Google integrations · Reviewed September 5, 2026

Google access, explained clearly.

Google connections are optional. LumenQube asks for a permission only when you connect the matching feature, uses it to complete actions you request, and lets you disconnect at any time.

In context

Separate connection for each service

Drive, Gmail, Calendar, and YouTube are authorized separately so one feature does not silently unlock another.

Least privilege

Permissions map to visible features

The table below explains each permission and its use. Google's per-file Drive permission also permits editing and deletion of eligible files.

User control

Approval before consequential actions

Sending mail, creating events or documents, RSVPing, and uploading videos require an explicit user action or approval.

Revocable

Disconnect whenever you choose

Disconnecting deletes LumenQube's stored authorization for that service and asks Google to revoke it once no other Google service you connected relies on it. Access can also be revoked in your Google Account.

1. Choose Connect

You start from the relevant LumenQube feature.

2. Review Google consent

Google shows the account and requested permissions.

3. Use the feature

LumenQube calls Google only for the action you request.

4. Disconnect

The encrypted server-side authorization record is deleted.

Permissions and why they are necessary

Google service and OAuth scopeUser-facing use in LumenQubeWhy a narrower permission is not enough
Google account sign-in
openid
email
profile
Sign in to a LumenQube account and display the identity returned for that sign-in.This sign-in request is separate from authorizing Drive, Gmail, Calendar or YouTube and does not grant their API permissions.
Google connector identity
openid
email
Show which Google account authorized the selected Drive, Gmail, Calendar or YouTube connector.These identity scopes accompany that connector's API scopes; profile is not requested by the current connector declaration.
Google Drive
https://www.googleapis.com/auth/drive.readonly
Search the user's Drive, read a file the user selects from results, import Google Sheets or CSV data, and refresh an explicitly connected spreadsheet.The feature searches files the user already has across Drive. drive.file alone cannot discover or read those existing files unless each is first opened with LumenQube.
Google Drive
https://www.googleapis.com/auth/drive.file
Create a new Google Doc only when the user approves a “create Drive document” action, and access files created or opened through LumenQube.The read-only scope cannot create a document. drive.file also permits editing and deletion within the files created by or authorized for LumenQube. It does not grant general write or delete access across Drive.
Gmail
https://www.googleapis.com/auth/gmail.readonly
Search the user's mailbox and read a message the user asks LumenAgent to summarize or use in a task.Metadata-only access does not provide the message body required for the user-requested reading and summarization feature. LumenQube does not request modify or delete access.
Gmail
https://www.googleapis.com/auth/gmail.send
Send a new email or reply after LumenQube shows the action and the user approves it.This is Google's send-only permission. It does not allow LumenQube to edit mailbox state or delete messages.
Google Calendar
https://www.googleapis.com/auth/calendar.events
https://www.googleapis.com/auth/calendar.events.freebusy
List and search events, check availability, create an event the user approves, and RSVP to an event at the user's direction.The feature needs both event reading and event changes. LumenQube does not request access to Calendar settings or unrelated Google account data.
YouTube
https://www.googleapis.com/auth/youtube.upload
Upload only the finished video the user chooses from LumenDesign, with the title, description, tags, audience, and visibility the user reviews.This is Google's upload-only scope. It does not grant permission to read, edit, or delete the user's existing videos.

Business data sources in LumenSheets

LumenSheets can also bring reporting data from Google Analytics, Search Console, Google Ads and a chosen Google Sheets range into a spreadsheet table, and refresh it. These sources are authorized separately, through a separate Google OAuth client, only when you add one to a workbook. They are used only to fill and refresh the tables you set up; LumenAgent does not use them.

