenRouter, for separate WrenchPilot product features (for example, the in-app job assistant). These AI features are architecturally isolated from the Google Workspace / Gmail integration (Google API Services User Data Policy Pathway C, Option 2: complete data isolation).
No raw or derived Google Workspace API data, Gmail message content, Gmail metadata, Google OAuth credentials, access tokens, refresh tokens, or other information obtained through Google APIs is transmitted to, processed by, or used by OpenRouter, DeepSeek, or any other third-party artificial intelligence service. Artificial intelligence features process only information entered directly into WrenchPilot by users or generated independently of Google Workspace APIs.
Google Workspace API data is not used to develop, improve, or train generalized artificial intelligence or machine-learning models.
Gmail OAuth scopes
https://www.googleapis.com/auth/gmail.send— send user-initiated business email (Gmail APIusers.messages.send)https://www.googleapis.com/auth/gmail.readonly— view mailbox messages inside WrenchPilot (in-app inbox on authorized dashboards)https://www.googleapis.com/auth/userinfo.email— identify the connected Google account
WrenchPilot does not request or use https://mail.google.com/. Sending uses the Gmail API only; SMTP / XOAUTH2 is not used. Gmail data obtained via these scopes is not sent to third-party AI providers (Pathway C Option 2: complete data isolation).
Storage & deletion: OAuth tokens and the connected Gmail address are stored with the shop email configuration. Disconnecting Gmail revokes the Google grant where possible and deletes those stored credentials. In-app inbox content is fetched to display the mailbox and is not kept as a separate long-term Gmail archive in WrenchPilot.
Artificial intelligence (third-party)
WrenchPilot integrates with a third-party AI service provider: OpenRouter (and models available through OpenRouter). This integration is for separate WrenchPilot features and is isolated from Google Workspace API data.
Google user data obtained via Google APIs is never sent to OpenRouter or used to train generalized AI models. See also our Privacy Policy and Terms of Service.
Questions: service@wrenchpilot.io