Google User Data Policy

This page is the authoritative disclosure of how Syncademia AI accesses, uses, stores, shares, retains, and deletes Google user data. It covers Google Sign-In and the separate Google Calendar OAuth flow, including the https://www.googleapis.com/auth/calendar.events scope.

Version 1.3 · Last updated August 19, 2026

1. Two separate OAuth flows

Google Sign-In identifies you. It requests OpenID, email, and basic profile (name, picture, and Google account identifier). It does not grant access to Google Calendar, Gmail, Drive, Contacts, or Tasks.

Google Calendar sync is a second, opt-in OAuth flow. You start it from Settings → Integrations. Signing in with Google never connects a calendar automatically. Connecting Calendar shows a second Google consent screen and requests the Calendar events scope listed below.

2. Scopes requested for Calendar sync

When you connect Google Calendar, Syncademia AI requests exactly these scopes. The product depends on calendar.events to read existing events and to create, update, or delete only the events Syncademia itself adds.

ScopeWhy we need it
OpenIDopenidConfirms which Google account authorized the connection.
Email addressemailShows you which Google account is connected, and matches it to your account.
Basic profileprofileDisplays your name and picture on the connected-account screen.
Google Calendar eventshttps://www.googleapis.com/auth/calendar.eventsReads your existing events so your Syncademia schedule reflects real conflicts, and creates, updates, or deletes only the events Syncademia itself adds when you sync a task or class.

Syncademia AI does not request Gmail, Google Drive, Google Contacts, Google Tasks, or any other Google Workspace content.

3. Calendar operations

  • Read: we read events in the calendars you authorize so Syncademia can show your real schedule and avoid placing study time on top of existing commitments.
  • Create: we create Google Calendar events only when you ask us to — for example, syncing an assignment due date or a class time.
  • Update: we update events that Syncademia created, so changing a task or class in Syncademia keeps the Google event accurate.
  • Delete: we delete events that Syncademia created when you remove the matching task or class. We do not delete or rewrite events that Syncademia did not create.

Calendar content is not used for advertising or profiling, is not sold, and is not used to train generalized AI or machine learning models. Where an AI feature needs schedule context to answer you, only the minimum necessary details are sent to the AI provider listed in our AI provider disclosure.

4. Token storage

After you complete the Calendar OAuth consent screen, Google issues an access token and a refresh token. Syncademia stores both encrypted at rest in the oauth_connection_status table for your user, with provider set to Google. Tokens are transmitted only over HTTPS, are never sent to the browser, and are never shared with advertisers or other third parties.

Access to production systems holding these tokens is limited to authorized personnel. Tokens exist solely to keep the Calendar connection working.

5. Retention

Google Sign-In profile data is retained while your Syncademia AI account is active. Calendar access tokens and refresh tokens are retained only while the Calendar integration remains connected.

Disconnecting Google Calendar deletes the stored tokens for that connection immediately and stops further read, create, update, and delete operations. When you delete your Syncademia AI account, Google user data is deleted or de-identified within 30 days, unless retention is required for legal, billing, security, backup, fraud prevention, or dispute resolution purposes.

6. Sharing

Google user data may be processed by the service providers needed to operate Syncademia AI, such as authentication, database, hosting, and security providers. Syncademia AI does not share Google user data with advertisers or data brokers.

7. Revocation

You can disconnect Google Calendar at any time from Settings → Integrations. Disconnect deletes the stored tokens and stops all further calendar reads and writes. Events already created in your Google Calendar remain there unless you delete them.

You can also revoke access from your Google Account third-party access settings. Revoking access there stops future calendar sync and Google Sign-In, but it does not delete your Syncademia AI account.

8. Deletion

Disconnecting Calendar deletes Calendar tokens. Deleting your Syncademia AI account deletes or de-identifies remaining Google user data within 30 days, subject to the legal holds listed under Retention.

To delete your account and associated data, use the in-app deletion tools or email syncademiaai@gmail.com with the subject "Data Deletion Request."