For CASA (Cloud App Security Assessment) submission and Google OAuth verification.
Publish this paragraph verbatim on a page accessible from the Pincer website footer (same page as, or adjacent to, the privacy policy). Google's verification reviewers search for this exact language.
Pincer's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Pincer's access to, and use of, Google user data is limited to providing or improving user-facing features of the Pincer application that are prominent from the requesting application's user interface. Pincer does not:
- use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models;
- transfer Google user data to third parties except as necessary to provide or improve user-facing features of the Pincer application, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior user notice;
- use Google user data for serving advertisements; or
- allow humans to read Google user data, except with the affirmative agreement of specific users for support (addressing a support ticket you have filed), where required by law, for security purposes such as investigating abuse, or for internal operations using data that has been aggregated and anonymized.
| OAuth scope | Why Pincer requests it | User-facing feature |
|---|---|---|
https://www.googleapis.com/auth/gmail.readonly |
Read messages so the agent can draft replies | Approval inbox rendering, agent draft generation |
https://www.googleapis.com/auth/gmail.send |
Send drafts the user has approved | "Approve" action in the approval inbox |
https://www.googleapis.com/auth/gmail.modify |
Apply labels, mark read/unread after user approval | Agent housekeeping after an action |
https://www.googleapis.com/auth/userinfo.email |
Identify the account being connected | Enrollment flow confirmation |
No other Google API scopes are requested.
No other third party (including web search providers, analytics, crash reporting) receives Gmail data under any circumstance.
No Pincer employee or contractor reads Gmail content as part of normal operations. Human access occurs only in the following cases, each logged and auditable:
For questions about Pincer's Gmail API usage, verification reviewers should contact rohbotics@gmail.com (subject: "Google API Verification"). We respond within 3 business days.
https://pincer-dzh.pages.dev/gmail-api-disclosure (final custom domain will be updated before submission)