Google data controls
A plain-language record of AINA's Google scopes, data flow, retention, revocation, and deletion controls.
Effective 2 August 2026
Current availability
Google Drive is an optional read-only connector controlled by AINA's feature and plan gates. Gmail is disabled and is not generally available while Google reviews AINA's request for the restricted gmail.readonly scope. AINA does not request Gmail access from Production users while that gate is disabled.
What AINA accesses
Drive access is limited to files permitted through Google's app-scoped Drive authorization. Gmail access, if verified and enabled later, would allow mailbox search and reading only the messages a user selects for visible email analysis.
- Drive: selected file name, type, modification metadata, source link, and supported text content.
- Gmail: selected message body, subject, sender, recipients, date, message and thread identifiers, and a source link.
- Identity: the Google account identifier and email address needed to show which account is connected.
Why Gmail read-only is required
AINA's user-visible Gmail productivity feature needs to search a mailbox, show candidate message metadata, and read the body of messages the user selects for summarisation or analysis. The narrower gmail.metadata scope does not provide message bodies. Gmail add-on scopes apply only while a Gmail add-on is running, which AINA is not. AINA does not request gmail.modify, gmail.compose, gmail.send, gmail.insert, or full-mailbox mail.google.com access.
How selected data is used
Selected Google content is stored with provenance in the AINA conversation or project chosen by the user. When the user asks for analysis, the required selected content is sent through AINA's authenticated backend and OpenRouter to the selected model. This transfer is solely to provide the visible user-requested feature.
AINA does not use Google Workspace data for advertising, sell it, use it to determine creditworthiness, or use it to train or improve a general AI model. AINA does not permit unrelated humans to read it. Human access is limited to specific documented user consent, necessary security investigation, or legal requirements.
Limited Use
AINA's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only to provide or improve the prominent user-facing connector feature the user requested.
Storage and encryption
OAuth authorization codes are exchanged only by AINA's server. Access tokens are kept in the narrow server operation that needs them and are not sent to the browser. Refresh tokens are protected with per-connection AES-256-GCM envelope encryption and server-only key-encryption material. Tokens and message content are excluded from analytics and application logs.
Selected imported content is stored in AINA's permission-scoped Supabase database. Project roles and row-level security apply. There is no unrestricted whole-account background synchronisation.
Retention and deletion
Selected imported content remains until the user disconnects that Google service and deletes imports, deletes the destination where supported, or deletes the AINA account. Disconnecting always removes the encrypted refresh token and all imported content for that service from AINA, cancels refresh work, and queues deletion verification. Account deletion locally removes encrypted tokens and imported content through database cascades.
- In AINA: open Settings, then Connections, and choose Disconnect and delete imports.
- In Google: open Google Account, Security, then third-party connections, select AINA, and remove access.
- For account deletion: open AINA Settings, Account, and complete the permanent deletion workflow.
Revocation failures
AINA asks Google to revoke the grant during disconnect and account deletion. If Google is temporarily unavailable, AINA still deletes the local encrypted token and imported content. The app then tells the user to remove AINA from Google Account permissions if it remains listed.
Security incidents and questions
AINA records privacy-safe connector audit events without tokens or message content. Suspected unauthorized Google-data access is investigated under AINA's incident-response process, affected access is disabled or revoked, evidence is preserved without copying message content into general logs, and Google is notified where its policy requires. Contact support@useaina.com for access, deletion, privacy, or incident questions.

