Google API Services Privacy Policy
Last updated: July 22, 2026
Overview
This policy describes how Mesh ("we," "us," or "our") accesses, uses, stores, and shares Google user data when you connect your Google Calendar or Gmail account to our platform. This policy supplements our general Privacy Policy.
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. What Google Data We Access
Depending on which Google connections you enable, we request the following OAuth scopes:
- Google Calendar (read-only): We access your calendar event details including event titles, dates, times, attendees, meeting links, and descriptions. We use the
calendar.events.readonlyscope. - Gmail (send-only): We can send an email message on your behalf, but only a message you have individually reviewed and approved. We use the
https://www.googleapis.com/auth/gmail.sendscope. This scope does not allow Mesh to read your email, list your inbox, or access any existing messages.
We do not request write access to your calendar: we cannot create, modify, or delete your calendar events. We do not request any Gmail read scope: Mesh cannot read, search, or download your Gmail.
2. How We Use Google Data
We use your Google data exclusively for the following purposes, depending on which connections you enable:
- Meeting Scheduling: Displaying your upcoming meetings within the Mesh dashboard so you can manage recording and preparation.
- Meeting Preparation: Using meeting details (attendees, agenda) to generate AI-powered meeting prep briefs with relevant client context.
- Participant Identification: Matching calendar attendees with your existing contacts and clients to provide context during meetings.
- Sending Email You Approve: When you connect Gmail and approve a specific message, we send that message on your behalf through your own Gmail account. Every send requires your explicit approval; Mesh never sends without you, and there is no automated or bulk sending.
We do not use Google data for advertising, market research, training or improving generalized AI or machine learning models, or any purpose unrelated to providing the Mesh service to you.
3. How We Store Google Data
- Calendar event data is stored in our secure, encrypted PostgreSQL database with row-level security isolating each organization's data.
- OAuth tokens (access and refresh tokens) for both the Calendar and Gmail connections are stored encrypted and are used only to maintain the connection you enabled.
- Because the Gmail connection is send-only, Mesh does not download or store the contents of your inbox. When you send an approved message, we store that message's content (encrypted) and its delivery metadata as part of your business records.
- We retain calendar data only for as long as your Google Calendar connection is active. When you disconnect, we delete your stored calendar data and revoke the OAuth tokens.
4. How We Share Google Data
We do not sell, rent, or share your Google data with third parties, except:
- AI Processing: Meeting details (such as attendee names and agenda topics) may be sent to our AI/LLM providers solely to generate meeting preparation briefs. No full calendar exports are shared - only the minimum data needed for the specific meeting being prepared.
- Infrastructure Providers: Our hosting and database providers process data on our behalf under strict contractual obligations and do not have independent access to your data.
We do not allow any third party, including AI/LLM providers, to use your Google data for purposes other than providing the Mesh service to you.
Mesh does not use any data received from Google APIs to train, retrain, or improve generalized artificial intelligence or machine learning models. Any email content Mesh drafts is generated from your own Mesh workspace data (such as meeting notes and client records), not from data read out of Gmail; the Gmail connection is send-only and grants Mesh no read access to your mailbox.
5. Limited Use Disclosure
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google data to provide and improve the user-facing features of Mesh that are visible to you.
- We do not transfer Google data to third parties except as necessary to provide the service, as required by law, or with your explicit consent.
- We do not use Google data for serving advertisements.
- We do not allow humans to read your Google data unless you have given affirmative consent for a specific purpose (e.g., support request), it is necessary for security purposes, or it is required by law.
6. Revoking Access
You can disconnect your Google Calendar or Gmail connection at any time by:
- Going to Settings in your Mesh dashboard and disconnecting the Google Calendar or Gmail integration.
- Removing Mesh from your Google Account permissions.
Disconnecting from Settings clears the stored OAuth tokens immediately. We delete your stored Google data and OAuth tokens within 30 days of revocation.
7. Contact Us
If you have questions about how we handle your Google data, please contact us:
- Email: privacy@meshfp.com
See also our general Privacy Policy for full details on how Mesh handles all user data.