Third-party apps and sites you once granted Google Account access can keep reading Gmail, Drive, Contacts, or calendar data until you revoke them. Review myaccount.google.com/connections (or Account → Security → Third-party access) on a schedule and remove anything you do not recognize or no longer use. This how-to is Google account OAuth/app access—not Find My Device setup, not Chrome Enhanced Safe Browsing, and not Apple Sign in with Apple review.

1. Why review access

“Sign in with Google” is convenient; forgotten CRM tools, old PDF editors, and malicious look-alike apps accumulate scopes. After a phishing incident, revocation is part of cleanup alongside a password change.

Only trust Google’s own myaccount.google.com UI for revocation. Random “Google permission cleaner” extensions and sites are a common way to grant *more* access while pretending to help.

2. What “access” is not

ItemMeaningSeparate control
Third-party app accessOAuth to Google dataThis guide
Android app permissionsCamera/mic/storage on the phoneAndroid Settings → Apps
Work profile appsManaged container isolationWork profile guide
Chrome Safe BrowsingBrowser phishing/malware warningsEnhanced Safe Browsing

3. Steps: review and revoke

  1. On a trusted device, open a browser and go to https://myaccount.google.com/connections (or myaccount.google.comSecurity → third-party access / connections—labels change over time).
  2. Sign in with the Google Account you care about. Prefer a bookmark you typed, not an email link.
  3. List apps and sites with access. Open each entry; read which data types it can see or do.
  4. Tap/click Delete all connections you have with … / Remove Access / Revoke for anything unknown, unused, or overly broad (full Gmail + Drive for a flashlight-style app is a smell).
  5. Repeat for other Google Accounts you use (work vs personal).
  6. Change the Google password if you suspect account theft; turn on 2-Step Verification if it is off.
  7. Check recent security activity in the Google Account for unfamiliar locations or devices.
  8. On Windows, keep one antivirus primary—Norton, Bitdefender, or other on-site options (TotalAV, McAfee, Avast)—especially if a bad app was authorized from a PC browser.

4. After a suspicious grant

  1. Revoke first, then change password and review recovery phone/email.
  2. Check Gmail filters and forwarding rules for attacker persistence.
  3. Watch for fake Google Play billing phishing that tries to re-steal the password you just rotated.

FAQ

Will revoking break a legitimate app?

Yes—you will need to sign in again and re-consent if you still use it. That is expected.

Is this the same as removing a device from Find My Device?

No. Device locate settings are separate from OAuth app connections.

Can Apple Sign in with Apple apps show here?

No. Those are Apple Account permissions—see the Sign in with Apple review guide.

How often should I review?

A practical habit is monthly, plus immediately after any phishing click or shared-computer sign-in.

Avoiding how to review Google account third-party app access does not require paid antivirus. Careful habits and official support paths are a valid buy-nothing stack. If you want multi-device paid protection later, use only these on-site paid links: TotalAV (paid link), Norton (paid link), Bitdefender (paid link), McAfee (paid link), Avast (paid link).