Google Forms Connector Privacy Notice
International privacy notice for the optional file.kiwi Google Forms Connector
1. Scope and your choice
Last updated: 8 September 2026.
This international notice explains how file.kiwi Google Forms Connector accesses, uses, stores, shares, and deletes Google user data. It forms part of the file.kiwi Privacy Policy, which identifies MiniKiwi and provides our contact details, processing grounds, international-transfer safeguards, and privacy-request procedures.
The Connector is optional. It connects a Google Form you select to your Collection Web Folder. Google user data is accessed only after you choose to connect and complete Google authorization. If you do not proceed, you can continue using other file.kiwi features.
When the connection screen identifies your request’s IP country as the Republic of Korea, it shows the Korean Google Forms notice, regardless of your interface language. Other requests are shown this international notice. This display rule does not determine which privacy laws apply to you.
Choosing to connect authorizes the requested Google access and the connection activities described here. It is not blanket consent to unrelated processing or a substitute for required international-transfer safeguards. Where separate consent is required, it must be obtained for that specific activity. We record the notice version you accepted and the acceptance time with the authorization record.
2. Permissions and information used
The Connector uses the following Google permissions:
drive.file: To read and update the existing Google Form that you explicitly select. It does not search or inspect your other Google Drive files.forms: This permission can allow broad access to Google Forms, but our integration uses it only to open the selected form and set or restore its submission-confirmation message.
To configure the connection, we read the selected form’s identifier, title, availability and response-acceptance status, question identifiers and settings, and responder and edit links.
We add required FileID and UploadURL fields to the form and prefill them in respondent links to associate a response with its file upload. We also update the submission-confirmation message. The original message and connection language are kept on Google’s systems so the message can be restored.
When the embedded form signals a page transition, we check recent responses on our server. Google’s response may include answers to other questions, but file.kiwi uses only the prefilled FileID and UploadURL answers to verify the upload and label the corresponding files. Answers to other questions are not used, logged, or retained. We retain the Google response identifier to prevent duplicate processing.
We also process the authorization information, connection and upload-session records, processing status, and notice-acceptance records needed to operate and secure the connection. Information comes from you, the selected form and its respondents, and Google’s services.
MiniKiwi is responsible for its own operation and security of the Connector. The form or Web Folder organizer is responsible for explaining its own collection and use of respondents’ information. The organizer’s authorization is not a respondent’s consent.
3. Storage, retention, and deletion
Authorization credentials are encrypted during transfer and storage. The one-time authorization code is not retained. Short-lived credentials are used only until expiry, and renewal credentials are used only while the connection is active.
Connection records and related response-processing, synchronization, and connection upload-session records are retained while the Connector is provided for the associated Collection Web Folder. An active connection is not deleted merely because six months have passed since it was connected or reconnected.
When you disconnect, we first use Apps Script to restore the original submission-confirmation message and delete the script settings kept for recovery, including the form identifier, connection language, and original message. The FileID and UploadURL fields and their descriptions remain in the form. We then delete the connection and its related response identifiers, processing records, synchronization state, and connection upload sessions from D1 and stop new response processing. We delete the same D1 connection records when you directly delete the associated Collection Web Folder. A daily cleanup removes orphaned connections after a Web Folder has been automatically deleted or its valid folder record is otherwise absent.
Credentials and notice-acceptance records are deleted when no remaining connection uses their authorization record. An authorization record created during an incomplete or replaced connection attempt may be retained for retry and error recovery for up to 30 days, then deleted if it remains unused. Unsuccessful or unfinished cleanup continues on subsequent daily runs. Limited recovery copies follow the provider’s recovery period; Cloudflare’s standard database recovery window is 7 or 30 days, depending on the service plan.
Disconnecting restores the original submission-confirmation message, deletes the Apps Script settings kept for that restoration, deletes the file.kiwi records described above, and erases stored credentials that no other connection uses. It does not delete the original Google Form, its responses, or the FileID and UploadURL fields. If you delete the Web Folder or close your account without using Disconnect first, the Google Form message and Apps Script settings may not be automatically restored or deleted.
4. Providers and international processing
MiniKiwi operates from the Republic of Korea. Connection data may be processed outside your country.
| Provider | Information and purpose | Processing location |
|---|---|---|
| Google LLC | Selected form information, response data, upload-reference fields, and the original confirmation message and language, to authorize access, connect, update, verify, and restore the selected form. The form remains in its owner’s Google account; our integration runs on Google’s systems. | Google’s global infrastructure. The form and integration are not subject to a promised enterprise data-location restriction. |
| Cloudflare, Inc. | Encrypted authorization credentials, connection and processing records, response identifiers, and notice-acceptance records, to host the connection, retain authorization, process responses, and protect the Service. | The reported storage region for connection records is Asia-Pacific; this is not a guarantee of storage in a particular country. Requests may be processed through its global network. |
The storage region for Google Forms connections is separate from the storage arrangement for audience-measurement records. Asia-Pacific is a region, not a country, and does not describe every processing, support, or recovery location.
For covered processing, provider safeguards include applicable contractual data-protection terms and transfer mechanisms. Their scope and the safeguards for our international processing are explained in Section 8 of the Privacy Policy. Google authorization does not itself establish a lawful basis for every international transfer. You can contact us to ask which safeguards apply to your information and how to obtain a copy, subject to necessary redactions.
Provider information and contacts:
- Google: Privacy Policy, international-transfer information, Forms and integration data-region information, and privacy inquiries.
- Cloudflare: Privacy Policy, Data Processing Addendum, recovery information, and [email protected].
5. Restrictions on use and sharing
file.kiwi does not sell Google user data or use it for advertising, creditworthiness, or lending. Google Workspace API data is not used to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
Humans do not read Google user data except with your affirmative consent, when necessary to investigate security, errors, or abuse, or when required by law. Google user data is not transferred to third parties except the Google and Cloudflare providers needed to provide the connection as described here.
file.kiwi’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Disconnecting and privacy requests
You can remove the Google Forms connection from your Web Folder and revoke authorization in your Google Account security settings. When you use Disconnect, file.kiwi restores the original submission-confirmation message and deletes its recovery settings before deleting the D1 connection records. FileID and UploadURL remain. If Google access was revoked first or restoration fails, disconnection is not completed and can be retried. Section 3 explains what is deleted, what processing stops, and which records may remain.
For access, correction, deletion, withdrawal of consent where applicable, or other privacy requests, contact [email protected]. You do not have to stop using unrelated file.kiwi features. Rights, response deadlines, complaints, and any permitted retention are explained in Section 9 of the Privacy Policy and its applicable regional sections.