Google API Limited Use Disclosure
Last updated: July 30, 2026 · Product: Nabze Web (نبض وب) · nabz-web.ir
Affirmative statements
Nabze Web's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Acceptable use case
Nabze Web is a reporting and analytics dashboard application. Customers connect their own Google Analytics 4 property (and optionally Google Tag Manager and Google Search Console) so they can view Farsi dashboards, export Excel reports, schedule reports, and ask questions about their own website metrics. Write scopes are used only for implemented tracking-setup features the user explicitly starts.
This aligns with an approved use of Google Analytics / related measurement APIs to provide user-facing reporting features for the account that granted access. We do not use Google user data for unrelated products, ads networks, data brokerage, or generalized model training.
Minimum scopes / incremental authorization
Initial Google connection requests read-only scopes only. Write scopes are requested later via a separate reconnect flow (upgrade=1) when the user uses implemented GA4/GTM setup features. We do not request scopes for unimplemented or future features. We do not request Google Drive scopes (including drive, drive.readonly, or drive.file) because the product never reads or writes user Drive files.
Scope justifications (first connect)
openidMy app uses openid to verify the signed-in Google account subject so the connection stays bound to the correct user and we can match Google security-event (RISC) tokens to the affected properties.
https://www.googleapis.com/auth/userinfo.emailMy app uses userinfo.email to display which Google account is connected in the dashboard and to help support match tickets to that account.
https://www.googleapis.com/auth/analytics.readonlyMy app uses analytics.readonly to read the user’s GA4 property metadata and report metrics so we can show Farsi dashboards, Excel exports, scheduled reports, and in-app explanations of that user’s own Analytics data.
https://www.googleapis.com/auth/tagmanager.readonlyMy app uses tagmanager.readonly to list GTM accounts/containers linked to the connected GA4 property and show current tracking setup in the UI without writing until the user opts into the setup wizard.
https://www.googleapis.com/auth/webmasters.readonlyMy app uses webmasters.readonly to read Search Console performance (queries, clicks, impressions) for a site URL the user explicitly links, and show SEO panels next to their GA4 reports.
Scope justifications (upgrade only — implemented features)
https://www.googleapis.com/auth/analytics.editMy app uses analytics.edit only after the user starts the tracking setup wizard, to create/update GA4 custom dimensions and custom events on the same property they connected. It is not requested on first sign-in.
https://www.googleapis.com/auth/tagmanager.edit.containersMy app uses tagmanager.edit.containers only when the user runs automated event/tag setup, to create or update tags, triggers, and variables inside a GTM container they select. It is not requested on first sign-in.
https://www.googleapis.com/auth/tagmanager.publishMy app uses tagmanager.publish only when the user explicitly confirms publishing a GTM container version from the setup UI after tags were prepared. It is not requested on first sign-in.
APIs and use cases we do not use
Nabze Web does not request user OAuth access to, and does not process user data from:
- Google Drive — we do not read, store, sync, or back up user Drive files. Our product is not a Drive backup, file manager, or storage migration tool. Therefore
drive,drive.readonly,drive.file, anddrive.appfolderare not applicable. - Gmail (user mailbox) — we do not read, search, label, or send email on behalf of the user's Gmail account via user OAuth. Transactional email from Nabze Web (password reset, support notices) is sent by our own mail infrastructure (SMTP app password or service-account
gmail.send) and is unrelated to accessing a customer's Gmail inbox. - Google Fit / Health Connect — we do not access fitness, activity, or health sensor data.
- Health research — Nabze Web is not a health research application and does not use Google user data to enable health research.
- Google Photos — we do not access photo libraries.
AI / ML and Limited Use
Optional assistant features may send a user's own synced website metrics (or short derived summaries) to a language-model provider solely to answer that user's question about their property. We do not use Google Workspace, Photos, Analytics, or other Google API user data (raw or derived, aggregated, or anonymized) to create, train, or improve a foundational or generalized AI/ML model. Any processing is limited to providing or improving user-facing features for the appropriate use case for that user.
Data handling
- We do not sell Google user data.
- We do not use Google user data for serving advertisements.
- Human access is limited to providing the service, security, and support as allowed by Google's policies.
- Users can disconnect Google OAuth at any time; disconnecting stops API access to their Analytics data. Account deletion can be requested via in-app support.