Google API Disclosure & Limited Use Policy
Last Updated: September 24, 2026 • In accordance with Google Cloud Trust & Safety Requirements
1. Overview & Purpose
AutoJawab.online integrates with Google Cloud Platform APIs to allow verified business owners, agency managers, and enterprise brands to seamlessly manage, analyze, and reply to customer reviews published on their Google Business Profiles (formerly Google My Business).
This disclosure explicitly outlines the Google API scopes we request, why we require them, how your Google account data is processed and stored, and our adherence to Google's Limited Use requirements.
“AutoJawab's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.”
- We never use Google user data to serve advertisements or retarget users.
- We never sell, rent, or transfer Google user data to data brokers or advertising exchanges.
- We never use your private Google Business reviews to train generalized public machine learning models.
- Human review of your Google data is strictly restricted unless you explicitly request technical support or troubleshooting.
2. Requested Google OAuth Scopes & Justification
When connecting your Google account through our secure OAuth 2.0 flow, AutoJawab requests access only to the following specific scopes:
https://www.googleapis.com/auth/business.manageCore FunctionalityWhy we need this: Allows AutoJawab to:
- Fetch the list of Google Business Profile locations you manage (`accounts/{accountId}/locations`).
- Fetch customer reviews, reviewer ratings, and timestamps to display on your AutoJawab dashboard.
- Publish your authorized or automated review reply comment back to Google (`reviews/{reviewId}/reply`).
- Retrieve the official Google direct review link (`newReviewUri`) to generate your custom printable QR review standee card.
openid, email, profileAuthenticationWhy we need this: Used exclusively to authenticate your identity, display your avatar/name, and ensure only authorized team members can manage your connected business locations.
3. Data Security, Token Storage & Encryption
We treat OAuth credentials and tokens with bank-grade security:
- Token Encryption: OAuth access tokens and refresh tokens are encrypted at rest using AES-256 encryption.
- Transit Security: All API communication between AutoJawab, your browser, and Google servers occurs strictly over HTTPS/TLS 1.3.
- Access Isolation: Multi-tenant isolation ensures that no other user can access or view your locations, reviews, or responses.
4. How to Disconnect & Revoke Google Access
You maintain complete sovereignty over your Google account. You may disconnect AutoJawab at any moment:
Option A: Direct from your Google Account
- Visit your Google Account Security page: Google Connected Apps
- Find AutoJawab in the list of Third-party apps with account access.
- Click Remove Access. Google will instantly invalidate all tokens.
Option B: Request full deletion
Email us at support@autojawab.online with subject “Delete My Account”. We will purge all cached locations, review history, and OAuth tokens from our databases within 24 hours.
5. Security & Compliance Inquiries
For any questions regarding Google API compliance, data protection, or security audits, contact our designated Data Protection Officer:
Compliance Officer: AutoJawab Legal & Trust Team
Email: support@autojawab.online