Glossary

Google Limited Use policy

The rules an app agrees to before Google lets it read your Gmail or Drive.

In short

Google's Limited Use requirements are part of the Google API Services User Data Policy and govern how apps may use data obtained through specified Google API scopes, including Gmail and Drive. Apps must limit their use of that data to "providing or improving user-facing features that are prominent in the requesting application's user interface," and may not transfer or sell it for advertising, to data brokers, or for credit decisions.

What the Limited Use requirements allow and prohibit

  • Use: only for user-facing features that are prominent in the app's interface.
  • Transfers: not allowed, except to provide those features with the user's consent, for security purposes such as investigating abuse, to comply with law, or as part of a merger or acquisition with the user's explicit consent.
  • Human reading: not allowed unless the user affirmatively agrees to let someone view specific data, it's needed for security (such as investigating a bug or abuse), it's required by law, or the data is aggregated for internal operations.
  • Prohibited: transferring or selling data to advertising platforms or data brokers, using it to serve ads (including retargeting and interest-based ads), and using it to determine credit-worthiness.

Limited Use and AI model training

Google's separate Workspace API User Data and Developer Policy adds a rule aimed at AI: apps may not use Workspace API data "to create, train, or improve a machine learning or artificial intelligence model beyond that specific user's personalized model for the appropriate use case or user-facing feature." In practice, an AI email tool can use your Gmail to help you, but not to train a general model for everyone.

Limited Use vs. OAuth verification

Limited Use is the set of rules. OAuth scope verification is how Google checks an app before it can request sensitive or restricted scopes from the public. Apps using restricted scopes, such as Gmail's read and modify scopes, and able to access that data through their own servers also have to pass a security assessment by a Google-empanelled assessor at least every 12 months.

Synced follows the Google API Services User Data Policy, including the Limited Use requirements, and doesn't use Google Workspace data to train generalized AI or machine-learning models. Details are on the Security page.

Questions

Frequently asked.

How can I tell if an app follows Google's Limited Use policy?

Check the app's privacy policy. Apps that follow the rules commonly include a sentence saying their use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google also checks apps that request restricted scopes during verification.

Get started

Get early access to Synced.

Join the private beta. Synced drafts the replies, finds the files, and proposes the meeting times. You approve.

Get Early AccessFree plan. No credit card.