OAuth access and refresh credentials are stored and managed in Base44’s secure connector infrastructure. They are not stored in Lorescent Customer Content, institution records, or ordinary application logs. Lorescent may store the connected account label; Google file or folder identifiers, names, types, links, timestamps, and parent relationships; allowed Drive boundaries; synchronization state; external-record relationships; and integration audit events.
Original Google files remain in Google unless the authorized user directs a supported Google action. When a user imports or processes a Google file, Lorescent may store a copy of selected or extracted content and Lorescent-derived records—such as text, transcripts, summaries, quotations, evidence, metadata, and Story development material—inside the institution’s Lorescent workspace. When Lorescent creates a Google Doc, Sheet, Slide, calendar event, folder, or other requested item, the created item remains in the connected Google service and Lorescent may store its identifier, link, title, and status.
Google user data may be available to authorized users of the same institution workspace and to service providers that process it solely for hosting, security, connector operation, transcription, AI-assisted processing, support, or another purpose necessary to provide Lorescent. We do not sell Google user data, share it with advertising platforms or data brokers, or permit service providers to use it for their own independent purposes. Human access is limited to the user’s direction, support or security needs, legal requirements, or authorized institution administration.
Google-derived information is retained only for as long as reasonably necessary to provide the connected feature, maintain the institution’s requested Lorescent archive, satisfy the applicable agreement, protect security, or comply with law. A user can disconnect a personal Google integration in Lorescent and can revoke Google authorization through the Google Account permissions page. Revocation or disconnection stops future API access after the revocation is processed, but it does not automatically delete content already imported into Lorescent or records created from that content. An authorized user or institution administrator may delete supported Lorescent records or request deletion of stored Google-derived data by contacting us. Residual copies may remain for a limited period in backups, security logs, or legally required records before deletion or isolation.