Draft, not yet in force. Some details on this page have not been filled in yet, shown in double braces.
Privacy Policy
WorkspaceRadar · Last updated: {{EFFECTIVE_DATE}}
This policy explains what WorkspaceRadar ("we", "the app") reads from your Google Workspace domain, what we keep, for how long, and who sees it.
1. Who we are
WorkspaceRadar is operated by Xinru Tang, a sole trader, Möwenweg 5, 91056 Erlangen, Germany (Impressum). Contact for anything in this policy: {{PRIVACY_CONTACT_EMAIL}}. {{IF_REQUIRED: Our data protection officer is {{DPO_NAME_AND_CONTACT}}.}}
2. Two kinds of data, two roles
- The administrator's sign-in identity. This is the email address of the administrator who signs in with Google, which we use to sign them in and to know who connected the domain. We decide why we use it, so for this data we are the controller.
- Data about the people in your Workspace domain. This is their directory details and usage timestamps (section 3). Your organisation decides to have it analysed, so your organisation is the controller and we process it on your organisation's behalf, under our Data Processing Agreement. Administrators are people in your domain too, so this includes their own directory details and usage, and any record the app keeps for your organisation about an administrator's actions in it (who entered a price, where change emails go).
3. What we read from Google
When an administrator connects the app, Google asks them to grant these permissions. We use each one only for the purpose shown.
| Permission (Google scope) | What we read | Why |
|---|---|---|
admin.directory.user.readonly |
Each user's email address, organisational unit, whether the account is suspended or archived, when it was created and when it last signed in | To list the licensed accounts being assessed |
admin.reports.usage.readonly |
Per-user usage reports: when each person last used Gmail and Drive, counts of emails sent and received, files created, and Chat activity counts; and account security facts: 2-step verification status, number of admin roles, number of third-party apps, Google's password strength and length labels, and less secure app access | To decide whether a licence is actually being used, and to show the Security screen |
admin.reports.audit.readonly |
For people who hold a Gemini add-on: when they used Gemini (number of uses and the latest time). Google asks every domain for this permission when the app is connected, but the app only uses it in a scan when someone in the domain holds a Gemini add-on | To show whether a Gemini add-on is being used |
apps.licensing |
Which Google Workspace licence each user holds | To price each licence |
openid, email, profile |
The signing-in administrator's identity | To sign you in |
What we never read: the content of anyone's email, files, calendar, chats, Gemini prompts or any other content. We never read a password, only Google's label about it (for example "strong").
About "View and manage Google Workspace licenses". Google offers only one licensing permission, and it is described as read and write. The app only ever reads. It never changes a licence, a user or any setting in your domain. Our own build process fails if any part of our code makes a changing request to Google.
4. What we keep, and why
| Data | Why we keep it | How long |
|---|---|---|
| Your domain's Google customer id and primary domain; the plan type, renewal date and billing currency you tell us; whether weekly scans are on | To identify your domain and show savings you can realise now vs at renewal | Until you disconnect, or 12 months without use (section 5) |
| The connecting administrator's email, and an access token that lets us scan again without you signing in (encrypted at rest) | To run the scans you ask for and, if weekly monitoring is on, the weekly rescan | Until you disconnect, or 12 months without use (section 5) |
| Per-user directory details, licences, usage timestamps and counts, the resulting verdict and the licence cost | To produce the dormant-licence list, the savings figure and the history | 12 months, except that your two most recent completed scans are always kept. A person's directory details are deleted once no kept scan refers to them and no scan has seen them for 12 months |
| Per-user account security facts (listed in section 3) | The Security screen | Same as the row above |
| For Gemini add-on holders: number of Gemini uses and the latest time | The AI seats screen | Same as the row above |
| The raw responses Google returned. We ask Google for only the fields listed in section 3, so these hold each user's Google id, email address, organisational unit, suspended and archived status, creation and last sign-in time, licence, the usage and security values listed above, and, for Gemini add-on holders, records of when they used Gemini; never IP addresses, prompts or other content, names or other profile details | So that every figure we show can be traced back to what Google said | 30 days, or until you disconnect if sooner |
| A price you entered to correct ours, and the email of the administrator who entered it | To use your price instead of the list price, and show who set it | Until you disconnect, or until you change the billing currency (prices in the old currency are deleted) |
| {{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} If you switch on change emails: your email address, and a copy of each email's counts and amounts | To send you an email when a weekly rescan finds a change | The address until you switch the emails off, unsubscribe, or another administrator reconnects the domain; each queued email 30 days |
| If you use the contact form: your name, email address and message | To answer you | Not stored by the app. Forwarded by email to our mailbox the moment you send it, and kept there until your request is dealt with, at most {{CONTACT_MESSAGE_RETENTION, e.g. 2 years}} |
| If you use the contact form: your IP address | To stop abuse: at most 5 messages per address per hour | Held in memory for at most one hour, never written to the database or the logs |
| Database backups, containing all of the above | To recover from a failure | 7 days, after which they are overwritten (section 5) |
| Technical logs: internal record ids, error codes, error types and, for some errors, an error message and the code location where it happened. We do not write email addresses or anyone's data to them on purpose. A failed scan is logged with only the error type and where it happened, and our database is set not to include data values in its error messages | To run and fix the service | 30 days |
Weekly monitoring. Weekly monitoring is on by default. The app rescans your domain once a week so it can show what changed. You can turn it off on the History screen, and then no request reaches Google unless you start one. If nobody from your organisation opens the app for 90 days, weekly scans pause on their own, and they resume the next time someone opens it.
