Skip to content

Google API disclosure

How Luxa uses Google data

Luxa connects Google Drive and Gmail to user-facing workspace features. Access is optional, separately authorized, and controlled by the user.

Effective and last updated: July 30, 2026

Authorized access and purpose

Google Drive

drive.file

Access files created by Luxa and files the user explicitly selects or authorizes. This supports visible search, folder, upload, download, move, rename, share, and import actions.

Gmail

gmail.modify

Read and search mail, show a selected message, create drafts, send, reply, forward, attach authorized Drive files, and save attachments selected by the user.

Google identity

openid · email · profile

Verify the connected Google account and display its email, name, and profile image to the signed-in Luxa user.

What happens when a user connects

  1. The user selects a Google feature inside Luxa.
  2. Google shows the account, requested permissions, and consent controls.
  3. After consent, Google returns access and refresh credentials to Luxa’s server.
  4. Luxa encrypts those credentials with AES-256-GCM before database storage. Browser clients do not receive stored token ciphertext.
  5. Luxa uses the authorization only when the signed-in user invokes a corresponding Drive or Gmail feature.

Google Drive behavior

  • Luxa does not request unrestricted access to every file in the user’s Drive.
  • Luxa works with files it created and files the user selected or authorized.
  • Workspace and project bindings record where a user intentionally connected a Drive file inside Luxa.
  • If a user imports a file, Luxa creates a separate private copy so the Luxa project can continue after Google is disconnected.
  • Moving, renaming, sharing, downloading, and uploading occur only after a visible user action.

Gmail behavior

  • Luxa lists and opens Gmail messages only for the connected user and excludes Spam and Trash from normal inbox listing.
  • Drafting, sending, replying, and forwarding happen only after the user initiates and confirms the action inside Luxa Mail.
  • A Gmail attachment is copied into Luxa only after the user selects that attachment and destination.
  • Drive files are attached to an email only after the user selects them in the compose interface.
  • Luxa does not permanently delete Gmail messages while bypassing Trash.

Storage and retention

OAuth tokens are stored in encrypted form for as long as the Google connection remains active. Disconnecting Google deletes the stored connection and asks Google to revoke the authorization.

A Drive file or Gmail attachment intentionally imported into Luxa becomes a separate Luxa file. Disconnecting Google does not silently delete those project assets; the user can delete them independently or request deletion.

Limited Use commitments

No sale of Google user data

No advertising or retargeting use

No credit or lending decisions

No generalized or personalized AI-model training

No human access without affirmative permission, a security need, or legal requirement

No transfer except to provide the visible user-requested feature, security, law, or a consented corporate transaction

Luxa’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

User controls

  • Connect Google Drive and Gmail only when needed.
  • Review the connected account and authorized services in Luxa Office settings.
  • Disconnect Google and revoke the authorization.
  • Revoke Luxa directly from the user’s Google Account permissions.
  • Delete copied Luxa files without changing the original Google file or email.
  • Request deletion or ask a privacy question using the contact below.

See Data Controls and Deletion for step-by-step instructions.

Contact

Google data-use questions: elijahisrael@luxastudiocos.net