Privacy policy

SheetLink never stores your transactions. Financial data flows from Plaid to your spreadsheet in under a second and is never cached on our servers.

Last updated: October 2026

TL;DR: plain language summary

What we do store

  • Encrypted Plaid access tokens. Deleted when you disconnect a bank or delete your account, and on the Free plan when a bank goes 7 days without a sync (see the Terms)
  • Your Google user ID and email
  • Linked sheet metadata (sheet ID, title)
  • Plaid metadata (item_id, institution_id, cursor)
  • Account display info (account name including the bank’s official name, last 4 digits, type and subtype), encrypted at rest. Never balances
  • Subscription plan (Free, Pro or Max)
  • Minimal operational logs (non-PII)
  • Product usage events (for example: sign-in, bank connected, sync completed), with counts and timings only. No financial data. Deleted after 13 months

What we never store

  • Transaction amounts, merchants, categories, or dates
  • Account balances or transaction history
  • Bank usernames or passwords (Plaid handles these)
  • Google OAuth tokens (stay in your browser)
  • Your spreadsheet contents

We do not sell or share your data. Ever. You can disconnect your bank and uninstall at any time, and you can ask us to delete your account and everything linked to it by emailing support@sheetlink.app.

How your data flows

SheetLink is a transparent data pipe, not a data vault.

  1. Plaid → SheetLink APIToken exchange only, no transaction data
  2. SheetLink API → PlaidFetch transactions using your encrypted token
  3. SheetLink API → Your browserReturns JSON (deleted from memory immediately after)
  4. Your browser / CLI → Your destinationData written directly to Google Sheets, Excel, Postgres, SQLite, JSON, or CSV, never stored on our servers

Privacy guarantee: Transaction data exists on SheetLink servers for less than a second during sync, just long enough to fetch from Plaid and return to your browser. Nothing is cached or logged.

Google OAuth & the callback page

How sign-in works

  1. Extension opens Google OAuth in a secure popup
  2. You authorize Google Sheets access via Google’s page
  3. Google redirects to sheetlink.app/oauth/callback with access token
  4. Callback page sends token to extension via local Chrome messaging
  5. Extension stores token locally for subsequent syncs

OAuth guarantee: The callback page at sheetlink.app/oauth/callback never sends your token to any server. It runs entirely client-side, extracts the token from the URL, and passes it directly to the extension via Chrome’s local messaging API. No analytics, no logging, no server processing.

Google user data

SheetLink’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes requested

  • auth/spreadsheets: write transaction data to sheets you select
  • auth/drive.file: Google’s per-file Drive access, limited to files you choose with SheetLink; it can’t see the rest of your Drive
  • auth/script.projects: create Apps Script projects for recipe installation
  • auth/userinfo.email: your email for authentication and account management

How we use it

We use Google user data only to sign you in, write transactions into the sheet you pick, and install the recipes you choose. We never use it for advertising, never sell it, and never use it for credit or lending decisions. SheetLink doesn’t use Google Workspace APIs or the data it gets from them to develop, improve or train generalized or non-personalized AI or machine learning models.

Data sharing

We do not sell data, share with advertisers, or send Google user data to any external analytics services. Disclosure is only made if required by law.

Data storage

  • Google Sheets data: not stored on our servers; written directly to your sheet
  • Apps Script projects: container-bound to your spreadsheet; we don’t store script content
  • OAuth tokens: managed by Chrome extension storage; never transmitted to our backend
  • User info: Google user ID and email stored in our database for authentication only

How it’s protected

The Google access token that writes to your sheet stays in your browser and never reaches our servers. At sign-in, our API checks Google’s ID token once to confirm who you are. Your Google user ID and email travel over HTTPS and are kept to sign you in and manage your account.

Retention and deletion

We keep your Google user ID and email while you have an account. Email support@sheetlink.app to delete your account, and we delete them along with everything linked to it. You can revoke SheetLink’s Google access at any time at myaccount.google.com/permissions.

