Privacy Policy
In short
Sheet Alerts sends reminders based on dates in your Google Sheet. To do that, we store a small part of your data: the rules you set and, for each scheduled reminder, the recipient and the text.
We read only the file you are using the add-on in, and only the columns you point at yourself. We have no access to your other files in Google Drive, and none to your Gmail.
What we process
| Data | Why | Kept for |
|---|---|---|
| Your Google email address | To recognize your installation | 90 days after the add-on last contacts us |
| Your spreadsheet ID | To link your rules to the right file | Same |
| Your reminder rules | To know what to send and when | Same |
| Per scheduled reminder: recipient, subject, text | To be able to send it | 90 days after it was sent, failed, or was cancelled |
| Send log | So you can see what went out | 90 days |
| Addresses that unsubscribed or bounced | So we never mail them again, which is the point of unsubscribing | Until the address is resubscribed |
We store no cell content beyond what appears in a reminder you set up yourself.
A job runs once a day and deletes whatever is past those dates. It is not a promise on paper: if the add-on stops contacting us, which is what happens when you remove it or delete the spreadsheet, everything belonging to that installation is deleted after 90 days of silence.
The permissions we ask for, and why
- The current spreadsheet only (
spreadsheets.currentonly): to read the columns you point at and to write the log tab. This permission gives no access to any other file. - Connect to our server (
script.external_request): to pass on your rules. - Schedule a task (
script.scriptapp): to check hourly whether something needs to go out. - Show the sidebar (
script.container.ui): to display the setup panel inside your spreadsheet. - Your email address (
userinfo.email): to identify your account.
We ask for no access to Gmail and no access to your Drive.
Who we share data with
We use two processors, and nobody else:
- Cloudflare runs our server and database. Your rules and your scheduled reminders are stored in the European Union.
- Resend delivers the email. Resend is based in the United States, so a recipient's address and the text of a reminder leave the EU at the moment we send it.
We do not sell data, we do not run advertising, and we do not use your data to train models.
Use of Google user data
Sheet Alerts' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: we use your data only to deliver the feature you set up yourself, we do not share it, and no human reads it (unless you explicitly ask us to while troubleshooting, or the law requires it).
Your rights
- Delete everything now: email us and we erase it within 30 days. If you simply remove the add-on, everything goes automatically after 90 days of silence, because removing an add-on sends us no signal. We would rather tell you that than pretend we get a notification we do not get.
- Request a copy: ask us for what we hold about you.
- Object or file a complaint: object to how we use your data, or take a complaint to your data protection authority.
Write to support@sheetalerts.com. We respond within 30 days.
Security
All traffic runs over an encrypted connection. The secret your installation uses to identify itself is stored only as a one-way hash. Anyone reading our database could do nothing with it.
Children
Sheet Alerts is not intended for users under 16.
Changes
If we change this policy materially, we will say so inside the add-on before the change takes effect.