Draft, not yet in force. Some details on this page have not been filled in yet, shown in double braces.

Privacy Policy

WorkspaceRadar · Last updated: {{EFFECTIVE_DATE}}

This policy explains what WorkspaceRadar ("we", "the app") reads from your Google Workspace domain, what we keep, for how long, and who sees it.

1. Who we are

WorkspaceRadar is operated by Xinru Tang, a sole trader, Möwenweg 5, 91056 Erlangen, Germany (Impressum). Contact for anything in this policy: {{PRIVACY_CONTACT_EMAIL}}. {{IF_REQUIRED: Our data protection officer is {{DPO_NAME_AND_CONTACT}}.}}

2. Two kinds of data, two roles

3. What we read from Google

When an administrator connects the app, Google asks them to grant these permissions. We use each one only for the purpose shown.

Permission (Google scope) What we read Why
admin.directory.user.readonly Each user's email address, organisational unit, whether the account is suspended or archived, when it was created and when it last signed in To list the licensed accounts being assessed
admin.reports.usage.readonly Per-user usage reports: when each person last used Gmail and Drive, counts of emails sent and received, files created, and Chat activity counts; and account security facts: 2-step verification status, number of admin roles, number of third-party apps, Google's password strength and length labels, and less secure app access To decide whether a licence is actually being used, and to show the Security screen
admin.reports.audit.readonly For people who hold a Gemini add-on: when they used Gemini (number of uses and the latest time). Google asks every domain for this permission when the app is connected, but the app only uses it in a scan when someone in the domain holds a Gemini add-on To show whether a Gemini add-on is being used
apps.licensing Which Google Workspace licence each user holds To price each licence
openid, email, profile The signing-in administrator's identity To sign you in

What we never read: the content of anyone's email, files, calendar, chats, Gemini prompts or any other content. We never read a password, only Google's label about it (for example "strong").

About "View and manage Google Workspace licenses". Google offers only one licensing permission, and it is described as read and write. The app only ever reads. It never changes a licence, a user or any setting in your domain. Our own build process fails if any part of our code makes a changing request to Google.

4. What we keep, and why

Data Why we keep it How long
Your domain's Google customer id and primary domain; the plan type, renewal date and billing currency you tell us; whether weekly scans are on To identify your domain and show savings you can realise now vs at renewal Until you disconnect, or 12 months without use (section 5)
The connecting administrator's email, and an access token that lets us scan again without you signing in (encrypted at rest) To run the scans you ask for and, if weekly monitoring is on, the weekly rescan Until you disconnect, or 12 months without use (section 5)
Per-user directory details, licences, usage timestamps and counts, the resulting verdict and the licence cost To produce the dormant-licence list, the savings figure and the history 12 months, except that your two most recent completed scans are always kept. A person's directory details are deleted once no kept scan refers to them and no scan has seen them for 12 months
Per-user account security facts (listed in section 3) The Security screen Same as the row above
For Gemini add-on holders: number of Gemini uses and the latest time The AI seats screen Same as the row above
The raw responses Google returned. We ask Google for only the fields listed in section 3, so these hold each user's Google id, email address, organisational unit, suspended and archived status, creation and last sign-in time, licence, the usage and security values listed above, and, for Gemini add-on holders, records of when they used Gemini; never IP addresses, prompts or other content, names or other profile details So that every figure we show can be traced back to what Google said 30 days, or until you disconnect if sooner
A price you entered to correct ours, and the email of the administrator who entered it To use your price instead of the list price, and show who set it Until you disconnect, or until you change the billing currency (prices in the old currency are deleted)
{{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} If you switch on change emails: your email address, and a copy of each email's counts and amounts To send you an email when a weekly rescan finds a change The address until you switch the emails off, unsubscribe, or another administrator reconnects the domain; each queued email 30 days
If you use the contact form: your name, email address and message To answer you Not stored by the app. Forwarded by email to our mailbox the moment you send it, and kept there until your request is dealt with, at most {{CONTACT_MESSAGE_RETENTION, e.g. 2 years}}
If you use the contact form: your IP address To stop abuse: at most 5 messages per address per hour Held in memory for at most one hour, never written to the database or the logs
Database backups, containing all of the above To recover from a failure 7 days, after which they are overwritten (section 5)
Technical logs: internal record ids, error codes, error types and, for some errors, an error message and the code location where it happened. We do not write email addresses or anyone's data to them on purpose. A failed scan is logged with only the error type and where it happened, and our database is set not to include data values in its error messages To run and fix the service 30 days

Weekly monitoring. Weekly monitoring is on by default. The app rescans your domain once a week so it can show what changed. You can turn it off on the History screen, and then no request reaches Google unless you start one. If nobody from your organisation opens the app for 90 days, weekly scans pause on their own, and they resume the next time someone opens it.