  • Revoke Google access at myaccount.google.com/permissions
  • Delete your sheet data by removing the spreadsheet tab in Google Sheets
  • Uninstall the extension to clear all local storage

JWT authentication & sessions

What tokens contain

  • Your user ID (UUID)
  • Your email address
  • Expiration timestamp (4 hours)
  • Cryptographic signature

What tokens don’t contain

  • Google OAuth token
  • Bank data or transactions
  • Google Sheets information
  • Any financial data

Session expiry: JWT tokens expire after 4 hours. Re-authentication is usually one click (Google remembers recent sign-ins). Tokens are stored in the extension’s local storage and never transmitted to third parties.

Client application disclosures

Chrome Extension

The extension does not collect browsing activity or track which websites you visit. It does not inject scripts into web pages. Transactions come through our API and are written to your sheet from your browser. JWT tokens are stored in chrome.storage.local and never transmitted to third parties. The Google access token that writes to your sheet stays in your browser; at sign-in, the extension sends Google’s ID token to our API once, to confirm who you are.

To measure and improve the product, the extension sends product usage events to our API: which screens are opened, and whether sign-in, bank connection, sheet linking and syncs succeed, with counts and timings. Events never include transaction data, amounts, balances, bank or account names, your email, or anything about your spreadsheet. They are linked to your SheetLink account and deleted after 13 months.

Excel Add-in Pro and Max

The add-in is a Microsoft Office task pane application hosted at sheetlink.app/excel/. It uses the same backend API and Plaid integration as the Chrome extension.

  • Auth: Google OAuth via Office.context.ui.displayDialogAsync, a Microsoft-managed dialog
  • Token storage: JWT stored in the task pane’s localStorage, scoped to the add-in, until you sign out or it expires
  • Data destination: Transactions written directly to your workbook via Office.js; no data sent to Microsoft servers by SheetLink

CLI & API keys Max

Max subscribers can create API keys, which let the sheetlink CLI and the SheetLink MCP server run without a browser sign-in, for example on a schedule.

  • Auth: API key sent as a bearer token over HTTPS, never stored in plaintext
  • Data destinations: Postgres, SQLite, JSON, CSV: data is written directly to your chosen destination and never cached on our servers
  • Logs: The CLI produces local logs only; no request bodies or transaction data are logged server-side
  • Claude: If you use SheetLink with Claude, Claude Desktop runs the SheetLink MCP server on your computer, fetches your data from SheetLink with your API key, and sends it to Anthropic as part of your conversation. SheetLink itself doesn’t send data to Anthropic. Subject to Anthropic’s privacy policy.

Encryption & transparency

Fernet encryption

Plaid access tokens are encrypted at rest using Fernet (AES-128-CBC + HMAC). The encryption key lives in environment variables. Even database access wouldn’t expose your tokens without it. Tokens are only decrypted during sync operations. The same encryption protects the account display info we cache (account names, the bank’s official account name, masked last 4 digits, and account type); balances and transactions are never stored.

Open source client

SheetLink’s browser extension is open source on GitHub. The published release builds are the exact packages we ship to the Chrome Web Store, so you can inspect exactly how your data flows before installing. Our CLI and MCP server are open source too. The backend API is private for security reasons.

Privacy middleware

Our backend includes middleware that automatically suppresses detailed logging for all Plaid-related endpoints. Only high-level request metadata is logged (e.g. “POST /plaid/sync”), never request bodies or transaction data.

Your rights

  • Disconnect anytime: removes encrypted token from our DB immediately
  • Delete your sheet: we have no copy
  • Uninstall: clears all local storage
  • Audit the code: extension is open source

Third-party services

Plaid

Securely connects to your bank and retrieves transaction data. Your banking credentials are handled exclusively by Plaid, never by SheetLink.

Plaid Privacy Policy ›

Google

We write data to your Google Sheet via the Sheets API. You control who can access your sheet.

Google Privacy Policy ›

Microsoft

The Excel Add-in uses the Office.js API to write transactions. SheetLink does not transmit workbook data to Microsoft.

Microsoft Privacy Statement ›

Anthropic (Max)

Max subscribers can query their transaction data in Claude Desktop through the SheetLink MCP server. Claude Desktop sends the data it fetches to Anthropic as part of your conversation; SheetLink itself doesn’t send data to Anthropic.

Anthropic Privacy Policy ›


Questions about privacy?

Email us at privacy@sheetlink.app

Security architecture ›Terms of Service ›

This policy may be updated from time to time. Material changes will be communicated via email or through the extension. Continued use after updates constitutes acceptance.