Task Columns

Google API disclosure

For users and Google OAuth reviewers · Cloud project striking-audio-507113-r3

Limited Use Compliance Statement

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Task Columns's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Full policy: https://taskcolumns.com/privacy. Data protection: data protection mechanisms for sensitive data.

Scope Configuration & Justification

Task Columns is not an integration platform. It requests two production-ready, user-facing consents. Scopes in Cloud Console match the app.

  • Sign-in (least privilege, non-sensitive): openid, email, profile. Used only to create the Task Columns session (name, email, photo). Narrower is not viable because we need a stable account identifier and a display name.
  • Google Tasks (sensitive, production-ready): https://www.googleapis.com/auth/tasks. Used to create, update, complete, and reopen tasks so Inbox, Kanban, and Google Tasks stay in sync. The read-only scope https://www.googleapis.com/auth/tasks.readonly cannot write completion, title, notes, or due date back to Google, so two-way sync would not work. We do not request Gmail, Drive, Calendar, Chat, Photos, YouTube, or Data Portability.

Clear Integration Access

Exact navigation for reviewers. No phone number, payment, or waitlist.

  1. Open https://taskcolumns.com/login.
  2. Click Sign in with Google. Approve openid, email, and profile. If scopes are collapsed, click “Show all services.”
  3. After Inbox loads, go to Settings in the left sidebar, then Google Tasks (also at https://taskcolumns.com/settings/integrations/google).
  4. Click Connect Google. Approve https://www.googleapis.com/auth/tasks. Expand the consent screen so every requested scope is readable.
  5. Click Sync now. Google tasks appear in Inbox. Mark one Done in Task Columns, then confirm it is completed in tasks.google.com. Edit a title here and confirm the same title in Google Tasks.
  6. Optional: click Disconnect to drop stored tokens. That does not delete tasks in Google.

Active Test Credentials

Reviewers should use their own Google account on production. There is no phone verification, credit card, or other blocker.

If you only need to browse the board without Google Tasks, a local demo login is on the same page under Use demo account:

  • Email: demo@lattice.app
  • Password: demo1234

Demo login does not grant Google Tasks. To see the Tasks scope and write-back, use Sign in with Google and Connect Google as above.

Demo Video

The Cloud Console submission includes an unlisted YouTube walkthrough of this same path: Google sign-in consent, Connect Google Tasks consent with scopes expanded, Sync now, a title edit, Done → completed in the Google Tasks source account, and disconnect. Publishing status stays In Production. New scopes are not shipped to unverified production traffic; Tasks is requested only after the user clicks Connect Google.

CASA and Data Portability

CASA is not required: we request a sensitive Tasks scope, not a restricted scope. We do not request Data Portability APIs.

Questions: josef2011@gmail.com.