Public OAuth disclosure

Drive metadata, with a narrow boundary.

Haeya Workspace Drive Metadata is an owner-operated capability for reviewing storage metadata from one authorized Google Drive account. It is designed for private storage analysis—not file access, advertising, or public account management.

Owner-only Metadata-only Read-only No advertising

Purpose

A private storage review, not a second Drive.

The requested Google scope is https://www.googleapis.com/auth/drive.metadata.readonly. It permits read-only access to Google Drive metadata so Haeya can prepare an owner-visible inventory and census. It does not authorize reading file contents or changing Drive.

01 · Authorize

Explicit owner action

Nothing is requested by visiting this disclosure site. OAuth begins only when the authenticated Workspace owner deliberately selects the metadata capability in the private Workspace.

02 · Inventory

Metadata, not bodies

The intended inventory is limited to metadata needed to understand owned My Drive structure, represented size, age, and review-only duplicate evidence.

03 · Review

Private evidence

Storage Core snapshots and census output are private owner evidence. They do not grant deletion authority and are not published, advertised, or sold.

Data boundary

What metadata means here.

The Google scope can make Drive file metadata available. Haeya’s intended inventory is bounded to the categories below and uses them only to provide the owner-facing storage review.

Metadata used

  • stable file, folder, and shortcut identifiers;
  • names, MIME types, and object type;
  • file size and quota usage when Google supplies them;
  • created and modified timestamps;
  • parent relationships, Drive space, and trashed state;
  • ownership metadata needed to limit coverage to items owned by the authorized account; and
  • provider checksums when Google supplies them.

Not accessed or performed

  • no file bodies, document contents, downloads, or exports;
  • no Shared Drives or directly shared items in the intended census;
  • no creation, editing, moving, renaming, sharing, or deletion;
  • no Gmail, Calendar, YouTube, or unrelated Google data; and
  • no advertising profiles, sale, or AI-model training.

Control

The owner stays in control.

Google access and refresh credentials are handled server-side and encrypted at rest. Google-side revocation stops provider authority; it does not by itself delete Haeya's encrypted local record. Local credential deletion occurs when the owner disconnects the capability in Haeya Workspace or completes a verified deletion request. Private Storage Core evidence remains owner-controlled and can be deleted manually or by sending a deletion request to haeya.biz@gmail.com.

Google API Services User Data Policy

Haeya Workspace’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.