One tap on "Sign in with Google" hands a token to a third party. It lives on their servers, survives the app being deleted, and only expires after six months without use. A new password revokes Google tokens that carry mail scopes and nothing else. Everything else stays until you remove it yourself.