Sign in with Google: Deleting the app doesn't revoke access
By pressing the blue button for quick sign-in to apps with a Google account, the app receives an access token, which is then stored on the provider's servers and not on your device. This is why uninstalling the app from your phone does not delete this login token. The token only stops working if the user revokes access, after six months of non-use, or in the event of certain technical changes. However, any data refresh, such as checking your calendar weekly, automatically resets this six-month period to zero.
Many users change their passwords when they suspect a security risk, believing that doing so will disconnect all external services. However, this only applies to tokens that have direct access to Gmail email. All other access, including Google Drive, Calendar, and Contacts, remains completely intact when changing the password. The exceptions to email are Apps Scripts and password changes made directly on Android devices.
These mechanisms raise legitimate concerns about the security of modern online logins, as users live in a false sense of security. Revocation of access only disables further logins, but does not delete data already stored by the provider. For example, attackers have used stolen tokens in the past to access corporate data without requiring a password or two-factor authentication code.
For full control, you need to visit your account settings at myaccount.google.com/linkedapps, where access is divided into three categories. Apple, Facebook, and Microsoft also have similar sections. Regularly checking these lists and removing suspicious apps is the only effective way to close the open door to your personal data.























