A user may explicitly authorize Moderavia through Google OAuth to access a supported Google service. Moderavia requests the scopes shown on Google's consent screen and uses the resulting authorization only for the connected workspace and the user-facing integration selected by the customer.
For the current Google Ads integration, customer-authorized access is used for reporting, analytics, account health, account discovery and classification, and evidence inside the customer's Moderavia workspace. This may include accessible customer identifiers, manager-account status, campaign information, performance metrics, connection health, and sync evidence. The current production path is read-only; this policy does not claim autonomous ad creation, budget changes, or spend.
OAuth access and refresh tokens are stored as encrypted credential envelopes and are unwrapped only within the credential-bearing execution boundary for the requested provider operation. Tokens and Google API data are not intentionally exposed to other customers. We do not sell Google API data, use it for advertising to users, or use it to train a general-purpose AI model.
Google API data is disclosed only as needed to operate the requested feature through contracted service providers, to protect the service, to comply with law, or at the customer's direction. Moderavia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.
Users can disconnect a Google integration in Moderavia, revoke authorization in their Google Account, or request deletion by contacting us. Revocation stops future access but does not by itself erase records that must be retained for security, audit, contractual, or legal reasons.