Use of Google API Services
How Cockpit Agents accesses, uses, stores and shares data from Google APIs.
Effective 1 September 2026
Why this page exists
Cockpit connects to the business systems your organisation already uses. You choose which ones, and you install those connectors in your workspace yourself. This page sets out, for transparency, what Cockpit does with each Google service, so you can see what you are granting before you grant it. Google's consent screen shows only Google's standard wording for each permission. This page is where we explain, in our own words, what Cockpit does with it.
It covers Google services only. Every other system is described the same way in our Privacy Policy, which this page does not replace. Nothing below applies unless your organisation has installed that connector in the workspace, either to read data or to change data in that system.
How access is granted
You grant access through Google's standard OAuth consent flow, and you see the exact permissions before you agree. We request only the access needed for the capability you enable, and nothing broader. We never ask for, store, or handle your Google password.
What we use each service for
Cockpit does two things with a system you connect. It reads, so it can answer questions and report on what it finds. It also makes changes, such as sending a message, amending a calendar event or updating a product listing.
A connector can be installed to read only. Your organisation can then upgrade it so Cockpit may also make changes. Which of the two applies to you depends on how your organisation installed that connector.
- Google Drive. Read only. We list the files and folders you give us access to, and we download the content of the documents you select. We monitor those locations for changes and sync new or updated documents into your workspace, so their content can be searched, retrieved and cited in answers. We perform no write operations. We never create, change, move or delete anything in your Drive.
- Google Analytics. Read only. We read the properties you authorise so we can report on them and answer questions about them. This is your own property, read on your instruction. We do not run Analytics on our own website.
- Google Search Console. Read only. We read search performance and indexing data so we can report on it and answer questions about it.
- Google Tag Manager. Read and write. We read container and tag configuration so we can report on how your measurement is set up. Where changes are enabled, we also create and update tags, triggers and variables, and publish container versions, so measurement keeps working as your site changes.
- Gmail. Read and write. For organisations that answer customer email from Gmail. We read messages and attachments so we can answer questions about correspondence, and we can watch a mailbox so those answers stay current. How a reply is sent depends on the mode your organisation chooses. The agent can prepare a draft for a person to review and send. It can also send within limits your organisation sets, with checks in place. We treat incoming email as an untrusted source and apply extra precautions to it.
- Google Calendar. Read and write. We read your calendars and events so we can answer scheduling questions. Where changes are enabled, we create, update and delete events, and respond to invitations.
- Google Ads. Read and write. We read campaign, spend and performance data for reporting and analysis. Where changes are enabled, we also change your advertising, including creating and amending campaigns, ad groups, budgets and bids, and pausing or resuming them.
- Google Merchant Center. Read and write. We read your product feed, listing and product status data, and where changes are enabled we update it. The purpose is data quality. We correct listing problems and keep product information accurate, so what Merchant Center holds matches what your business actually sells.
Every change stays inside the permissions your organisation granted. You can withdraw those permissions at any time, as described in Retention and revoking access.
Where a service is read only above, that is the access we ask for today, not a limit of the service itself. We describe only what Cockpit does now. When we add a Google service, or when a connector starts writing where it previously only read, we ask for the new permission and update this page before that change reaches you.
How we store it
Content is encrypted at rest and connections are encrypted in transit. Access credentials are held in a dedicated secret store, separate from application data. Access to production systems is restricted to the people who need it and is logged.
AI processing and model training
Content may be processed by AI services to produce the answers you ask for. Those services operate under agreements that prohibit using your content to train their models. We do not use data from Google APIs to train AI models, and we do not transfer it to anyone who would.
No person reads your Google data except where you have specifically asked us to look at particular messages or files, or where the law or a security investigation requires it.
Limited Use
Cockpit Agents' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and revoking access
Data derived from a connected Google service is retained while the connection is active. You can revoke access at any time in your Google Account permissions, or by disconnecting the service inside Cockpit. Disconnecting removes the stored credential and stops further access.
You may ask us to delete derived content at any time. Retention is described in the Privacy Policy.