Google User Data Policy
What Adoptiv does with data from Google APIs, the single Gmail scope we request, and our commitment to the Google API Services User Data Policy Limited Use requirements.
Adoptiv Inc · Updated 2026-08-03
01Our commitment
Adoptiv's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This page exists to say plainly what that means in our product. It covers data we receive from Google APIs when a user connects a Google account to Adoptiv. Our general privacy terms are at /legal/privacy, and this page prevails over that one on anything concerning Google user data.
Adoptiv is operated by Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States.
02The scope we request
Adoptiv requests one restricted Gmail scope, and no others.
| Scope | Type |
|---|---|
| https://www.googleapis.com/auth/gmail.modify | Restricted |
We request one scope rather than several because gmail.modify is a superset of the narrower Gmail scopes. It already authorises everything the integration does, so requesting readonly, send or labels alongside it would add consent prompts without adding capability. The connected address is read from the Gmail profile endpoint, which modify covers, so we do not request a separate profile or userinfo scope either.
A user connects their own mailbox through Google's consent screen. An administrator cannot connect a mailbox on another person's behalf.
03What we do with it, and why
Every use below is a feature the user can see and use in the Adoptiv interface. There is no other use.
| What the product does | Why it needs the access |
|---|---|
| Lists and fetches messages, threads and attachments | To show a user their email inside Adoptiv, next to the contact or deal it relates to |
| Reads labels and folders | So the mailbox structure in Adoptiv matches the mailbox itself |
| Reads the Gmail history feed | To pick up new and changed messages incrementally instead of re-reading the whole mailbox |
| Registers a watch on the mailbox | So Google can notify Adoptiv through Google Cloud Pub/Sub when the mailbox changes. The notification carries a change marker, not message content |
| Sends messages | To send the email a user writes and sends from Adoptiv, from their own address |
| Updates read state and labels | So that reading or filing a message in Adoptiv is reflected in the mailbox, and the other way round |
| Reads the account profile | To confirm which address was connected, and to attribute messages to the right account |
Adoptiv cannot delete or trash a message in your Gmail mailbox. The product does not call the Gmail delete, trash or batch delete endpoints.
Drafts a user composes in Adoptiv are held on Adoptiv servers. They are not written into your Gmail drafts folder.
04What we never do
- We do not use Google user data to develop, improve or train generalised or non-personalised artificial intelligence or machine learning models. This applies to our own models and to any model operated by a third party.
- We do not sell Google user data. Not to data brokers, not to advertisers, not to anyone.
- We do not use Google user data for advertising of any kind, including retargeting or personalised advertising, and we do not pass it to an advertising network.
- We do not use Google user data to build a profile of anyone outside the workspace that connected the mailbox, and we never combine one customer's mailbox data with another's.
- We do not transfer Google user data except as set out in the next section.
Where a workspace switches on AI features that act on email, the message content is sent to a model provider to produce that specific output, such as a summary or a suggested reply, and for nothing else. Those providers are engaged under terms that prohibit them from training on the data or retaining it beyond what the request requires.
05Who else may receive it
Google user data is transferred only where it is necessary to provide the features described above, to comply with applicable law, or as part of a merger or acquisition after notice. These are the categories that may receive it.
| Category | Why | On by default |
|---|---|---|
| Cloud hosting and object storage | The mailbox content has to be stored and served somewhere. Our primary infrastructure is in Germany | Yes, it is how the product runs |
| AI and language model providers | To produce a summary, a suggested reply or an extracted CRM field the user asked for | No. AI features are opt-in per workspace and every switch starts off |
| Google Cloud Pub/Sub | Google's own service, which delivers the change notification that tells us to sync. It carries a change marker, not content | Yes, for connected Gmail accounts |
No other category receives Gmail message content. Our telephony providers, payment processor, data enrichment providers and marketing analytics do not receive it.
Each recipient is named, with what it receives, at /legal/sub-processors. We give 30 days' notice before we add one. Every one of them is under a written contract that limits it to processing on our instructions.
06When a person can see it
Adoptiv staff do not read your mail. Access by a human being is limited to the four cases the Limited Use requirements permit, and no others.
- You ask us to. If you raise a support ticket about a specific message or thread and give us permission to look at it, a support engineer may open that message. Permission is asked for each time and is not a standing grant.
- Security, abuse and legal necessity. Where we must investigate a security incident, abuse of the platform, or respond to a valid legal order.
- Aggregated and anonymised operations. Counts and error rates that cannot identify a person or a message, used to keep the sync working.
- Terms enforcement, where the data is required to establish a breach of our terms.
Production access is restricted to a small number of named engineers, requires multi-factor authentication, and is logged. We do not grant standing access to mailbox content.
07How to revoke access
You can do this two ways, and either one is enough.
- In Adoptiv. Open the integrations screen and disconnect the mailbox. We cancel the Gmail watch and revoke the token with Google, so it cannot be used again.
- In your Google Account. Go to the security section, open the list of third-party apps with account access, select Adoptiv and remove access. We lose access immediately and the sync stops.
When a mailbox is disconnected, messages that are not attached to a contact or a deal are deleted from Adoptiv, along with the folder structure and the drafts held for that mailbox. Messages already attached to a contact or a deal are kept as part of the customer's CRM record, so the account history behind a deal survives.
Revoking access stops future sync. It does not by itself delete what has already been retained. Use the next section for that.
08How to request deletion
Email privacy@adoptiv.com with the subject Google Data Deletion and tell us the connected address. We will confirm within 2 business days and complete the deletion within 30 days.
This covers everything retained from the mailbox, including messages attached to a contact or a deal, the stored transcript of any AI output derived from them, and the OAuth tokens.
If your mailbox belongs to a workspace run by someone else, that customer is the controller of those records. We will carry out the deletion with them and will tell you when it is done.
OAuth tokens are encrypted at rest with AES-256-GCM and are destroyed when the connection is removed.
09Questions
Write to privacy@adoptiv.com, or to Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Our phone number is +1 (636) 556 0022.
The controls behind these commitments are described at /legal/security-practices. If you think you have found a way around any of them, please tell us through /legal/vulnerability-disclosure.
Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Questions about this document go to legal@adoptiv.com. Privacy requests go to privacy@adoptiv.com.