This policy explains exactly what Workaholic Connect can see when you connect an account, what we do with it, and how to take that access away. It is written to be read, not to be skimmed past.
Effective 4 August 2026 · Last updated 4 August 2026
Workaholic Connect is operated by Workaholic Developers ("Workaholic", "we", "us"), a software company with engineering teams in India and client operations in Canada. We build and run business systems for our clients.
This policy covers Workaholic Connect only — the service
at connect.workaholicdevelopers.com that links the accounts you
already own to the systems we build for you. Our main website has its own
separate privacy policy covering ordinary visitors.
You already use tools like Google Workspace, Microsoft 365 or Dropbox. The systems we build for you often need to work alongside those tools — putting a confirmed booking on your calendar, saving a report where your team can find it, sending a confirmation from your own address.
Rather than asking you for passwords, or asking again for every separate system we build, Connect uses the industry-standard authorisation process offered by each provider. You approve a specific, listed set of permissions directly with Google, Microsoft or Dropbox. They give us a revocable token. We never see or hold your password.
You are shown the exact list at the moment you connect, and you can review it at any time in your provider's own security settings. Nothing below is requested unless the feature you have asked for requires it.
| Permission | What it lets us do |
|---|---|
openid, email, profile | Identify which account has been connected, and show your name against it. |
calendar.events | Create and update the appointments your system books. We do not read or alter events we did not create. |
calendar.readonly | Check availability before offering a time, so you are not double-booked. |
drive.file | Save files we generate for you, and open files you explicitly choose. This permission cannot see the rest of your Drive. |
spreadsheets, documents | Write the exports, reports and documents you have asked the system to produce. |
contacts.readonly | Import your contacts into your own system, when you ask for that import. |
tasks | Keep task lists in step between your system and Google Tasks. |
youtube.upload | Publish video to channels you own, when you have asked us to manage them. |
| Permission | What it lets us do |
|---|---|
User.Read | Identify the connected account. |
Calendars.ReadWrite | Check availability and place confirmed bookings. |
Files.ReadWrite | Save generated reports and exports to OneDrive or SharePoint. |
Mail.Send | Send the messages your system generates — confirmations, receipts, notices — from your own address. |
Contacts.ReadWrite | Keep contact records in step with your system. |
offline_access | Continue working without asking you to sign in again every hour. |
| Permission | What it lets us do |
|---|---|
account_info.read | Identify the connected account. |
files.metadata.read | List file names and folders so you can choose where things are saved. |
files.content.read | Open files you have explicitly pointed us at. |
files.content.write | Save the reports and exports we generate for you. |
sharing.write | Create share links for deliverables, when you ask for one. |
We keep the minimum needed to keep the connection working:
Equally important is what we do not keep:
We use this access for one purpose: to perform the actions the systems you have commissioned are meant to perform. Nothing else.
Specifically, and without exception:
Workaholic Connect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: data obtained through Google APIs is used only to provide or improve the features you have asked for, is not transferred to others except as required to provide those features or by law, is not used for advertising, and is not read by humans except with your explicit permission, for security purposes, to comply with the law, or where the data has been aggregated and anonymised.
No third party receives your connected-account data. We do not share it with advertisers, data brokers, or analytics companies.
The only exceptions are the ordinary, necessary ones:
For as long as the connection is active, and no longer. When you disconnect an account, the stored token is deleted and we instruct the provider to revoke it. Operational logs recording that an action took place — without the content of that action — may be retained for a reasonable period for security and accounting.
You are never locked in. You can withdraw access at any time, two ways:
Revoking access stops any feature that depended on it. Nothing else about your systems is affected.
Tokens are encrypted at rest, all traffic runs over TLS, and access is restricted and logged. Our Security page sets out precisely what we do — and is deliberately limited to measures actually in place.
Depending on where you are, you may have rights under laws such as India's Digital Personal Data Protection Act, Canadian privacy legislation, or the GDPR. Regardless of which applies to you, we will honour a request to:
Write to info@workaholicdevelopers.com. We aim to respond within 30 days and will tell you promptly if a request will take longer.
Workaholic has teams in India and Canada, and our infrastructure is located with our hosting provider. Your data may therefore be processed in more than one country. Wherever it is handled, the protections in this policy apply.
Connect is a business service and is not directed at children. We do not knowingly create connections for anyone under 18.
If we change what we access or what we do with it, we will update this page and change the date above. Where a change materially affects you, we will tell you directly rather than relying on you to notice.
Questions about this policy, or about anything Connect has done on your behalf, go to info@workaholicdevelopers.com. A person reads that address.