Google API data use (Limited Use disclosure)
Last drafted: 2026-09-30 · Effective date: [EFFECTIVE DATE]
Gladhear’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This page describes exactly what our Google Business Profile integration does. It is written to match the code. Status: the integration is built but has only been tested with simulated Google responses; it is off until Google approves API access for our project.
What we request
- One scope:
https://www.googleapis.com/auth/business.manage. Google does not offer a narrower scope for reading and replying to reviews, so the scope itself is broader than what we use. We do not use it for anything except the features below. - Offline access (a refresh token) so that we can fetch reviews and post an approved reply without you being signed in to Google at that moment.
What we do with the data
- List the Business Profile accounts and locations you can access, so you can choose which ones to link to a Gladhear location. (Location name and identifier only.)
- Read reviews for the locations you linked: star rating, reviewer display name (or “A Google user” if anonymous), review text, review identifier, whether an owner reply already exists. We do not store reviewer profile photos or review photos/videos.
- Generate a reply draft from the review text and rating using an AI provider, check it with our automated privacy rules, and send an approval link to the person you designated. The message contains no reviewer name or star rating.
- Only after a person approves that specific reply and clicks “Post to Google”, call Google’s
reviews.updateReplyto publish exactly the approved text as your owner reply. There is no auto-posting and no bulk-reply mode.
These uses are the user-facing features you see in Gladhear. We do not use Google user data for any other purpose, including advertising, profiling, credit decisions, or building our own review database.
Limited Use commitments
- We use Google user data only to provide or improve the visible features described above.
- We do not transfer Google user data to others except (a) to service providers that process it on our behalf to run those features (AI draft generation, email/SMS delivery, hosting — see the Privacy Policy), (b) as required by law, or (c) with your consent.
- We do not use Google user data for serving advertisements, and we do not sell it.
- We do not use Google user data to develop, improve or train generalised AI/ML models. Review text is sent to an AI provider only to produce the draft for you. We will only use providers whose terms do not permit training on our API data [VERIFY before launch].
- Humans at Gladhear do not read Google user data unless you ask us to (for support), it is necessary for security or abuse investigation, or the law requires it. Data is otherwise handled by software.
Storage, retention and deletion
- 30-day limit. Google’s Business Profile API policy allows content from the API to be stored only temporarily, for no more than 30 calendar days, securely, and without manipulating or aggregating it. Each Google-sourced review (and the drafts derived from it) is stored with an expiry of [28] days after it was fetched and is deleted automatically by a scheduled job; expired rows are also never shown by the app.
- No aggregation. Google-sourced content is excluded from weekly digests, counts, averages and reply-rate statistics. The only Google-related number in a digest is a content-free count of replies awaiting your approval.
- Refresh, not archive. After deletion, a new sync fetches fresh content from Google if the review still needs a reply. We do not keep hashes, copies or tombstones of deleted Google reviews.
- Your approved reply text is your own content; it is deleted together with the review copy it belongs to, and it remains on Google as your public reply.
- Tokens are encrypted at rest (AES-256-GCM) and used only server-side; they are never shown in the browser or logs.
- Disconnect (Google integration page): we revoke the tokens at Google, delete the stored tokens, and immediately delete all Google-sourced reviews and drafts for your organisation. You can also revoke access at myaccount.google.com/permissions, after which our access stops working. Deleting your account does the same.
- Backups: [DESCRIBE — backups containing Google-sourced content must also expire within the 30-day window].
Security
Encrypted tokens, per-organisation access control, OAuth state validation, HTTPS in production, rate limits, and audit events for connect, sync, post and disconnect (audit events contain no review text).
Contact
Questions or deletion requests: [CONTACT EMAIL - placeholder hello@gladhear.com; owner must set up this mailbox] — [COMPANY NAME], [POSTAL ADDRESS].