Google Limited Use

Last updated: 17 August 2026 · v2026.08

Disclosure

NurtureCRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This page is the standalone statement of that commitment. The same disclosure appears in the Privacy Policy.

The four Limited Use commitments

  1. Limited use. NurtureCRM uses Google user data only to provide or improve user-facing features that are prominent in the NurtureCRM interface.
  2. Limited transfer. NurtureCRM does not transfer Google user data to third parties except to provide or improve those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with prior notice.
  3. No advertising. NurtureCRM does not use Google user data for advertising, and does not sell it.
  4. No human reading. No human at NurtureCRM reads Google user data, except where the user has explicitly consented for specific messages, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.

NurtureCRM does not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models. AI features process message content only to return a result to the user who invoked the feature, using providers contracted not to train on that content. See the AI Policy.

Scopes requested, and the feature each serves

Scope Classification Feature it serves
https://www.googleapis.com/auth/gmail.readonly Restricted Ingesting messages from the consenting mailbox into the NurtureCRM unified inbox, so CRM contact activity, thread history and reply detection reflect the user's real email
https://www.googleapis.com/auth/gmail.send Sensitive Sending replies and composed messages as the consenting user, from within NurtureCRM
openid, .../auth/userinfo.email, .../auth/userinfo.profile Basic Identifying the consenting mailbox owner and binding the connection to a NurtureCRM user account

NurtureCRM does not request permission to modify or delete messages. The gmail.modify scope is not requested, because no NurtureCRM feature changes read state, labels or message contents in a Gmail mailbox.

Narrower scopes are not sufficient: gmail.metadata cannot deliver message bodies, which the unified inbox and the drafting features require, and gmail.addons.current.message.readonly covers only add-on context, not the background ingestion that keeps the inbox current.

Who grants access, and how to withdraw it

  • Access is granted by the mailbox owner, through Google's own consent screen. An administrator cannot connect another person's mailbox on their behalf.
  • A mailbox owner can disconnect at any time from within NurtureCRM, or by removing NurtureCRM at myaccount.google.com/permissions.
  • Revocation tears down the change subscriptions and marks the stored credential revoked so it can no longer reach the mailbox.

Where Google user data is stored

Message content and metadata are ingested into the Customer's own isolated database, inside the Customer's own runtime container, with its own object storage and its own container network. One Customer's Google user data is never written to another Customer's database. OAuth tokens are encrypted at rest.

Full detail is in the Data Policy. The third parties that may process Google user data on our behalf are named at Sub-processors.

Contact

AiCoaches dot com LLC 111 NE 1ST ST, 8TH FLOOR 89145, Miami, Florida, USA 33132 support@aicoaches.com