1. Disconnect Google from HomeCraft
An authorized user can open Settings → Google Workspace, locate the exact connected account, and choose Disconnect. HomeCraft disables that connection before attempting provider revocation, so it cannot be used for new Google API access while disconnection is being completed.
When disconnection completes, HomeCraft deletes the encrypted local refresh-token secret and marks the credential record deleted. HomeCraft retains non-secret connection and audit history needed to show who disconnected the capability, when it changed, and whether provider revocation was confirmed.
If Google does not confirm revocation, the connection remains disabled in HomeCraft. The encrypted credential may be retained only while an authorized retry is needed; it is deleted after the safe disconnect completes. When another explicit HomeCraft binding uses the same Google grant, HomeCraft may skip provider-wide revocation to avoid disabling that other binding while still deleting the disconnected binding’s local credential.
2. Revoke access in your Google Account
You may also remove HomeCraft from the third-party connections page in your Google Account. Revoking access at Google prevents future token use but does not delete email, files, calendars, or other content held by Google.
After revoking access at Google, disconnect the corresponding account in HomeCraft or ask your tenant administrator to do so. This lets HomeCraft record the connection state and remove its local encrypted credential material through the controlled disconnect workflow.
3. Gmail mailbox-review data
When the optional restricted mailbox-review capability is enabled and the exact connected user runs a search, HomeCraft requests metadata headers for at most 10 matching threads. The search text and returned sender, recipient, subject, date, message body, attachment, and result content are not stored by HomeCraft.
HomeCraft retains a content-free access audit and, only when the user explicitly confirms it, the exact Gmail thread and message identifiers linked to a project. Disconnecting Google stops future mailbox access but does not silently erase an authorized project link or other canonical HomeCraft business record.
4. Request access, export, correction, or deletion
Contact your HomeCraft tenant administrator first when the request concerns business records controlled by your company. You may also email privacy@homecraftos.com with the connected Google email address, the HomeCraft company name, and the specific access, export, correction, or deletion request. Do not send passwords, OAuth tokens, or private mailbox content.
HomeCraft will verify the requester’s identity and authority for the affected tenant before acting. We will delete or de-identify eligible HomeCraft data when appropriate, but some canonical business, security, financial, legal, or audit records may need to be retained for continuity, accountability, dispute resolution, or legal obligations. Required corrections use the applicable HomeCraft correction or reversal workflow rather than silently rewriting posted records.
5. What HomeCraft does not delete from Google
Disconnecting HomeCraft or deleting eligible HomeCraft records does not delete the user’s original Gmail messages, Google Drive files, Google Calendar data, or other Google-account content. Google remains the authority for that provider content, and the user must manage or delete it through Google.
For more information, read the HomeCraft Privacy Notice and Terms of Service.
