I intentionally simplified that language to
> [accesses Gmail and also accesses other servers]
... because that's all that convoluted line means. Break it down:
- Access to "restricted scope Google user's data" (in this case, all we care about is Gmail)
- AND ability to access data from or through a third party server.
It's that last bit that people seem to be getting confused about. For example:
- if your app accesses Gmail and Hotmail accounts, then your app is doing both
- if your app accesses Gmail and also checks today's weather, you're doing both
- if your app accesses Gmail and sends basic usage telemetry. Or checks for updates. Or has plugins that provide spam checking or virus scanning... you're probably doing both
- if your app has ANY plugin system, it could be argued that your app is doing both.
While the language may be unclear, "third party server" is probably intended to reference any non-google service.
And my overall point still stands: YOU do not get to decide what triggers their security review. All you have the right to do is pay the bill.