Privacy Policy
Last updated: May 12, 2026
gptsheet is built around a simple promise: your data and API keys don't touch our servers. This page explains exactly what we store, where, and why.
What we collect
- Email address. When you purchase a license, Stripe collects your email at checkout. We store it alongside your license key so we can deliver the key and bind it to your Google account.
- License key + bound Google account email. When you activate your license inside the add-on, we record which Google account it was bound to so the key cannot be re-used by someone else.
- Server logs. Our license-verification endpoint logs request IPs and timestamps for at most 30 days, used only to debug failures and detect abuse.
What we do not collect
- The contents of your spreadsheets.
- Your prompts to OpenAI, Anthropic, or Google Gemini.
- The output of any LLM call you make.
- Your LLM provider API keys. These are stored locally in your browser (sidebar tools) or in Google's per-user properties storage (cell formulas). They never transit our servers.
- Analytics, tracking pixels, or cookies on the marketing site beyond what Vercel sets automatically for hosting.
Where your data lives
- Your license key + bound email: Supabase (Postgres), in the EU/US region you visit closest.
- Your provider API keys: Your browser's
localStorage(for the sidebar) and Google'sPropertiesService(for cell formulas). Neither is visible to us. - Payment info: Stripe. We never see your card number.
- License delivery emails: Sent via Amazon SES.
Third parties we use
- Stripe — payment processing.
- Supabase — license storage and verification.
- Amazon Web Services (SES) — license-delivery email.
- Vercel — hosting for the marketing site and docs.
- Google — Apps Script runtime, OAuth, Workspace Marketplace listing.
We don't sell or share your data with any other party.
What gptsheet sends to LLM providers
When you run a formula or use the sidebar, your prompt (and any cell values you reference) goes directly from your browser or from Google's Apps Script runtime to the LLM provider whose API key you configured. We have no visibility into that traffic. Refer to the privacy policies of:
Your rights
You can request deletion of your license record at any time by emailing leepun@gmail.com. Note that deleting your record means your license will stop working; this is permanent. If you're within your 14-day refund window, you'll get a refund too.
Children
gptsheet is not intended for use by anyone under 13.
Changes
If we materially change what we collect, we'll update this page and bump the "Last updated" date.
Contact
Questions: leepun@gmail.com.