"You will use commercially reasonable efforts to protect user information collected by your API Client, including personally identifiable information (PII), from unauthorized access or use and will promptly report to your users any unauthorized access or use of such information."
User Privacy and API Clients
"You will comply with all privacy laws and regulations including those applying to PII. You will provide and adhere to a privacy policy for your API Client that clearly and accurately describes to users of your API Client what user information you collect (such as PII, login information and Google account data) and how you use and share such information (including for advertising) with Google and third parties. If your privacy policy is used to comply with the EU Data Protection Directive, then it must adhere to the US Safe Harbor principles of Notice, Choice, Onward Transfer, Security, Data Integrity, and Access at http://www.export.gov/safeharbor/eu/eg_main_018475.asp."
Retrieval of content
"When a user's non-public content is obtained through the APIs, you may not expose that content to other users or to third parties without explicit opt-in consent from that user."