GBPly connects to your Google Business Profile using Google's official OAuth flow. You sign in with Google directly; we never see, ask for, or store your Google password.
By default, we request only two scopes:
business.manage — to read and update the Business Profiles you choose to manage: business information, posts, photos, reviews and replies, and performance data.userinfo.email — to identify which Google account is connected, so you can safely link and separate multiple accounts.
If you choose to connect your own mailbox so client emails come from your address, that is a separate, optional sign-in you start from Workspace Settings:
gmail.send — permission to send email on your behalf, used only for the emails you schedule or trigger in GBPly, such as review requests, client reminders and activity summaries. It does not allow reading, searching or deleting anything in your mailbox. The equivalent Microsoft 365 permission (Mail.Send) is used if you connect an Outlook mailbox instead.
This mailbox connection is optional, is not needed for day-to-day use, and can be removed at any time from Workspace Settings.
We do not request access to Google Drive, Google Ads, Search Console, or Google Analytics. You can disconnect a Google account from GBPly at any time, and you can also revoke access from your Google account security settings. When you delete your GBPly account, we revoke the tokens we hold with Google.