Privacy Policy – Google Sheets Tool
Effective Date: December 27, 2026
Summary
This Privacy Policy explains how the Google Sheets tool handles data when creating and editing spreadsheets on behalf of a user through ChatGPT. The app acts as a technical intermediary between ChatGPT and the Google Sheets API.
Overview
This app enables ChatGPT to create and edit Google Sheets based on structured instructions during a ChatGPT conversation. The app processes and forwards spreadsheet data to the Google Sheets API as required to fulfill requests.
Data We Process
The app processes:
- Spreadsheet data: Titles, column headers, cell values (including personal, financial, health, or other sensitive information entered by users)
- Authentication data: Google OAuth access tokens and refresh tokens (temporarily during requests)
- Metadata: Spreadsheet IDs, URLs, and titles (temporarily stored in memory for idempotency)
Data Protection Mechanisms for Sensitive Data
- Encryption in Transit: All data is transmitted over HTTPS/TLS 1.2+:
- All API communications between the app and Google Sheets API use HTTPS
- All communications between ChatGPT and the app use HTTPS
- OAuth flows use HTTPS endpoints only
- Secure Authentication: OAuth 2.0 with Google:
- Access tokens are used only during active requests and not stored persistently
- Token refresh is handled securely through Google's OAuth infrastructure
- Client credentials are stored securely as environment variables
- Minimal Data Retention:
- Spreadsheet contents are processed in memory only and discarded after each request
- Only non-sensitive metadata (spreadsheet ID, URLs, title) is stored temporarily in server memory for up to 24 hours for idempotency
- No spreadsheet content is stored on disk or in databases
- Access Controls: The app requests and uses only the minimum Google Sheets permissions required to create and edit spreadsheets
- No Data Analysis: The app does not analyze, transform, or derive insights from data beyond what is required to insert it into spreadsheets
- Secure Infrastructure: The app is designed to run on secure infrastructure with proper network security controls
How Data Is Used
Data is used only to create or update Google Spreadsheets as specified. The app:
- Receives spreadsheet specifications from ChatGPT
- Formats and transmits data to the Google Sheets API using the user's authorized Google account
- Returns confirmation and spreadsheet access URLs
- Does not use data for analytics, advertising, or other purposes
Data Storage and Retention
- Spreadsheet contents: Not stored; processed in memory during requests and discarded immediately after completion
- Authentication tokens: Used temporarily during requests; not stored persistently (ChatGPT manages token lifecycle)
- Metadata: Spreadsheet IDs, URLs, and titles are stored in server memory for up to 24 hours for idempotency; automatically deleted after 24 hours
- Logs: Operational logs may include high-level error or status information but exclude spreadsheet contents or sensitive personal data; access tokens in logs are truncated
Data Sharing
The app does not sell, share, or disclose user data to third parties. Data is transmitted only to:
- Google, as required to create or update spreadsheets via the Google Sheets API (subject to Google's Privacy Policy)
- ChatGPT, for returning operation results and spreadsheet access URLs
Google Account Access
The app accesses the user's Google account only after explicit authorization and requests the minimum Google Sheets permissions necessary to create and edit spreadsheets. The app does not access other Google services.
User Rights and Control
- All spreadsheets are owned by the user
- Users may view, modify, or delete their spreadsheets directly in Google Sheets at any time
- Users may revoke access at any time through their Google account settings
- Users may request information about their data by contacting us (see Contact section)
Security Measures
- HTTPS/TLS encryption for all data transmission
- Secure OAuth 2.0 authentication flows
- No persistent storage of sensitive data
- Minimal data collection and processing
- Regular security best practices implementation
Logging and Error Handling
Operational logs may include high-level error or status information but do not include spreadsheet contents or sensitive personal data. Access tokens in logs are truncated for security.
Changes to This Policy
This Privacy Policy may be updated as the app evolves or as requirements change. Material changes will be reflected in this document with an updated effective date. Continued use of the app after changes constitutes acceptance of the updated policy.
Third-Party Services
This app integrates with:
Users should review these third-party privacy policies to understand how they handle data.