Separate connection for each service
Drive, Gmail, Calendar, and YouTube are authorized separately so one feature does not silently unlock another.
Google connections are optional. LumenQube asks for a permission only when you connect the matching feature, uses it to complete actions you request, and lets you disconnect at any time.
Drive, Gmail, Calendar, and YouTube are authorized separately so one feature does not silently unlock another.
The table below explains each permission and its use. Google's per-file Drive permission also permits editing and deletion of eligible files.
Sending mail, creating events or documents, RSVPing, and uploading videos require an explicit user action or approval.
Disconnecting deletes LumenQube's stored authorization for that service and asks Google to revoke it once no other Google service you connected relies on it. Access can also be revoked in your Google Account.
You start from the relevant LumenQube feature.
Google shows the account and requested permissions.
LumenQube calls Google only for the action you request.
The encrypted server-side authorization record is deleted.
| Google service and OAuth scope | User-facing use in LumenQube | Why a narrower permission is not enough |
|---|---|---|
| Google account sign-in openid profile | Sign in to a LumenQube account and display the identity returned for that sign-in. | This sign-in request is separate from authorizing Drive, Gmail, Calendar or YouTube and does not grant their API permissions. |
| Google connector identity openid | Show which Google account authorized the selected Drive, Gmail, Calendar or YouTube connector. | These identity scopes accompany that connector's API scopes; profile is not requested by the current connector declaration. |
| Google Drive https://www.googleapis.com/auth/drive.readonly | Search the user's Drive, read a file the user selects from results, import Google Sheets or CSV data, and refresh an explicitly connected spreadsheet. | The feature searches files the user already has across Drive. drive.file alone cannot discover or read those existing files unless each is first opened with LumenQube. |
| Google Drive https://www.googleapis.com/auth/drive.file | Create a new Google Doc only when the user approves a “create Drive document” action, and access files created or opened through LumenQube. | The read-only scope cannot create a document. drive.file also permits editing and deletion within the files created by or authorized for LumenQube. It does not grant general write or delete access across Drive. |
| Gmail https://www.googleapis.com/auth/gmail.readonly | Search the user's mailbox and read a message the user asks LumenAgent to summarize or use in a task. | Metadata-only access does not provide the message body required for the user-requested reading and summarization feature. LumenQube does not request modify or delete access. |
| Gmail https://www.googleapis.com/auth/gmail.send | Send a new email or reply after LumenQube shows the action and the user approves it. | This is Google's send-only permission. It does not allow LumenQube to edit mailbox state or delete messages. |
| Google Calendar https://www.googleapis.com/auth/calendar.events https://www.googleapis.com/auth/calendar.events.freebusy | List and search events, check availability, create an event the user approves, and RSVP to an event at the user's direction. | The feature needs both event reading and event changes. LumenQube does not request access to Calendar settings or unrelated Google account data. |
| YouTube https://www.googleapis.com/auth/youtube.upload | Upload only the finished video the user chooses from LumenDesign, with the title, description, tags, audience, and visibility the user reviews. | This is Google's upload-only scope. It does not grant permission to read, edit, or delete the user's existing videos. |
LumenSheets can also bring reporting data from Google Analytics, Search Console, Google Ads and a chosen Google Sheets range into a spreadsheet table, and refresh it. These sources are authorized separately, through a separate Google OAuth client, only when you add one to a workbook. They are used only to fill and refresh the tables you set up; LumenAgent does not use them.
| Google service and OAuth scope | User-facing use in LumenQube | Why a narrower permission is not enough |
|---|---|---|
| Google Analytics 4 https://www.googleapis.com/auth/analytics.readonly | List the properties you can access and read the report you configure for one of them into a table. | This is Google's read-only Analytics scope. LumenQube cannot change Analytics settings or data. |
| Google Search Console https://www.googleapis.com/auth/webmasters.readonly | List your verified sites and read search performance for the site you choose. | This is the read-only Search Console scope. LumenQube cannot change site settings or submit anything. |
| Google Ads https://www.googleapis.com/auth/adwords | List the accounts you can access and read the performance report you configure for one of them. | Google Ads offers no read-only scope. LumenQube only sends report queries; it never creates or changes campaigns, budgets or ads. |
| Google Sheets https://www.googleapis.com/auth/spreadsheets.readonly | Read the tab and range you choose from an existing spreadsheet into a table. | Reading a spreadsheet you did not create with LumenQube needs a Sheets read scope; drive.file cannot reach it. |
| Google Sheets https://www.googleapis.com/auth/spreadsheets (only when you turn on write-back) | Write your edits back to that same range when you push them. | The read-only scope cannot write. It is requested only when you turn write-back on for a connection; reading never asks for it. |
LumenQube's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and, for Google Workspace data, the Google Workspace user data and developer policy, including their Limited Use requirements. This statement describes our required handling of Google user data; it is not a statement that Google has approved every OAuth client or requested scope.
These are the scopes requested by the current product source. A requested or internally documented scope is not the same as a scope submitted to or approved by Google; current provider-review status must be evidenced separately.
For the complete legal disclosure, including subprocessors, security, retention, international transfers, and privacy rights, read our Privacy Policy. For help connecting or disconnecting a service, contact support@lumenqube.com.
Explore the broader privacy model or get help with connecting and disconnecting a Google service.