Separate connection for each service
Drive, Gmail, Calendar, and YouTube are authorized separately so one feature does not silently unlock another.
Google connections are optional. LumenQube asks for a permission only when you connect the matching feature, uses it to complete actions you request, and lets you disconnect at any time.
Drive, Gmail, Calendar, and YouTube are authorized separately so one feature does not silently unlock another.
Read and write permissions are limited to the operations described below; LumenQube does not request delete access.
Sending mail, creating events or documents, RSVPing, and uploading videos require an explicit user action or approval.
Disconnecting deletes LumenQube's stored authorization for that service. Access can also be revoked in your Google Account.
You start from the relevant LumenQube feature.
Google shows the account and requested permissions.
LumenQube calls Google only for the action you request.
The encrypted server-side authorization record is deleted.
| Google service and OAuth scope | User-facing use in LumenQube | Why a narrower permission is not enough |
|---|---|---|
| Google identity openid profile | Sign in to LumenQube with Google and show which Google account is connected to an optional service. | LumenQube receives only the account identifier, name, email address, and profile image needed for sign-in and account transparency. |
| Google Drive https://www.googleapis.com/auth/drive.readonly | Search the user's Drive, read a file the user selects from results, import Google Sheets or CSV data, and refresh an explicitly connected spreadsheet. | The feature searches files the user already has across Drive. drive.file alone cannot discover or read those existing files unless each is first opened with LumenQube. |
| Google Drive https://www.googleapis.com/auth/drive.file | Create a new Google Doc only when the user approves a “create Drive document” action, and access files created or opened through LumenQube. | The read-only scope cannot create a document. drive.file is the narrow write permission and does not grant general write or delete access across Drive. |
| Gmail https://www.googleapis.com/auth/gmail.readonly | Search the user's mailbox and read a message the user asks LumenAgent to summarize or use in a task. | Metadata-only access does not provide the message body required for the user-requested reading and summarization feature. LumenQube does not request modify or delete access. |
| Gmail https://www.googleapis.com/auth/gmail.send | Send a new email or reply after LumenQube shows the action and the user approves it. | This is Google's send-only permission. It does not allow LumenQube to edit mailbox state or delete messages. |
| Google Calendar https://www.googleapis.com/auth/calendar.events | List and search events, create an event the user approves, and RSVP to an event at the user's direction. | The feature needs both event reading and event changes. LumenQube does not request access to Calendar settings or unrelated Google account data. |
| YouTube https://www.googleapis.com/auth/youtube.upload | Upload only the finished video the user chooses from LumenDesign, with the title, description, tags, audience, and visibility the user reviews. | This is Google's upload-only scope. It does not grant permission to read, edit, or delete the user's existing videos. |
Limited Use. LumenQube's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
For the complete legal disclosure, including subprocessors, security, retention, international transfers, and privacy rights, read our Privacy Policy. For help connecting or disconnecting a service, contact support@lumenqube.com.
Explore the broader privacy model or get help with connecting and disconnecting a Google service.