8. Google Workspace for Stream Deck: Google OAuth & User Data
Last Updated: August 2026
The Arise Google Workspace for Stream Deck plugin (Arise GWS) uses Google OAuth 2.0 to read data from your Google account, and to take the specific write actions listed below, so it can display and act on your account from Stream Deck hardware keys and dials. This section explicitly describes what Google user data is accessed, the sole purpose for which it is used, and how it is protected.
Google User Data We Access
The plugin requests ten narrow OAuth scopes across Calendar, Chat, the People API, and Gmail. None fall into Google’s restricted category, and Google Drive requires no scope at all. Most are read-only:
- Google Calendar: Read access to your agenda (event titles, times, attendees, meeting links) so it can be shown on keys and dials, and to the list of your calendar names so you can pick which calendar is read. Attendee availability is checked through the free/busy query, which returns busy/free time windows only — never the contents of anyone else’s events. Writes only when you press a key that says it will: Schedule Follow-up and Extend Meeting create a calendar event with a Google Meet link, and invited attendees are notified, exactly as if you had created the event in Calendar yourself.
- Google Chat: Read access to the list of your chat spaces and their memberships, so you can pick a destination and direct messages are labeled correctly. The plugin cannot read the content of any chat message. It sends a message only when you press a key that explicitly sends one; sent messages appear under your own name with a visible app tag beside them.
- Directory & Contact Names: Read-only access to your Workspace directory and your own contacts, used solely to display the names of your direct-message partners on the key you configure. No contact data is modified, stored beyond the session, or shared.
- Gmail: Read-only access to Gmail label metadata — the unread and total counts of labels you choose. The plugin cannot read message contents or subject lines, and cannot send, modify, or delete email.
- Account Identity: The OpenID identity scope, used to tell your own account apart from other people in a conversation (for example, which side of a direct message is you). It grants no access to any Google data.
- Google Drive: No Google Drive API access at all. Drive keys simply open drive.google.com pages in your browser. Listing your own folders would have required a broader scope, which we chose not to request.
- Google Meet: No separate Google API access. Meet keys join using the meeting link already present in your Calendar data (see above) and open it in your browser. There is no distinct Meet API call.
Write Actions: Explicit and Key-Triggered Only
The plugin never writes to your Google account in the background. It writes only when you press a key whose stated purpose is to do so: Schedule Follow-up and Extend Meeting create a calendar event, and Join Meeting (with announcing enabled) or Announce send a chat message. If any attendee’s availability cannot be verified, scheduling refuses to book over them and opens Google Calendar’s own editor with the proposed time for you to confirm by hand. Every other action is read-only: reading your agenda, listing calendars or chats, checking availability windows, and reading unread counts.
No Server-Side Storage:
Arise Create does not store, transmit, or process any Google user data on its servers. All data fetched from Google APIs is processed and displayed directly by the plugin on your device. No Google user data is ever sent to Arise Create infrastructure.
All Data Stays Local:
The plugin communicates directly between your device and Google’s APIs over HTTPS. Your OAuth tokens are stored securely on your device and are never transmitted to or accessible by Arise Create. Signing out inside the plugin clears everything it read from your account — cached agendas, chat names, and prepared drafts included.
Revoking Access:
You can revoke the plugin’s access to your Google account at any time by visiting myaccount.google.com/security, navigating to "Third-party apps with account access", and removing the Arise Google Workspace for Stream Deck application.
Privacy Contact:
For questions specifically about how the Arise Google Workspace plugin handles your Google user data, contact us at:
privacy@arise-create.de
This page covers data handling specific to the Arise Google Workspace for Stream Deck OAuth application. For general Arise Create website and product privacy practices, see the Arise Create Privacy Policy.