Contact form. The form asks only for your name, email address and message, and you choose what to write. We use them only to answer you; the legal basis is our legitimate interest in answering questions about the service, or steps towards a contract you asked for (Art. 6(1)(f) and (b) GDPR). The message is sent by email (Amazon SES) to our mailbox and is not kept by the app. The form uses no tracking and no third-party captcha: a hidden field and a per-address limit keep spam out. Please don't send us employee lists or other personal data about your users.

{{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} Change emails. Off unless you switch them on, on the History screen. They go only to the administrator who switched them on, only when a weekly rescan finds seats that became dormant or licences that were released, and they contain counts and amounts, never anyone's name or email address. Every email has a one-click unsubscribe link.

5. Deleting your data

In Settings → Disconnect this domain, the app first withdraws its access at Google, then deletes everything it holds about your domain, all tables included, in one step. If Google does not confirm the withdrawal, we still delete everything, and we tell you to remove the app's access in your Google Admin console yourself.

After 12 months with nobody from your organisation opening the app, we do the same automatically. Because we do not collect a contact address, we cannot warn you beforehand.

Backups. Deletion removes your data from our live database at once. Copies remain in our encrypted database backups for up to 7 days until those backups are overwritten; they cannot be edited to remove one domain. If our database itself is ever deleted or replaced, for example when we move or shut down our hosting, an encrypted final snapshot of it is taken automatically; we delete that snapshot within 7 days. {{RESTORE_POLICY — e.g. "If we ever restore a backup, we delete again everything that had been deleted since it was taken." A commitment about how you operate; publish it only if it will be true}}

6. Who we share it with

Nobody, apart from the service providers who host or process it for us:

Provider What for Where
Amazon Web Services ({{AWS_CONTRACTING_ENTITY — typically Amazon Web Services EMEA SARL for EEA accounts; confirm on the AWS agreement}}) Hosting the app, its database, backups and logs EU, Ireland (AWS region eu-west-1)
Amazon Web Services (Amazon Bedrock) {{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} Writing the AI summary on the dashboard, from aggregate figures only EU, Ireland (eu-west-1)
Amazon Web Services (Amazon SES) Delivering contact-form messages to our mailbox: your name, email address and message EU, Ireland (eu-west-1)
{{CONTACT_MAILBOX_PROVIDER — today Google (Gmail); see docs/legal/README.md before publishing}} Our mailbox, where contact-form messages arrive and from which we reply {{MAILBOX_LOCATION}}
Amazon Web Services (Amazon SES) {{KEEP_IF_CHANGE_EMAILS_ENABLED_AT_LAUNCH}} Sending change emails to an administrator who switched them on: their address, and counts and amounts only EU, Ireland (eu-west-1)
{{ANY_OTHER_SUBPROCESSOR, e.g. email for support, or delete this row}}

We contact Google only to make the read requests in section 3, using your domain's own permission. We do not sell data. We do not use it for advertising. We do not load analytics or tracking scripts, and our fonts and icons are served from our own site, so opening the app contacts no other company. The CSV files you export are downloaded by you and sent to no one else.

7. Cookies

The app sets one cookie, __Host-SESSION, which keeps you signed in. It is strictly necessary and contains only a random identifier. The sign-in it refers to ends when you sign out, after 30 minutes without activity, or 12 hours after you signed in, whichever comes first; your browser deletes the cookie itself when you close it. There are no analytics, advertising or third-party cookies.

8. Security

9. Google API Services User Data Policy

WorkspaceRadar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

{{KEEP_IF_AI_SUMMARY_ENABLED_AT_LAUNCH}} The AI summary is generated by Amazon Bedrock in the EU (Ireland) from aggregate figures only. No names or email addresses are sent. Amazon Bedrock does not store the request or use it to train models, and Anthropic, the model's maker, has no access to it.

10. Your rights

If you are in the EU/EEA or the UK, you have the right to:

The administrator can export scan results (CSV) and delete everything (section 5) without contacting us. For any other request, write to {{PRIVACY_CONTACT_EMAIL}}.

If you are an employee of an organisation that uses the app, your organisation is the controller of your data (section 2). Please direct requests to your organisation's administrator first. We will help them respond.

Legal basis (for the administrator's sign-in identity, where we are the controller): {{LEGAL_BASIS — typically Art. 6(1)(b) GDPR, performance of the contract with your organisation, for the administrator's sign-in data; to be confirmed}}.

11. Changes

If we change this policy, we will update the date at the top. If a change reduces your rights, or changes what we read from Google, we will show it in the app before it takes effect.