بازگشت به حریم خصوصی

Google API Limited Use Disclosure

Last updated: July 30, 2026 · Product: Nabze Web (نبض وب) · nabz-web.ir

Affirmative statements

Nabze Web's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Acceptable use case

Nabze Web is a reporting and analytics dashboard application. Customers connect their own Google Analytics 4 property (and optionally Google Tag Manager and Google Search Console) so they can view Farsi dashboards, export Excel reports, schedule reports, and ask questions about their own website metrics. Write scopes are used only for implemented tracking-setup features the user explicitly starts.

This aligns with an approved use of Google Analytics / related measurement APIs to provide user-facing reporting features for the account that granted access. We do not use Google user data for unrelated products, ads networks, data brokerage, or generalized model training.

Minimum scopes / incremental authorization

Initial Google connection requests read-only scopes only. Write scopes are requested later via a separate reconnect flow (upgrade=1) when the user uses implemented GA4/GTM setup features. We do not request scopes for unimplemented or future features. We do not request Google Drive scopes (including drive, drive.readonly, or drive.file) because the product never reads or writes user Drive files.

Scope justifications (first connect)

  • openid

    My app uses openid to verify the signed-in Google account subject so the connection stays bound to the correct user and we can match Google security-event (RISC) tokens to the affected properties.

  • https://www.googleapis.com/auth/userinfo.email

    My app uses userinfo.email to display which Google account is connected in the dashboard and to help support match tickets to that account.

  • https://www.googleapis.com/auth/analytics.readonly

    My app uses analytics.readonly to read the user’s GA4 property metadata and report metrics so we can show Farsi dashboards, Excel exports, scheduled reports, and in-app explanations of that user’s own Analytics data.

  • https://www.googleapis.com/auth/tagmanager.readonly

    My app uses tagmanager.readonly to list GTM accounts/containers linked to the connected GA4 property and show current tracking setup in the UI without writing until the user opts into the setup wizard.

  • https://www.googleapis.com/auth/webmasters.readonly

    My app uses webmasters.readonly to read Search Console performance (queries, clicks, impressions) for a site URL the user explicitly links, and show SEO panels next to their GA4 reports.

Scope justifications (upgrade only — implemented features)

  • https://www.googleapis.com/auth/analytics.edit

    My app uses analytics.edit only after the user starts the tracking setup wizard, to create/update GA4 custom dimensions and custom events on the same property they connected. It is not requested on first sign-in.

  • https://www.googleapis.com/auth/tagmanager.edit.containers

    My app uses tagmanager.edit.containers only when the user runs automated event/tag setup, to create or update tags, triggers, and variables inside a GTM container they select. It is not requested on first sign-in.

  • https://www.googleapis.com/auth/tagmanager.publish

    My app uses tagmanager.publish only when the user explicitly confirms publishing a GTM container version from the setup UI after tags were prepared. It is not requested on first sign-in.

APIs and use cases we do not use

Nabze Web does not request user OAuth access to, and does not process user data from:

  • Google Drive — we do not read, store, sync, or back up user Drive files. Our product is not a Drive backup, file manager, or storage migration tool. Therefore drive, drive.readonly, drive.file, and drive.appfolder are not applicable.
  • Gmail (user mailbox) — we do not read, search, label, or send email on behalf of the user's Gmail account via user OAuth. Transactional email from Nabze Web (password reset, support notices) is sent by our own mail infrastructure (SMTP app password or service-account gmail.send) and is unrelated to accessing a customer's Gmail inbox.
  • Google Fit / Health Connect — we do not access fitness, activity, or health sensor data.
  • Health research — Nabze Web is not a health research application and does not use Google user data to enable health research.
  • Google Photos — we do not access photo libraries.

AI / ML and Limited Use

Optional assistant features may send a user's own synced website metrics (or short derived summaries) to a language-model provider solely to answer that user's question about their property. We do not use Google Workspace, Photos, Analytics, or other Google API user data (raw or derived, aggregated, or anonymized) to create, train, or improve a foundational or generalized AI/ML model. Any processing is limited to providing or improving user-facing features for the appropriate use case for that user.

Data handling

  • We do not sell Google user data.
  • We do not use Google user data for serving advertisements.
  • Human access is limited to providing the service, security, and support as allowed by Google's policies.
  • Users can disconnect Google OAuth at any time; disconnecting stops API access to their Analytics data. Account deletion can be requested via in-app support.

Related pages