Google User Data Policy

This Google User Data Policy describes how Oncancel accesses, uses, stores, and shares information obtained from Google APIs, in particular the Gmail API, when you use Oncancel's email-based subscription detection. It supplements the Oncancel Privacy Policy and applies only if you choose to connect a Google account. If you never connect a Google account, this policy does not apply to you; you can use Oncancel fully by connecting a bank account instead.

This policy is published by Endure Labs, Inc., a Delaware corporation with its principal place of business at 2228 Ellesworth Avenue, Copper Canyon, TX 75077, USA ("Oncancel", "we", "us", or "our").

1. What the Gmail connection does

Connecting Gmail lets Oncancel identify your subscriptions by reading subscription-related emails in your inbox, such as payment receipts, billing statements, renewal notices, price-change notices, trial-conversion notices, and cancellation confirmations. The information identified is used to build your subscription list in the app, power your spending and savings totals, and trigger renewal, price-increase, and free-trial alerts. Connecting Gmail is optional and requires your explicit consent on Google's consent screen.

2. The scope we request

Oncancel requests a single Gmail OAuth scope:

This is the minimum scope needed to deliver the feature. Because it is read-only, Oncancel cannot send, modify, archive, delete, or forward any of your email. We do not request any other Gmail permission or any other Google API permission for this feature.

3. Limited Use commitment

Oncancel's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In line with that commitment, we use information received from Google APIs only to:

We will not:

Oncancel personnel do not read your email data except in the narrow circumstances the Google API Services User Data Policy permits: with your explicit consent for a specific message (for example, when you ask support to investigate a mis-detected subscription), where necessary for security purposes such as investigating abuse, to comply with applicable law, or for internal operations using data that has been aggregated and anonymized.

4. What we derive and what we store

When a scan runs, Oncancel processes messages that match subscription-related queries and derives structured data points such as: the merchant or service name, the transaction amount and currency, the billing cycle (for example weekly, monthly, or annual), the next expected charge date, and detection timestamps. This derived data is what we store and show you in the app.

We do not store the full content of your emails, and the feature is designed to focus on subscription-related messages rather than personal correspondence. Gmail access tokens are stored encrypted and are used only to run subscription scans and keep your alerts current.

5. Sub-processors

A small number of sub-processors support this feature: our cloud hosting provider, which hosts the backend services that process subscription detection, and Google LLC, as the provider of the Gmail API, OAuth identity, and the Google Cloud project that hosts our OAuth client. Sub-processors process information received from Google APIs only on our instructions and under contractual obligations consistent with the Google API Services User Data Policy, including the Limited Use requirements.

6. Your control over Google data

To keep your subscription list and alerts up to date, Oncancel maintains an authorized read-only connection to your Gmail account after you grant consent, until you revoke it. You control that access through any of the following paths:

Disconnecting Gmail stops further access but does not by itself delete the subscription data already derived from earlier scans, since you may still want your history. To remove that data too, delete your account or email support@oncancel.com with a specific deletion request.

7. Security

We protect information received from Google APIs with encryption in transit (TLS 1.2 or higher) and at rest (AES-256), encrypted token storage, role-based access controls, multi-factor authentication on administrative access, security logging and monitoring, and regular vulnerability management. In addition, our Gmail integration undergoes an independent third-party security assessment (CASA, the Cloud Application Security Assessment framework), which Google requires before granting and renewing restricted-scope access. No system can be guaranteed completely secure, but we apply commercially reasonable measures to protect this data.

8. Changes to this policy

We may update this policy from time to time, revising the "Last updated" date above. If a change is material, for example a change to the Google API scopes we request or to how we use, store, or share Google user data, we will notify you in advance in the app or by email, prompt you to consent to the updated terms before any additional access begins, and, where required, complete an additional independent security assessment.

9. Contact

For privacy questions specific to our handling of Google user data, email support@oncancel.com with the subject line "Google User Data". We respond within 30 days.

To report a security vulnerability affecting our Google API integration, such as an issue in the OAuth flow or token handling, email security@oncancel.com privately with a description, reproduction steps, and supporting material, before any public disclosure. We aim to acknowledge reports within 3 business days.

Endure Labs, Inc.
2228 Ellesworth Avenue, Copper Canyon, TX 75077, USA