Security & Privacy

OAuth & Permissions

Understanding Google OAuth and Synoveo's permissions

Synoveo uses Google OAuth to securely access your Google Business Profile.

OAuth Flow

When you connect your Google account:

  1. You're redirected to Google
  2. Google shows requested permissions
  3. You approve or deny
  4. Google sends tokens to Synoveo
  5. Synoveo uses tokens to access your GBP

Permissions Requested

Synoveo requests minimal permissions:

ScopePurpose
business.manageRead and update your GBP
userinfo.profileIdentify your account

What We CAN Do

  • Read your business profiles
  • Update profile information
  • Create and manage posts
  • Reply to reviews
  • Upload photos

What We CAN'T Do

  • Access your Gmail
  • Access Google Drive
  • Access other Google services
  • Change your Google password
  • Access your Google Ads

Token Management

Access Tokens

  • Short-lived (1 hour)
  • Used for API calls
  • Automatically refreshed

Refresh Tokens

  • Long-lived (6 months)
  • Used to get new access tokens
  • Encrypted at rest

Token Refresh

  • Automatic before expiration
  • Background refresh (no interruption)
  • Re-auth prompt if refresh fails

Revoking Access

You can revoke Synoveo's access anytime:

In Synoveo

  1. Go to Settings → Connected Accounts
  2. Click "Disconnect Google"
  3. Confirm disconnection

In Google

  1. Go to Google Security Settings
  2. Find "Third-party apps with account access"
  3. Remove Synoveo

Cross-Account Protection

Synoveo supports Google's Cross-Account Protection:

  • Security events from Google
  • Automatic token invalidation if suspicious activity
  • Re-authentication required after security events

Security Best Practices

  1. Connect only needed accounts - Don't connect personal accounts
  2. Review permissions - Understand what you're granting
  3. Monitor activity - Check sync history regularly
  4. Disconnect if unused - Remove access when not needed

On this page