Google Workspace API Data Use Policy

Welcome to the Google Workspace API Data Use Policy for Innovation Within. This standalone document explains exactly how—and only how—we access and handle your Google Calendar information when you connect your account. It makes clear that we request read-only permission to view your calendar events, use that data solely to power our scheduling features, and do not retain it for any AI/ML training or deep analytics. Please review this policy alongside our main Privacy Policy to understand how your calendar data is collected, used, protected, and deleted.

Effective Date: 20 June 2024
Last Updated: 27 May 2025
Contact: support@innovationwithin.com

1. Purpose

This policy explains how Innovation Within accesses and uses data obtained exclusively via the read-only Google Calendar API. It supplements our main Privacy Policy and applies solely to the Google Workspace integration.

2. Scope

Applies to: Any calendar event data pulled from Google Workspace via the read-only Calendar API.
Personnel & Systems: All Innovation Within employees, contractors, and services that handle this API data.

3. Data Collected

Innovation Within requests only the following OAuth scope:

  • https://www.googleapis.com/auth/calendar.events.readonly

  • Grants read-only access to the user’s calendar events (e.g. meeting titles, times, descriptions, attendees).

We do not request or collect any other Google Workspace scopes or user data.

4. How We Use Calendar Data

Calendar data is used strictly to:

  • Display your upcoming meetings and events within the Innovation Within application.

  • Sync event details for reminders and scheduling features you explicitly enable.

  • Diagnose and resolve issues related to calendar display or synchronization.

We do not use calendar data for any purpose beyond those listed above.

5. No ML/AI Training or Deep Logging

Innovation Within does not:

  • Develop, improve, or train any artificial-intelligence (AI) or machine-learning (ML) models using Calendar API data or Google account data of any of our platform user data.

  • Perform deep data logging, aggregation, or analytics on your calendar events beyond on-screen display and basic error diagnostics.

All calendar information remains confined to your individual account session and is never repurposed for model training or bulk analysis.

6. Data Retention and Deletion

  • Retention of Cached Calendar Data
    We retain cached calendar data only as long as your session is active or as needed for immediate feature functionality.

  • Retention of Selected Meeting IDs
    When you select a calendar meeting for auto-processing in our platform, we store only the meeting’s unique ID. This allows us to match the Zoom “recording completed” webhook to that specific meeting so we can automatically ingest it into our system. The meeting ID is retained solely for this purpose and is deleted immediately after the recording has been processed.

  • Deletion on Logout or Revocation
    When you log out or revoke our access, all other cached calendar information is permanently deleted.

7. Data Security

We protect all Calendar API data using industry-standard controls:

  • Encryption in Transit: TLS for all API calls.

  • Encryption at Rest: Encrypted storage for any temporary caches.

  • Access Controls: Strict role-based access and audit logging on servers handling calendar data.

  • Periodic Reviews: Regular security assessments to verify controls.

8. Policy Changes

When this policy is updated, we will:

  1. Post the new version at the same URL.

  2. Update the “Last Updated” date at the top.

  3. Notify you via email if changes materially affect how we use your calendar data.

9. Contact

For questions or concerns about this policy, please contact: support@innovationwithin.com

This policy is linked from our main Privacy Policy at https://innovationwithin.com/privacy-policy