This section explains how Wexa handles information we receive when you connect a Google account to Wexa through Google APIs ("Google user data"). Where this section differs from any other part of this policy, this section applies to Google user data.
Limited Use
Wexa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Google data we access
We access only the Google services you choose to connect, and only with the permissions you approve on Google's consent screen. Depending on the services you connect, this can include:
- Gmail: reading and searching your messages, and sending email, when you or an agent you set up asks Wexa to work with your mailbox.
- Google Drive: finding, reading, downloading, creating, uploading, sharing, and deleting the files you direct Wexa to work with.
- Google Sheets: reading spreadsheets and updating them, including adding, editing, and removing cells, rows, columns, and sheets.
- Google Docs: creating documents and updating their content.
- Google Calendar: reading your events, and creating, updating, or deleting events when you ask. If you use the Wexa meeting assistant, we read your calendar to find the meetings the assistant should join.
- Google Analytics: read-only access to your accounts, properties, and reports so you can query your analytics data.
- YouTube: read-only access to your channel and video information, such as channel statistics, when you ask Wexa about your channel.
- Your Google account email address, so we know which account is connected.
How we use Google data
We use Google user data only to provide the features you use it for: running the searches, reads, and actions you request, answering your questions about your own data, scheduling the meeting assistant, and showing the results to you.
We do not use Google user data for advertising, including personalized, retargeted, or interest-based advertising. We do not sell it, and we do not use it to determine creditworthiness or for lending purposes.
Wexa staff do not read Google user data unless you give us permission for specific data (for example, in a support request), it is necessary for security purposes such as investigating abuse, it is needed to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
AI and model training
We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine learning models. We do not use it to train our own models, and we do not allow our AI providers to train theirs with it.
When you ask a Wexa agent to work with your Google data, the relevant content is sent to the AI model provider selected for your workspace, such as Amazon Web Services Bedrock or Microsoft Azure OpenAI Service, only to generate the response or action you asked for.
Who we share Google data with
We transfer Google user data only as needed to provide the features you use, for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after notice to you. We share it only with these service providers, which process it on our behalf:
- Recall.ai, our meeting assistant provider. If you connect Google Calendar to the meeting assistant, Recall.ai receives an OAuth token for your calendar and your account email address so it can read your calendar and have the assistant join the meetings you choose. Recall.ai also processes the audio, video, and transcripts of the meetings the assistant joins.
- AI model providers (Amazon Web Services Bedrock and Microsoft Azure OpenAI Service), which process content only to generate responses, as described above.
- Cloud infrastructure providers (Microsoft Azure and Amazon Web Services), which host our servers, encrypted secret storage, file storage, and search indexes.
- Langfuse, our AI monitoring provider, which may receive prompts and responses that contain Google user data so we can find errors and keep agent behavior secure.
We do not transfer Google user data to data brokers, advertising platforms, or any other third party.
How we protect Google data
OAuth tokens are stored in an encrypted secrets vault. Google user data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Access is limited to the systems and staff that need it to provide the service.
How long we keep Google data
We keep OAuth tokens while your Google account is connected. Content we fetch to complete a request is used for that request. Content you choose to index for search, and records of agent actions that include Google user data, are kept while the connection is active so your features keep working.
When you disconnect a Google service or delete your Wexa account, we delete the related OAuth tokens right away, and we delete the related Google user data, including indexed content, action records, stored files, and meeting transcripts, within 30 days.
How to revoke access
- In Wexa: remove the Google connector from your workspace's connector settings, or disconnect your calendar from the meeting assistant.
- In your Google Account: go to myaccount.google.com/permissions, select Wexa, and remove access.
- By email: write to hello@wexa.ai and we will disconnect your Google account and delete your Google user data for you.
When you disconnect in Wexa, we revoke our access with Google, delete the tokens we hold, remove your calendar from Recall.ai, and delete the related Google user data within 30 days. If you remove access from your Google Account instead, Wexa can no longer reach your Google data, and we delete the Google user data we hold within 30 days of the access being revoked.