How Xaviour uses Google data
Xaviour product · Last updated 2 September 2026
After you sign in with Google, Xaviour asks you through Google's consent screen to grant Gmail and Google Calendar permissions. Xaviour cannot access either service until you grant those permissions. It requests two data permissions. This page explains each one in plain words; the full Privacy Notice has the detail.
Gmail
Permission: https://www.googleapis.com/auth/gmail.modify
Xaviour uses Gmail access to:
- understand your messages and the context of each conversation;
- prioritise what needs your attention and what can wait;
- answer your questions about your own communication — who you are waiting on, what happened with someone, what you promised;
- prepare and save drafts in your Gmail Drafts for you to review;
- send a message — only as an action you explicitly approve;
- organise your mailbox with Xaviour's own labels, archiving, and marking messages read or unread, under the rules you approve, all reversible.
Xaviour never silently sends consequential communication. A send happens only after you confirm that exact draft. Xaviour never permanently deletes mail; there is no code path for it.
Google Calendar
Permission: https://www.googleapis.com/auth/calendar.events
Xaviour uses Calendar access to:
- read your primary calendar's events for context and availability, so the day's commitments sit beside your mail;
- propose scheduling actions when you ask, showing the exact title, date, time and attendees first;
- create the meeting or event, and add attendees, so Google sends the calendar invitations;
- execute a calendar change only after you confirm it. Nothing is created before your confirmation.
Data handling
- Backend-only tokens. Your Google refresh token is held only on Xaviour's servers, encrypted with a per-account key wrapped by a dedicated AWS KMS key. Access tokens live in memory only. Browsers and AI models never receive your Google credentials.
- Encryption. HTTPS in transit; encrypted database at rest in AWS Europe (Ireland), in private network subnets with no internet route.
- Purpose limitation. Google data is used only to provide the Xaviour features you see and use. Message bodies are fetched when a feature needs them and are not stored in Xaviour's database.
- Limited Use. Xaviour's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- No advertising. Google user data is never sold, never used for advertising, and never shared with advertisers.
- No generalised AI training. Google user data is not used to build, train or improve generalised AI or machine-learning models. Where a model-backed feature is enabled (Anthropic Claude on Amazon Bedrock, inside AWS Europe), only the bounded excerpts that feature needs are sent, with third parties' names and addresses pseudonymised, to produce the immediate result.
- Deletion and disconnect. Disconnecting Google inside Xaviour revokes access at Google and destroys the stored token immediately. You can also revoke Xaviour from your Google Account permissions. Email privacy@xaviour.ai to have your product data erased.
See the Privacy Notice and Terms. Questions: privacy@xaviour.ai.