Google API Data Use
Prisma Connect lets people connect their own Google accounts to an AI assistant such as Claude or ChatGPT. This page explains which Google data the service can access, why it is used, where it is sent, and what is stored.
Last updated: 21 September 2026
What Prisma Connect does
Users organize accounts into groups — one per business, client, or personal space — and choose which read or write actions their AI assistant may use for each connected Google account.
Google data that may be accessed
Depending on the connector and actions the user enables, Prisma Connect may access:
- Google Analytics reports and account or property configuration.
- Google Ads accounts, reports, campaigns, conversion actions, and related configuration.
- Google Calendar calendars and events.
- Google Docs content and formatting.
- Selected Google Drive files, folders, and file metadata.
- Google Sheets values, formulas, and formatting.
- Google Search Console sites, performance data, sitemaps, and indexing actions.
- Gmail messages, drafts, labels, and sending actions when the Gmail connector is enabled.
Prisma Connect requests only the scopes required for the actions the user enables. An action is run only when the user asks their connected AI assistant to run it.
How Google data is used and shared
After authorization, Prisma Connect retrieves only the data needed for the requested action and passes the result to the AI assistant selected by that user. Google data is not sold, used for advertising, or used for profiling. Prisma Connect does not use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or machine-learning models. Google data is not sent to an AI provider unless the user invokes an enabled action through that provider. The selected AI provider then handles that result under the user's account and agreement with it.
What is stored
Prisma Connect stores the user's account settings and encrypted Google OAuth credentials so the connection continues to work. Google source content is fetched live for every request and is not cached or stored in Prisma Connect's database, backups, or persistent logs. Account settings and encrypted credentials can remain in encrypted disaster-recovery backups for up to approximately 14 days after account deletion. See the Data Retention Policy for details.
User control
Every connector can be turned off. Read and write permissions are controlled separately, and actions that create, send, edit, publish, or delete remain disabled until the user deliberately enables them for the relevant account. Users can disable individual actions, disconnect a Google account, or delete their Prisma Connect account at any time.
Security and human access
Google OAuth credentials are encrypted at rest and traffic uses HTTPS. Connector results are marked as untrusted data so an AI client is instructed not to follow commands embedded inside emails, documents, files, events, or API results. Prisma Connect staff do not read Google source content except with the user's affirmative permission for requested support, for security or abuse investigation, in aggregated and anonymized form for internal operations, or when legally required.
Prisma Connect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.