Google API Disclosure

Google data only for the connected workspace.

MarketingOS uses Google API data only when a user explicitly connects a Google account.

01

Exactly eight incrementally requested scopes

Each visible capability group requests only its exact scope: gsc.read uses webmasters.readonly, gsc.sitemaps.manage uses webmasters, ga4.read uses analytics.readonly, ga4.measurement.manage uses analytics.edit, gtm.read uses tagmanager.readonly, gtm.workspace.edit uses tagmanager.edit.containers, gtm.version.create uses tagmanager.edit.containerversions, and gtm.version.publish uses tagmanager.publish. Previously granted scopes are not requested again; a write capability fails closed when its read prerequisite is missing. After authorization, the three read groups may run; the five write groups are never autonomous.

02

Data types and uses

GSC provides raw property, sitemap and URL Inspection data plus aggregated Search Analytics by query and page with clicks, impressions, CTR and position. GA4 provides account, property, data stream and key event metadata plus aggregated reports for landing pages, channels, users, sessions, events and key events, but not user-level raw event data. GTM provides configuration data for accounts, containers, workspaces, tags, triggers, variables and versions. MarketingOS uses these data only in the connected workspace for diagnostics, prioritization, visible setup plans, approved execution, receipts and post-change measurement.

03

Controlled writes

GSC sitemap actions, GA4 Admin changes and GTM changes require an exact target and payload preview, a one-time approval, at most one provider attempt, a receipt, a technical provider post-check and rollback where supported or explicit recovery. A changed preview invalidates the approval. Creating a GTM version and GTM publish remain separate actions; publish requires a second, separate approval. General CMS, Bing and other writes stay closed without their own connector contract. MarketingOS does not manage ads or spend ad budget.

04

Managed broker boundary and protection

The standard path uses the managed connector at app.scilipoti.de. Google access and refresh tokens remain there inside the AES-256-GCM-encrypted persistent proxy state; the master key is readable only by the proxy service identity. Tokens are never returned to the browser interface, Local Agent, OpenClaw or Hermes agents, or a model. The connector accepts only tenant-bound and workspace-bound signed requests and Google operations from a fixed allowlist of named operations; token fields are excluded from responses.

05

Optional model transfer and consent

Model transfer is off by default. Only the workspace owner can separately opt in, and the owner can immediately disable new transfers at any time. While that consent remains active, MarketingOS may transfer only the following Google API data and data derived from them for the current or later connected Google Search Console (GSC), Google Analytics 4 (GA4) and Google Tag Manager (GTM) connectors in that workspace: GSC property, sitemap and URL Inspection data and aggregated Search Analytics; GA4 account, property, data stream and key event metadata and aggregated reports, never user-level raw events; GTM account, container, workspace, tag, trigger, variable and version configuration; and the derived workspace artifact types goal metric, plan, evidence including diagnostics, claim, action, execution receipt, observation, outcome and connector only as needed for visible workspace-related MarketingOS analysis, prioritization, recommendations and drafts. Workspace context and goals are non-transferable local control data. The sole recipient is the Controlled OpenClaw model path displayed in Google permissions with its exact provider origin, model ID and descriptor digest; Hermes Direct is not eligible for this transfer. The model provider processes transferred data under its own contract and privacy notice. Google tokens and credentials are not transferred. Every provider request containing Google-derived data requires a fresh one-time authorization immediately before transfer; new and replayed requests fail closed after consent is disabled. If disable wins before that authorization commit, no transfer occurs. A request already one-time authorized and durably committed to immediate provider handoff before disable may still be transmitted and completed while the UI shows draining. Consent lasts until withdrawn and covers only this closed list of data types and purposes. New data types or uses require a new disclosure and consent. MarketingOS cannot delete copies already stored by the model provider; its deletion and retention controls apply to those copies. MarketingOS does not use the data for MarketingOS advertising, sale or general-purpose model training.

06

Review status

The managed Google connector is undergoing live validation only on dedicated reviewer infrastructure and is not a customer release. Google review and general customer release remain open. This state proves neither Google approval nor general customer availability.

07

Limited Use and exclusions

MarketingOS use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Apart from the separately consented transfer to the exact Controlled OpenClaw model path bound in Google permissions as described above, MarketingOS does not sell Google user data, use it for advertising, transfer it to other or unrelated third parties, train general-purpose AI models with it, or access Gmail or Drive.

08

Retention, disconnect, revocation and deletion

OAuth state expires after ten minutes. Access and refresh tokens remain inside the AES-256-GCM-encrypted server-side proxy state until confirmed provider revocation or local connector deletion. The proxy does not durably store raw Google API responses. Encrypted operational backups of the reviewer installation expire within seven days. Disconnect disables execution but retains the credential envelope and connection record and does not revoke Google consent. Provider revocation disables first, asks Google to revoke access and deletes the credential envelope after a confirmed result; the user can also inspect or remove Google's account permission at https://myaccount.google.com/permissions. Local deletion does not revoke Google consent: a digest-bound inventory preview must be confirmed before the credential envelope or managed binding, raw Google data, and goal metrics, plans, evidence, claims, actions, execution receipts, observations and outcomes derived exclusively or partly from that data are deleted. A sanitized connector shell remains for later setup. Payload-free guardian and audit metadata remains as the integrity and deletion record for the lifetime of the workspace: workspace and artifact IDs, types, versions, content hashes, scope, disclosure and provider digests, timestamps, event states and the minimal deletion receipt; it contains no Google payloads or tokens. Local Google-data deletion does not delete Google-derived content already persisted in OpenClaw transcripts or OpenClaw workspace state. That runtime copy must be deleted separately through the root-authenticated OpenClaw lifecycle deletion or runtime controls; after model consent is disabled or local deletion completes, it remains blocked from all new provider egress. The reviewer alpha has no automatic 400-day deletion for that metadata. Local Google-data deletion is not complete workspace erasure; a complete MarketingOS workspace erasure request goes to the privacy contact. Pending OAuth states become invalid immediately through the changed authorization epoch and expire within ten minutes. Later customer-controlled local backups and copies already stored by the model provider remain under the control of their respective operator and are not deleted automatically. Ambiguous revocation outcomes are safely fenced and are not retried blindly.

09

Contact

Questions about Google API data use go to francesco@scilipoti.de.