Google API transparency
Google User Data Disclosure
Last updated: 30 July 2026
Access requested
| Scope | Actual use | Why a narrower scope is insufficient |
|---|---|---|
.../auth/calendar | Lists writable calendars; reads events in the selected calendar; creates, updates and cancels linked events; synchronises dates, times, titles, descriptions, reminders and private AuraSuite appointment identifiers. | AuraSuite provides two-way event management. Read-only cannot create/update events; events-only access cannot list calendars so the user can select the correct writable calendar. |
.../auth/gmail.readonly | Runs the fixed query from:incontact@fnb.co.za newer_than:90d, lists up to 100 matches and retrieves each new matching message in full to parse FNB transaction text. | Gmail metadata does not include the message body containing amount, payer/payee and reference needed for the visible transaction-review feature. AuraSuite does not send, edit or delete mail. |
Data stored
The local/private AuraSuite server stores access and refresh tokens, expiry, selected calendar ID, sync time, Google event IDs, selected event details, Gmail message IDs, sender, subject, date and parsed transaction/source text. These may appear in local backups. Tokens are stored in the local database and are not application-level encrypted in this build.
Use and user control
Calendar events are linked to known clients only when the subject matches a single existing client or the user links an unmatched event. Gmail transactions remain suggestions until an authorised user confirms them. Google data is used only for these visible features, security, legal compliance and user-authorised support.
Gemini and sharing
The current code does not send raw Gmail content, Calendar events or OAuth tokens to Gemini. Google data is not sold, used for advertising, credit decisions, or to train or improve a general-purpose AI/ML model. Humans do not read it except with documented user consent for specific support, for security, or where legally required.
Disconnect, deletion and retention
The in-app disconnect control requests revocation and deletes local tokens. Users may choose to also delete cached unmatched Calendar data, unconfirmed Gmail suggestions and Google link identifiers. Google access can separately be revoked in the Google Account's third-party connections page. Confirmed salon appointments and financial records may remain as business records. Gmail searches cover 90 days; Calendar synchronisation covers 30 days back and 365 days forward. See the step-by-step deletion instructions.