Google API Services

Google API Data Policy

Last updated: 27 August 2026

This policy explains how Helena Bioinformatics EOOD uses Google Drive data when a Folklore user explicitly connects a Google account.

Access requested

Folklore requests the read-only Google Drive scope https://www.googleapis.com/auth/drive.readonly. It lets the user browse file metadata in My Drive and explicitly approved Shared Drives and download a selected binary genomic file for import.

The narrower drive.file scope is not sufficient because Folklore must read genomic files that already exist in user-selected Drive roots and were not created by Folklore or individually opened through the Google Picker. Folklore does not create, edit, rename, move, share, or delete Google Drive content.

Use, storage, and deletion

Drive access is initiated by the user. Folklore lists only the configured roots and imports only a file selected by the user. Google Docs, shortcuts, trashed objects, link-only objects, and files that cannot be downloaded are excluded.

OAuth tokens are encrypted at rest and used through short-lived operation leases. Disconnecting Google Drive removes the stored connector credentials. A genomic file that the user imports becomes customer-controlled case data and is handled under the Folklore Privacy Notice, contractual retention settings, and the customer's instructions.

Sharing and AI/ML

Raw files downloaded from Google Drive are not sent to an external AI provider. If a user separately invokes Folklore's private case assistant, a bounded derived case context may be sent directly to the OpenAI API to answer that user's request. The private case-assistant path uses OpenAI's standard API in a dedicated project; it does not use an aggregator or model hub. It excludes raw files, full genomes, direct identifiers, demographics, and unrestricted clinical notes.

Helena Bioinformatics does not use raw or derived Google Workspace API data to develop, improve, or train generalized AI or machine-learning models, and does not sell it or use it for advertising. The use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Contact and related policy

Questions can be sent to privacy@helena.bio. See the Privacy Notice for the broader privacy framework.