How we access, use, and protect the Google data our clients authorize — and how we handle it under Google's Limited Use policy.
Effective June 18, 2026
Charpen (PG&J) (“we,” “us”) operates a multi-client SEO/GEO monitoring platform used by our agency to monitor and report on the search and local-presence performance of client businesses that have authorized us to access their data.
With each client’s explicit authorization via Google OAuth, we access the following Google data belonging to that client:
We access this data only for properties a client connects, and only after they grant consent. We also store the basic account information of our own team members who sign in.
We use this information solely to display monitoring dashboards, generate performance reports, and raise alerts for the client whose data it is. We do not use it for advertising or any purpose unrelated to providing that client’s reporting service.
If a team member connects their Google account so the platform can send client reports and notifications from their address, we use the gmail.send permission only to send messages that the team member composes or triggers from within the platform. We do not read, search, or store the contents of any mailbox, and we do not access received mail. This is the narrowest Gmail permission available for sending.
We do not sell Google user data and we do not share it with advertisers, data brokers, or any third party for their own purposes. We share it only with the service providers needed to operate the platform, and only to the extent required to deliver the features described above:
We may also disclose data where required by law, or as part of a merger or acquisition.
We do not use Google user data to develop, improve, or train any generalized artificial-intelligence or machine-learning model, and we do not transfer Google user data to any third party that would use it for that purpose. Our AI provider processes the content described above only to return the requested draft and does not use it to train its models.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, lending, or credit decisions, and do not use or transfer it to develop, improve, or train generalized AI/ML models.
OAuth refresh tokens are encrypted at rest. Tenant data is isolated per organization and protected by database row-level security. Access is restricted to authorized team members. Data is transmitted over TLS.
We retain a client’s data for as long as they remain an active client. On request or on offboarding, we revoke the relevant Google authorizations and delete or export that client’s data. Clients may also revoke our access at any time from their Google Account permissions page.
Questions about this policy or your data: privacy@charpen.io.