Agents built on Donkit can optionally be connected to Google Calendar, Google Sheets, Google Docs, and Google Drive (the "Google Workspace integration"). This section describes what we ask Google for, how the data we receive from Google APIs ("Google user data") is used, stored, and shared, and how you can withdraw access. It applies alongside the rest of this policy.
The integration is off until the owner of an agent enables it in the agent's Integrations settings, where the owner chooses, for each of the four services, whether the agent gets no access, read-only access, or read-and-write access. A Google account is connected only through Google's own sign-in and consent screen, which lists exactly the permissions requested; you can decline, grant only some of them, and connect a different Google account from the one you sign in to Donkit with. Signing in to Donkit with Google is separate from this integration: sign-in uses only your basic profile (name, email address, and profile picture) and grants no access to your Google Workspace data. The integration does not request access to Gmail.
What we ask permission for
When you connect from an agent, the consent screen asks only for the services and access levels that agent is configured to use. When you add a Google account directly to your Connections library, it asks for the full set below, so that the account can later be used by any agent you attach it to without a second consent. The permissions that can be requested are:
PermissionWhat it lets the agent do
Basic account information (openid, email)See the email address of the Google account you connected, so that you and the agent owner can tell which account is in use. Requested with every connection.
Google Calendar — readList events from your calendar within a time window.
Google Calendar — read & writeIn addition, create events and update existing ones. Attendees listed on an event see it on their own calendars.
Google Sheets — readRead a range of cells from a spreadsheet that you or the agent owner point the agent at.
Google Sheets — read & writeIn addition, write values to a range, append rows, and create new spreadsheets.
Google Docs — readRead the title and body of a document that the agent is pointed at.
Google Docs — read & writeIn addition, create documents and append text to them.
Google Drive — files the agent created or you opened with itList and upload files in Google Drive. This permission (drive.file) is limited to files the agent created or that you opened with Donkit; the agent cannot see, search, or download any other file in your Drive.
In chat and in workflow steps, the access level set by the agent owner is enforced on our side before every call: an agent configured for read-only access to a service cannot write to it, even if your Google account granted more. If an agent later needs a permission you have not granted, you are asked again through Google's consent screen; permissions are never widened silently.
How Google user data is used
We use Google user data solely to provide the user-facing features of the agent you connected it to, at your or the agent owner's request:
- In chat: when you ask an agent to do something that involves your calendar, spreadsheets, documents, or Drive files, the agent reads or writes the relevant data, and the result becomes part of that conversation.
- In workflows: a workflow step can read from or write to the connected services, within the access levels set by the agent owner, when a run is started by you, on a schedule you set up, or by a webhook you configured.
- When building an agent on a shared account: the owner's Google account can be read (never written to) by the Builder, so that it can inspect the spreadsheets and documents the owner names and configure the agent to use them.
- In an agent's own application code: where an agent includes a custom application built on Donkit, that application's server-side code can obtain a short-lived access token for the connected account and call Google's APIs directly, within the permissions you granted.
We do not use Google user data for advertising, for profiling, to determine creditworthiness, or for any purpose unrelated to the agent you connected it to, and we do not use it to develop, improve, or train generalized AI or machine-learning models (see "AI Model Training Policy" above).
Who can act on a connected account
The agent owner chooses one of two connection modes, which you can see before you connect:
- Each user connects their own account. Your Google account is used only for your own conversations with that agent and for workflow runs that act on your behalf. Other users of the agent cannot reach your data through it.
- One shared account. The agent owner connects a single Google account that the agent uses for everyone who talks to it and for every workflow run. Anyone able to use that agent can therefore cause it to read from, or write to, the owner's calendar, spreadsheets, documents, and Drive files within the access levels the owner set. This is the owner's decision — Donkit shows the owner a warning when such an agent is shared or published — and the owner is the controller of the data processed this way.
A Google account you connect is kept in your Connections library and can be reused by other agents you attach it to, each within the services and levels its owner enabled. You can see at any time which agents use which account, and unlink or delete an account from the library.
How Google user data is stored and protected
- Credentials. For each connected account we store an OAuth refresh token, the list of permissions you granted, and the account's email address. The refresh token is encrypted at rest as described under "Data Security & Integration Credentials" and is decrypted only in memory when the agent needs to act. Short-lived access tokens obtained from it are held in server memory until they expire (typically one hour) and are never written to a database or to disk.
- Content. We do not copy your calendar, spreadsheets, documents, or Drive into a separate store of our own. Data the agent reads from Google is retained only where the agent's work is kept: in the conversation it was used in, in the records of the workflow run that processed it, and in any file the agent produces from it. These are Agent Data under this policy, controlled by you or by the agent owner, and are deleted when the conversation, run, agent, or account is deleted.
- People. Our staff do not read Google user data, except with your consent, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or in aggregated, anonymised form for internal operations.
How Google user data is shared
To produce the agent's response, the content the agent reads from Google is sent to the AI model provider that powers the agent — one of the default providers listed under "Third-Party AI Providers" or, if the agent owner uses BYOK, the provider they chose — and is processed on our infrastructure provider's servers. These providers act as our processors (or, for BYOK, under the owner's own agreement with them) and are bound not to train their models on it. Google user data is not transferred to anyone else, except as described under "Information Sharing and Disclosure" (for example, to comply with the law), and it is never sold, never used to serve advertisements, and never shared with data brokers.
Retention and withdrawing access
- Stored credentials are kept until you delete the account from your Connections library (Account → Connections on the web, Settings → Connections in the mobile app) or delete your Donkit account. When you delete a connection, we delete the stored token and ask Google to revoke the access grant. When you delete your Donkit account, every connection is deleted with it; Donkit may remain listed under your Google Account's third-party access until you remove it there.
- You can also revoke Donkit's access at any time from your Google Account, under Security → Third-party apps & services (myaccount.google.com/permissions). Revocation takes effect immediately: the agent can no longer reach your account until you connect it again.
- Withdrawing access does not by itself delete data the agent already retrieved into conversations or workflow runs; delete those as described under "Data Retention" and on our Delete Account page.
Limited Use disclosure
Donkit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we only use Google user data to provide or improve the user-facing features described above; we do not transfer it to others except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with your explicit prior consent; we do not use or transfer it to serve advertisements; we do not allow humans to read it except as set out above; and we do not use it to develop, improve, or train generalized AI or machine-learning models.