Google API Data Usage & Limited Use Compliance

Overview

Verumate is committed to protecting customer privacy and handling Google API Data responsibly.

This page explains how Verumate accesses, uses, stores, and protects Google API Data obtained through Google OAuth. It also describes our commitment to complying with the Google API Services User Data Policy, including the Limited Use requirements.

This document should be read together with our Privacy Policy, Data Retention & Deletion Policy, and Security documentation.


Our Principles

Verumate is built on the following principles:

  • Customer Data belongs to the Customer.

  • Customers control which Google Accounts they connect.

  • Read-only access by default.

  • Least Privilege access.

  • Transparent AI.

  • Evidence-backed analysis.

  • Privacy by Design.

  • Security by Design.


Supported Google Services

Verumate currently supports the following Google services through secure Google OAuth authorization.

Google ServiceAccessPurpose
Google AnalyticsRead-onlyRetrieve analytics data to generate evidence-backed insights, investigations, reports, and business analyses.
Google Search ConsoleRead-onlyRetrieve search performance data to generate SEO insights, reports, and business analyses.

As Verumate expands its integration capabilities, support for additional Google services may be introduced. Any new Google integrations that process Google API Data will be documented on this page before they become generally available.


Why Verumate Requests Google Permissions

Verumate requests only the permissions required to provide the functionality explicitly requested by the Customer.

Google Analytics

Permissions are used to:

  • Retrieve analytics metrics and dimensions.

  • Analyze website performance.

  • Generate business reports.

  • Answer customer questions.

  • Produce evidence-backed insights.

Verumate does not modify Google Analytics properties, settings, configurations, or collected data.


Google Search Console

Permissions are used to:

  • Retrieve search performance information.

  • Analyze search queries and clicks.

  • Review indexing and search visibility information.

  • Generate SEO reports.

  • Answer customer questions.

Verumate does not modify Search Console settings, website ownership, or search configurations.


Read-Only Access

Verumate is designed around a read-only access model wherever supported by Connected Services.

By default, Verumate:

  • Retrieves authorized business information.

  • Analyzes available data.

  • Generates reports.

  • Produces evidence-backed recommendations.

  • Answers business questions.

Verumate does not create, modify, or delete data within Google services on behalf of Customers.


How We Use Google API Data

Google API Data is processed solely to provide functionality requested by the Customer.

Examples include:

  • Retrieving authorized business information.

  • Answering business questions.

  • Identifying trends and patterns.

  • Detecting anomalies.

  • Generating reports.

  • Producing evidence-backed business insights.

  • Supporting business investigations.

Google API Data is processed only within the Customer’s Workspace and only for the Services requested by the Customer.


How AI Uses Google API Data

Verumate combines deterministic investigation and decision engines with artificial intelligence to assist Customers in understanding their business performance.

Google API Data may be processed to:

  • Explain business performance.

  • Summarize trends.

  • Generate reports.

  • Produce evidence-backed recommendations.

  • Answer natural language business questions.

AI is used solely to deliver functionality requested by the Customer.

Verumate does not use Google API Data to develop, improve, or train generalized artificial intelligence or machine learning models.


What Verumate Does Not Do

Verumate does not:

  • Sell Google API Data.

  • Use Google API Data for advertising or marketing purposes.

  • Use Google API Data for user profiling unrelated to the Services.

  • Share Google API Data with unauthorized third parties.

  • Access Google services without Customer authorization.

  • Store Google Account passwords.

  • Use Google API Data to train generalized AI or machine learning models.


Security of Google API Data

Verumate protects Google API Data using administrative, technical, and organizational safeguards designed to maintain confidentiality, integrity, and availability.

These safeguards include:

  • HTTPS/TLS encryption for data in transit.

  • Encryption of OAuth credentials.

  • Secure authentication and authorization.

  • Role-based access controls.

  • Workspace isolation.

  • Infrastructure monitoring.

  • Audit logging.

  • Secure backup and recovery procedures.

Additional information is available in our Security documentation.


Customer Control

Customers remain in control of their Google integrations.

Customers may:

  • Connect Google Accounts.

  • Disconnect Google Accounts.

  • Revoke OAuth authorization.

  • Delete their Verumate account.

  • Request deletion of Customer Data in accordance with our Data Retention & Deletion Policy.

When a Google integration is disconnected, Verumate immediately stops retrieving new Google API Data.


Google API Data Retention

Google API Data is retained only for as long as necessary to provide the Services requested by the Customer.

When a Google integration is removed:

  • Verumate stops retrieving new data immediately.

  • OAuth credentials are securely removed when no longer required.

  • Previously retrieved information is managed according to our Data Retention & Deletion Policy.


Compliance with the Google API Services User Data Policy

Verumate’s use and transfer of information received from Google APIs to any other application complies with the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Verumate:

  • Uses Google API Data only to provide or improve user-facing functionality explicitly requested by the Customer.

  • Requests only the minimum permissions necessary to provide the requested functionality.

  • Does not sell Google API Data.

  • Does not use Google API Data for advertising or marketing purposes.

  • Does not use Google API Data to develop, improve, or train generalized artificial intelligence or machine learning models.

  • Protects Google API Data using appropriate administrative, technical, and organizational safeguards.

  • Processes Google API Data only as described in our published documentation.


Contact

If you have questions regarding how Verumate processes Google API Data or complies with the Google API Services User Data Policy, please contact:

Privacy Team

Email: support@verumate.com

For additional information, please refer to our Privacy Policy, Data Retention & Deletion Policy, and Security documentation.