Google service and OAuth scopeUser-facing use in LumenQubeWhy a narrower permission is not enough
Google Analytics 4
https://www.googleapis.com/auth/analytics.readonly
List the properties you can access and read the report you configure for one of them into a table.This is Google's read-only Analytics scope. LumenQube cannot change Analytics settings or data.
Google Search Console
https://www.googleapis.com/auth/webmasters.readonly
List your verified sites and read search performance for the site you choose.This is the read-only Search Console scope. LumenQube cannot change site settings or submit anything.
Google Ads
https://www.googleapis.com/auth/adwords
List the accounts you can access and read the performance report you configure for one of them.Google Ads offers no read-only scope. LumenQube only sends report queries; it never creates or changes campaigns, budgets or ads.
Google Sheets
https://www.googleapis.com/auth/spreadsheets.readonly
Read the tab and range you choose from an existing spreadsheet into a table.Reading a spreadsheet you did not create with LumenQube needs a Sheets read scope; drive.file cannot reach it.
Google Sheets
https://www.googleapis.com/auth/spreadsheets (only when you turn on write-back)
Write your edits back to that same range when you push them.The read-only scope cannot write. It is requested only when you turn write-back on for a connection; reading never asks for it.

How Google user data is handled

  • Access and use. LumenQube accesses Google data only after the user connects that service and only to provide the visible feature described above.
  • Storage. OAuth access and refresh tokens are encrypted at rest in LumenQube's server-side vault. Google file, email, and calendar responses are not routinely retained as a separate server-side dataset. Content used in a document or task can remain in that document or task history. Cloud or mobile task history, sync, sharing and publishing can also store the relevant saved content on LumenQube's servers under those features' access controls and retention lifecycles.
  • AI-assisted tasks. When a user explicitly asks LumenAgent to summarize or transform connected content, the content needed for that request may be sent through LumenQube's managed backend to the AI processor identified in our Privacy Policy. It is used only to return that user-facing result, not for advertising or to train generalized AI models.
  • Sharing. LumenQube does not sell Google user data, use it for targeted advertising, or disclose it to data brokers. A service provider receives data only when needed to deliver the user-requested feature, protect the service, or comply with law.
  • Human access. LumenQube personnel do not read Google user data unless the user gives explicit permission for specific support, access is necessary to investigate abuse or a security incident, or access is required by law.
  • Retention and deletion. Disconnecting deletes the stored connector token record for that service and, once no other Google service you connected relies on the same authorization, asks Google to revoke it. Revoking access in your Google Account ends Google's authorization but does not itself delete LumenQube's stored record. A subsequent request that detects the ended grant marks the connection as needing reconnection; disconnect it to delete the record. Neither action erases previously saved documents, task histories, synced or shared content. Use their deletion controls or the account and data-deletion process; cloud copies and backups follow the retention policy. Local files remain under your control.

LumenQube's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and, for Google Workspace data, the Google Workspace user data and developer policy, including their Limited Use requirements. This statement describes our required handling of Google user data; it is not a statement that Google has approved every OAuth client or requested scope.

These are the scopes requested by the current product source. A requested or internally documented scope is not the same as a scope submitted to or approved by Google; current provider-review status must be evidenced separately.

Your controls

  1. Connect only the Google service you want from its feature in LumenQube.
  2. Review Google's consent screen before granting access.
  3. Review consequential actions in LumenQube before they are sent to Google.
  4. Use Disconnect in LumenQube to delete the stored connector authorization; LumenQube also asks Google to revoke the grant once no other Google service you connected relies on it. You can revoke LumenQube in your Google Account's third-party access controls at any time to end Google's grant.
  5. Request account and associated cloud-data deletion by emailing privacy@lumenqube.com.

For the complete legal disclosure, including subprocessors, security, retention, international transfers, and privacy rights, read our Privacy Policy. For help connecting or disconnecting a service, contact support@lumenqube.com.

Connect only what helps your workflow.

Explore the broader privacy model or get help with connecting and disconnecting a Google service.

Review Google data handlingSee retention, provider, and deletion details in one place.Open the policy → Get connection helpFind common fixes or reach the LumenQube support team.Visit support →