Legal information
How S5 Respons uses Google data
Last updated 3 August 2026
Separate and optional connections
“Continue with Google” on the sign-in page identifies the user and opens the correct S5 workspace. It does not grant access to Gmail or Google Calendar. A business administrator may later connect Gmail and Google Calendar as separate, optional integrations under Settings → Integrations, using separate consent screens.
Gmail permissions
S5 Respons requests openid, email and profile to verify the selected account, and https://www.googleapis.com/auth/gmail.send to send responses the user has explicitly reviewed and approved. The Gmail connection cannot read, search, modify or delete the inbox.
How Gmail data is used
Account identity is used to display and verify the connected sender. gmail.send is used only when an authorized user sends an approved response or starts an explicit sender test. S5 Respons records the provider confirmation, message ID and thread ID to show truthful delivery status and prevent duplicates.
Google Calendar permissions
The Calendar integration is optional and separate from Gmail. The Gmail permission does not grant calendar access. When an administrator chooses to connect Google Calendar, S5 Respons requests these permissions:
https://www.googleapis.com/auth/calendar.calendarlist.readonlyhttps://www.googleapis.com/auth/calendar.events.owned
How the calendar list is used
calendar.calendarlist.readonly retrieves the calendar list so S5 Respons can identify calendars owned by the selected Google account. Shared calendars where the account only has write access are not shown and cannot be selected. S5 Respons synchronizes only owned calendars the user actively selects.
How calendar events are used
calendar.events.owned checks availability and conflicts in the selected owned calendar and creates or updates appointments approved by a user. An S5-managed appointment can also be cancelled in Google after explicit approval. External events are stored locally as minimized busy blocks without title, description or location.
AI and Google data
S5 Respons uses the OpenAI API for analysis and drafts. OAuth tokens, Gmail API data, raw calendar events, calendar IDs and provider IDs are not sent to OpenAI. When AI needs calendar evidence, it receives only a minimized result such as whether the check succeeded and whether availability was found. Customer enquiries submitted or explicitly forwarded by the business may be used in an AI draft; this is not Gmail inbox access through the Gmail API.
Storage, security and Limited Use
Reusable OAuth tokens are encrypted and restricted to the correct signed-in user and Google account, business and integration. Access is role-controlled, and connection, disconnection, sending and calendar actions are logged. Google data is not sold, used for advertising or used to train or improve general AI models.
S5 Respons' use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoke access
An administrator can disconnect Gmail or Google Calendar separately in S5 Respons. Reusable local access secrets are removed when they are no longer used by an active connection, and S5 Respons attempts to revoke the relevant access with Google. Access can also be removed directly in the Google account. See the disconnection and data deletion instructions.