HighFlyer’s use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Before you connect
Conductor shows an in-product Google data disclosure immediately before the button that starts Google’s OAuth consent flow. Continuing is optional. If you do not continue and approve Google’s consent screen, Conductor does not receive the requested Google tokens or account data.
Connect only the Google account you intend Conductor to use. The Google grant is attached to that account and the HighFlyer Conductor OAuth project.
Access Conductor requests
- Identity: the connected account’s stable Google identifier and verified email address.
- Gmail:
gmail.modify. This permits search and reading of messages and threads; access to headers, labels, and attachments; creation of drafts; and mailbox-state changes such as archive, inbox, read, unread, star, label, trash, and untrash. - Primary Google Calendar:
calendar.events.owned. This permits reading events the connected user owns and creating, updating, or cancelling owned events.
Google does not offer a draft-only Gmail scope. The requested Gmail scope is technically capable of sending mail, but Conductor’s supported Gmail workflow exposes draft creation for the user to review and does not expose a send command. Calendar reads do not require approval; the supported workflow requires a fresh, action-specific approval immediately before each Calendar create, update, or cancellation.
How Google data is used and shared
Conductor accesses Google data only to perform the Gmail or Calendar task the authorised user requested. For example, it may search a mailbox, summarise a relevant thread, prepare a draft, find an owned event, or make a specifically approved Calendar change.
The relevant Google content can be processed in Conductor’s AWS-hosted environment and, when AI is needed, sent through OpenRouter to a selected downstream model provider solely to provide that user-facing feature. Google data is not sold, used for advertising or credit decisions, or used to train or improve a general-purpose AI model.
Google data is transferred only to provide the user-facing feature with consent, for security, to comply with law, or in a merger, acquisition, or asset sale after explicit prior user consent. Human access is limited to documented explicit consent for specific data, security necessity, or legal necessity.
Storage and retention
Google access and refresh tokens are stored in the connected agent’s isolated runtime credential file. Conductor does not build a separate archive of the user’s Gmail mailbox or Calendar. Relevant Google content may remain in a private Conductor conversation, tool output, memory, audit record, or file that the user asked Conductor to download.
A successful managed disconnect immediately deletes the active token file and clears the current Google account label, Google subject, and scope list from the connection record. Minimal security and transaction records without tokens may be retained for up to 90 days. After a verified deletion request, identified Google-derived content is removed or de-identified from active Conductor systems within 30 days and from ordinary backup cycles within 90 days, subject to a binding legal hold or legal retention duty.
Disconnect Google from Conductor
- Ask your organisation’s Conductor administrator to open the relevant agent.
- Open Connected services.
- Find Google Gmail and Calendar and choose Disconnect.
- Confirm the removal. Wait for Conductor to report that the connection was removed.
If you cannot reach the administrator, email hello@highflyerglobal.com and identify the customer organisation and connected Google account. Do not email a token, password, connection link, or sensitive mailbox content.
Revoke HighFlyer Conductor in Google
- Open Google Account → third-party connections.
- Select the HighFlyer Conductor connection.
- Choose the option to remove access and confirm.
Google-side revocation is separate from Conductor’s Disconnect button. Revoking the grant stops future Google API access and can invalidate every Conductor binding that uses the same Google account and OAuth project.
Request deletion of Conductor-held Google data
Email hello@highflyerglobal.com with the subject Conductor Google data deletion. Include:
- the customer organisation and connected Google account;
- the Conductor agent or assistant name, if known;
- whether the request covers Google-derived content only or the whole Conductor account; and
- a safe way for HighFlyer to verify your identity and authority.
Do not include passwords, OAuth tokens, private connection links, or unnecessary Gmail or Calendar content. HighFlyer will verify the request and complete active-system deletion or de-identification within 30 days, with ordinary backup expiry within 90 days, subject to a binding legal hold or legal retention duty.
What disconnection, revocation, and deletion do not undo
These controls do not automatically:
- delete Gmail drafts or reverse mailbox changes already made;
- delete, restore, or reverse Calendar events or attendee notifications;
- delete messages or records held independently by Google, recipients, the customer, or another connected service; or
- erase historical Conductor sessions, memories, audit records, or downloaded files unless they are included in a verified deletion request.
Manage Google-side records in Gmail and Google Calendar. For questions or urgent suspected misuse, contact HighFlyer at hello@highflyerglobal.com or +64 9 883 6868.