Google User Data Usage
Last updated: July 2026
This page describes how DeskAI accesses, uses, stores, and shares Google user data — the calendar data of business customers who connect their Google account to DeskAI. It exists as a plain-language companion to our Privacy Policy and to satisfy the disclosure requirements of Google's OAuth verification process.
What Google user data DeskAI accesses
When you click "Connect Google Calendar" in the DeskAI dashboard, we request the following OAuth scopes:
https://www.googleapis.com/auth/calendar— read and write access to your Google Calendars. We use this to list, create, update, and delete events on the specific calendar you select.https://www.googleapis.com/auth/userinfo.email— your Google account's email address. We use this solely to show you which account is connected in the DeskAI dashboard ("Connected as your.email@gmail.com").
We do not access any other Google product or scope — no Gmail, no Drive, no Contacts.
How DeskAI uses that data
- Reading events. When answering an incoming SMS, DeskAI reads events on the connected calendar within a bounded time window (typically the current day plus the next 14 days) so it can quote accurate availability to your customer.
- Creating events. When a customer confirms a booking, DeskAI creates the corresponding event on your calendar with the customer's name, service, staff assignment, and any relevant notes.
- Updating events. If a customer reschedules — or if you drag an event to a new time in the DeskAI agenda sidebar — DeskAI updates the event's start and end times on your calendar.
- Deleting events. If a booking is cancelled through DeskAI, the corresponding event is removed from your calendar.
What DeskAI does not do with Google user data
- We do not sell Google user data. Ever.
- We do not use Google user data to serve advertisements.
- We do not share Google user data with third parties, except with our own hosting and AI providers strictly as needed to operate the service (see Privacy Policy section 5).
- We do not read Google user data as humans, except with your explicit consent (e.g. you email us a support ticket including a calendar screenshot), for security incident response, for the small number of authorised operators debugging a customer-reported issue, or as required by law.
- We do not use Google user data to train AI models, either our own or Anthropic's. Calendar events are treated as operational data only.
How Google user data is stored
We store a refresh token (long-lived) on our server so we can keep operating on your calendar without asking you to log in again every hour. The refresh token is encrypted at rest. Individual calendar events are read on demand from Google — we do not maintain a shadow copy of your entire calendar. A minimal set of event references (Google event IDs) is stored on our side so that we can update or delete the specific event corresponding to a specific booking.
How you can revoke access
You can disconnect your Google account from DeskAI at any time. Two paths:
- From the DeskAI dashboard: Settings → Google Calendar → Disconnect. This deletes our copy of the refresh token immediately.
- From your Google account directly: visit myaccount.google.com/permissions, find DeskAI, and click Remove Access. Google will invalidate the token from their side.
Compliance with the Google API Services User Data Policy
DeskAI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about how we use Google user data: privacy@deskai.com.au