Google API Services Disclosure
Last updated on July 26, 2026
This page describes how OOMOL accesses, uses, stores, and shares data obtained through Google APIs, and states OOMOL’s compliance with the Limited Use requirements of the Google API Services User Data Policy.
It supplements the OOMOL Privacy Policy and the OOMOL Terms of Service. Where this page and the Privacy Policy describe the same practice, both apply.
1. Limited Use compliance statement
OOMOL’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For Google Workspace services such as Gmail, Google Drive, Google Calendar, Google Sheets, Google Docs, and Google Slides:
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
For Google Photos:
The use of information received from Photos APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
2. What OOMOL is
OOMOL is a connection layer between the tools you already use and the programs you run. It has three parts:
- OOMOL Console, where you connect accounts and manage permissions, logs, and usage.
ooCLI, a command-line program that runs on your machine and calls connected apps.- OOMOL Connector, the hosted service that holds credentials and executes API calls on your behalf. You can also run it yourself as self-hosted OpenConnector.
You connect a Google account by completing Google’s OAuth consent flow in OOMOL Console. OOMOL requests only the scopes required by the Google services you choose to connect, and stores the resulting credential so later actions can run without asking you to sign in again.
Google services available through OOMOL include Gmail, Google Drive, Google Calendar, Google Sheets, Google Docs, Google Slides, Google Forms, Google Tasks, Google Photos, YouTube, Google Analytics, Google Search Console, and Google BigQuery.
3. How a request reaches Google
Every call OOMOL makes to a Google API corresponds to a specific action you invoked, such as gmail.get_message or googledrive.download_file. OOMOL adds the credential you authorized, calls the Google API, and returns the response to whoever invoked the action.
OOMOL does not read your Google data on its own initiative. It calls a Google API only when:
- you run an action from
ooCLI, OOMOL Console, or the OOMOL HTTP API; or - a trigger you configured polls for new events on the schedule you set.
You can revoke either at any time by disconnecting the account or deleting the trigger.
When an AI agent invokes OOMOL
Most people drive oo CLI through an AI agent such as Claude Code, Codex, or Cursor. This is a choice you make, not a requirement: oo CLI, OOMOL Console, and the OOMOL HTTP API each work on their own.
When you do use an agent:
- The agent runs in your environment, under your own model provider account, and issues the same CLI commands you could type yourself.
- OOMOL returns the Google API response to the process that invoked the action. Data enters the agent’s context because you directed it there.
- Your agreement with your model provider governs how that provider handles the data.
- The agent never receives your Google credentials. OOMOL injects them server-side; raw tokens are not exposed to the caller.
- Actions can be allowed or blocked per connection in OOMOL Console, so you decide which Google operations an agent is able to run at all.
4. Artificial intelligence and machine learning
OOMOL does not transfer, sell, or use Google user data to create, train, or improve a machine learning or artificial intelligence model. This includes foundational, generalized, and frontier models.
Specifically:
- Google user data is never added to a training corpus or a fine-tuning dataset.
- OOMOL does not build embeddings, vector indexes, or other derived datasets from Google user data. Action search in OOMOL is a keyword index over OOMOL’s own catalog of action names and schemas; it does not index your data.
- OOMOL does not store Google user data in conjunction with any model.
- The OOMOL Connector runtime makes no model calls. It authenticates the request, calls the Google API, and returns the response.
- OOMOL’s hosted AI services, such as image, video, and speech generation, receive only the input a caller places in the request. They have no access to your connected accounts and cannot read your Google data.
If an AI agent you run receives Google data through OOMOL, it does so at inference time to complete the action you asked for, under your own model provider account, and under your agreement with that provider.
5. Human access to Google user data
OOMOL does not allow humans to read Google user data, unless:
- OOMOL has obtained and documented your explicit consent or affirmative agreement to view specific messages, files, or other data, for example to help you re-access a service;
- the data, including derivations, is aggregated and anonymized and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements;
- it is necessary for security purposes, such as investigating a bug or abuse; or
- it is necessary to comply with applicable laws or regulations.
6. Transfers, sale, and advertising
OOMOL does not transfer or sell Google user data to advertising platforms, data brokers, or information resellers. OOMOL does not use Google user data for serving ads, including retargeting and personalized or interest-based advertising, and does not use it to determine credit-worthiness or for lending purposes.
Google user data is transferred only:
- to provide the action you invoked, which means sending the request and its results between Google, OOMOL Connector, and the client that invoked the action;
- for security purposes, such as investigating abuse;
- to comply with applicable laws; or
- as part of a merger, acquisition, or sale of assets, after obtaining your explicit prior consent.
Site analytics do not receive Google user data. OOMOL’s product analytics record which action ran, whether it succeeded, and how long it took.
7. Storage and retention
Credentials. OAuth access and refresh tokens are encrypted at rest and decrypted only in memory when an action runs. They are never returned to oo CLI, an agent, or your browser. Disconnecting an account deletes the stored credential.
Google user data. OOMOL reads Google user data only to carry out the action you invoked, and returns the result to the client that invoked it. OOMOL does not collect Google user data for its own purposes and does not use it to build any product, dataset, or model. The infrastructure providers that operate OOMOL are described in the Privacy Policy.
Self-hosting. When you run OpenConnector yourself, credentials and data stay in your own environment and OOMOL does not receive them.
OOMOL does not scrape Google services and does not build databases of Google user data, including databases for model training purposes.
8. Managing and revoking access
- Disconnect a Google account from Connections in OOMOL Console. This deletes the stored credential; actions on that account stop working immediately.
- Review or block individual actions for a connection in OOMOL Console.
- Revoke OOMOL’s access directly from Google at Third-party apps & services.
- Request deletion of your OOMOL account and associated data as described in the Privacy Policy.
9. Contact
Questions about this disclosure or about how OOMOL handles Google user data:
Privacy: privacy@oomol.com Data Protection Officer: dpo@oomol.com Support: support@oomol.com
Oomol Studio Limited, China Resources Building, 26 Harbour Road, Wan Chai, Hong Kong