1. Two Separate Google Permissions
Google Sign-In allows an account holder to authenticate to AVENZERS Cloud and, depending on granted identity scopes, provide basic identity details such as name, profile picture, email, and a Google account identifier. Sign-In alone does not grant Google Drive file access.
Connect Google Drive is an optional user-initiated operation requiring a separate Google authorization step. The intended request uses the non-sensitive restricted-to-selected-files permission https://www.googleapis.com/auth/drive.file. It does not mean AVENZERS Cloud can read or inventory all files in the user's Google Drive.
A user who declines Google Drive access may still use other service functionality that does not require that connection, subject to account configuration. Business model decision: External-storage integration is a Paid Plan feature; on Free Plan downgrade it is suspended while AVENZERS-managed Free Plan storage remains subject to its own quota.
2. What the App Accesses and Why
For a user who chooses to connect Drive, the application may:
- identify the connected account and record whether authorization remains active;
- create or find an AVENZERS Cloud folder in the user's Drive and save user-requested uploads there;
- work with files the application created or that the user deliberately opens/selects for the app through Google Picker;
- read authorized file names, metadata, and file bytes for user-requested listing, preview, download, organization, or sharing functions;
- maintain app-side identifiers and authorized references for conversations/workspaces when the user elects to share those items.
Actual capabilities depend on the granted scope, file-specific permissions, provider API support, and deployed functionality. The app must not promise universal listing of unrelated Google Drive content.
3. Where Data Is Stored or Processed
Original Drive documents normally remain in the user's Google Drive account. AVENZERS Cloud may store the account connection, encrypted authorization credentials, app-side identifiers, item metadata, sharing records, and audit events in controlled backend systems. When a user requests an operation, file bytes may transiently cross an authenticated AVENZERS-controlled server path. No automatic permanent copy to managed object storage is made merely to attach a Drive-backed file reference to an in-app message.
Backend operators and subprocessors, and the locations in which data is processed, must be confirmed against actual production infrastructure and disclosed in the public Privacy Policy.
4. User-Controlled Sharing and Access Revocation
Google Drive files stay private by default; the application must not silently set a file to "Anyone with the link." An in-app share may create an AVENZERS application-level access record for permitted recipients; this is distinct from native Google permissions and requires server-side checks. A recipient who is removed from a conversation or workspace should not receive new authorized access, although already-downloaded copies cannot be recalled.
On paid-to-free downgrade: The intended app state is suspended, not disconnected. AVENZERS does not perform Google Drive file API operations while the user is on the Free Plan; server-side encrypted OAuth credentials may remain associated with the active account. After upgrade, access resumes only if the provider authorization remains valid and item-level/recipient permissions pass a fresh check; user reauthorization may be required. Existing channel/message attachment references remain, but previews/downloads are unavailable while suspended.
On explicit disconnect, provider revocation or AVENZERS account deletion: The app must invalidate/remove the stored connection credentials and stop further authorized access through that connection. The original file remains subject to the owner's Google Drive controls. Google's permission revocation interface is https://myaccount.google.com/permissions.
None of these intended downgrade and restoration behaviors is declared fully operational until OAuth token storage, suspension and permission paths are independently tested.
5. Google API Services User Data Policy / Limited Use
The operator must ensure all actual accesses, uses, storage, and disclosures of Google user data comply with the Google API Services User Data Policy and relevant Google Workspace developer policies.
Our intended commitments:
- Use Google API user data only to provide/improve explicitly requested user-facing functionality, maintain security, satisfy legal obligations, or for another Google-permitted purpose.
- Do not use Google API data to serve advertisements or sell it to data brokers.
- Do not use Google API data to train generalized machine-learning or AI models.
- Do not transfer Google API data to unrelated third parties except in policy-permitted circumstances, necessary service-provider operations, authorized user-selected sharing, legal requirements, or with affirmative consent as applicable.
- Limit human access to Google API data to circumstances permitted by Google's policy, with need-to-know access controls.
- Request no broader Google Drive scope than needed without explicit product necessity, disclosure, and new consent.
6. Provider-Specific Restrictions
Google Drive API policies prohibit treating Drive as a substitute for a large-scale CDN, abusive storage quota circumvention, and other prohibited uses. The planned server-side private file relay requires its own documented compliance assessment and technical transfer/rate limits before public scale. If the proposed approach is not permitted, use an explicitly authorized alternative rather than concealing public links or bypassing policy.
7. Required Public User Disclosures
Before production OAuth publishing, publish a public homepage and Privacy Policy that disclose:
- Google Sign-In identity data and separate Drive authorization;
- the exact requested Drive scope and per-file limitations;
- what file data/metadata is accessed and for what purpose;
- where original files remain and whether contents are processed by AVENZERS servers;
- recipients/processors and sharing behavior;
- storage of connection credentials and revocation/disconnect;
- retention/deletion practices and how to contact the operator;
- Google's Limited Use requirements.
These statements must be accurate for the deployed product and available from the consent-screen homepage/privacy links. The actual legal entity/contact information must be complete.
8. Official Sources
- Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
- OAuth branding and homepage/privacy requirements: https://developers.google.com/identity/protocols/oauth2/production-readiness/brand-verification
- Google Drive authorization scopes: https://developers.google.com/workspace/drive/api/guides/api-specific-auth
- Google Drive API policies: https://developers.google.com/workspace/drive/api/terms
Review status: NOT YET VERIFIED OR APPROVED.