Contact form. The form asks only for your name, email address and message, and you choose what to write. We use them only to answer you; the legal basis is our legitimate interest in answering questions about the service, or steps towards a contract you asked for (Art. 6(1)(f) and (b) GDPR). The message is sent by email (Amazon SES) to our mailbox and is not kept by the app. The form uses no tracking and no third-party captcha: a hidden field and a per-address limit keep spam out. Please don't send us employee lists or other personal data about your users.
{{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} Change emails. Off unless you switch them on, on the History screen. They go only to the administrator who switched them on, only when a weekly rescan finds seats that became dormant or licences that were released, and they contain counts and amounts, never anyone's name or email address. Every email has a one-click unsubscribe link.
5. Deleting your data
In Settings → Disconnect this domain, the app first withdraws its access at Google, then deletes everything it holds about your domain, all tables included, in one step. If Google does not confirm the withdrawal, we still delete everything, and we tell you to remove the app's access in your Google Admin console yourself.
After 12 months with nobody from your organisation opening the app, we do the same automatically. Because we do not collect a contact address, we cannot warn you beforehand.
Backups. Deletion removes your data from our live database at once. Copies remain in our encrypted database backups for up to 7 days until those backups are overwritten; they cannot be edited to remove one domain. If our database itself is ever deleted or replaced, for example when we move or shut down our hosting, an encrypted final snapshot of it is taken automatically; we delete that snapshot within 7 days. {{RESTORE_POLICY — e.g. "If we ever restore a backup, we delete again everything that had been deleted since it was taken." A commitment about how you operate; publish it only if it will be true}}
6. Who we share it with
Nobody, apart from the service providers who host or process it for us:
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services ({{AWS_CONTRACTING_ENTITY — typically Amazon Web Services EMEA SARL for EEA accounts; confirm on the AWS agreement}}) | Hosting the app, its database, backups and logs | EU, Ireland (AWS region eu-west-1) |
| Amazon Web Services (Amazon Bedrock) {{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} | Writing the AI summary on the dashboard, from aggregate figures only | EU, Ireland (eu-west-1) |
| Amazon Web Services (Amazon SES) | Delivering contact-form messages to our mailbox: your name, email address and message | EU, Ireland (eu-west-1) |
| {{CONTACT_MAILBOX_PROVIDER — today Google (Gmail); see docs/legal/README.md before publishing}} | Our mailbox, where contact-form messages arrive and from which we reply | {{MAILBOX_LOCATION}} |
| Amazon Web Services (Amazon SES) {{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} | Sending change emails to an administrator who switched them on: their address, and counts and amounts only | EU, Ireland (eu-west-1) |
| {{ANY_OTHER_SUBPROCESSOR, e.g. email for support, or delete this row}} |
We contact Google only to make the read requests in section 3, using your domain's own permission. We do not sell data. We do not use it for advertising. We do not load analytics or tracking scripts, and our fonts and icons are served from our own site, so opening the app contacts no other company. The CSV files you export are downloaded by you and sent to no one else.
7. Cookies
The app sets one cookie, __Host-SESSION, which keeps you signed in. It is strictly
necessary and contains only a random identifier. The sign-in it refers to ends when you sign
out, after 30 minutes without activity, or 12 hours after you signed in, whichever comes first;
your browser deletes the cookie itself when you close it. There are no analytics, advertising or
third-party cookies.
8. Security
- Access tokens are encrypted at rest (AES-GCM), bound to your domain's record, and use a key that can be rotated.
- All traffic uses HTTPS.
- The database is encrypted at rest, has no public address, accepts network connections only from the app, and is backed up automatically, with backups kept 7 days.
- Technical logs are kept 30 days.
- The session cookie is
HttpOnly,SecureandSameSite=Lax. - Every database query for your data is scoped to your domain.
- {{ORGANISATIONAL_MEASURES: who at Xinru Tang can access production, and how}}
9. Google API Services User Data Policy
WorkspaceRadar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide the features you see in the app.
- We do not transfer it except as needed to run the app, for security, or to comply with the law.
- No human at Xinru Tang reads it unless you ask us to (for example in a support request), or it is needed for security or required by law.
- We do not use it to train or improve general-purpose artificial intelligence or machine learning models.
{{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} The AI summary is generated by Amazon Bedrock in the EU (Ireland) from aggregate figures only. No names or email addresses are sent. Amazon Bedrock does not store the request or use it to train models, and Anthropic, the model's maker, has no access to it.
10. Your rights
If you are in the EU/EEA or the UK, you have the right to:
- access your personal data, correct it, or have it erased;
- restrict or object to its processing;
- receive it in a portable format;
- complain to a supervisory authority ({{LEAD_SUPERVISORY_AUTHORITY}}).
The administrator can export scan results (CSV) and delete everything (section 5) without contacting us. For any other request, write to {{PRIVACY_CONTACT_EMAIL}}.
If you are an employee of an organisation that uses the app, your organisation is the controller of your data (section 2). Please direct requests to your organisation's administrator first. We will help them respond.
Legal basis (for the administrator's sign-in identity, where we are the controller): {{LEGAL_BASIS — typically Art. 6(1)(b) GDPR, performance of the contract with your organisation, for the administrator's sign-in data; to be confirmed}}.
11. Changes
If we change this policy, we will update the date at the top. If a change reduces your rights, or changes what we read from Google, we will show it in the app before it takes effect.