TL;DR: plain language summary
What we do store
- Encrypted Plaid access tokens. Deleted when you disconnect a bank or delete your account, and on the Free plan when a bank goes 7 days without a sync (see the Terms)
- Your Google user ID and email
- Linked sheet metadata (sheet ID, title)
- Plaid metadata (item_id, institution_id, cursor)
- Account display info (account name including the bank’s official name, last 4 digits, type and subtype), encrypted at rest. Never balances
- Subscription plan (Free, Pro or Max)
- Minimal operational logs (non-PII)
- Product usage events (for example: sign-in, bank connected, sync completed), with counts and timings only. No financial data. Deleted after 13 months
What we never store
- Transaction amounts, merchants, categories, or dates
- Account balances or transaction history
- Bank usernames or passwords (Plaid handles these)
- Google OAuth tokens (stay in your browser)
- Your spreadsheet contents
We do not sell or share your data. Ever. You can disconnect your bank and uninstall at any time, and you can ask us to delete your account and everything linked to it by emailing support@sheetlink.app.
How your data flows
SheetLink is a transparent data pipe, not a data vault.
- Plaid → SheetLink APIToken exchange only, no transaction data
- SheetLink API → PlaidFetch transactions using your encrypted token
- SheetLink API → Your browserReturns JSON (deleted from memory immediately after)
- Your browser / CLI → Your destinationData written directly to Google Sheets, Excel, Postgres, SQLite, JSON, or CSV, never stored on our servers
Privacy guarantee: Transaction data exists on SheetLink servers for less than a second during sync, just long enough to fetch from Plaid and return to your browser. Nothing is cached or logged.
Google OAuth & the callback page
How sign-in works
- Extension opens Google OAuth in a secure popup
- You authorize Google Sheets access via Google’s page
- Google redirects to
sheetlink.app/oauth/callbackwith access token - Callback page sends token to extension via local Chrome messaging
- Extension stores token locally for subsequent syncs
OAuth guarantee: The callback page at sheetlink.app/oauth/callback never sends your token to any server. It runs entirely client-side, extracts the token from the URL, and passes it directly to the extension via Chrome’s local messaging API. No analytics, no logging, no server processing.
Google user data
SheetLink’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes requested
auth/spreadsheets: write transaction data to sheets you selectauth/drive.file: Google’s per-file Drive access, limited to files you choose with SheetLink; it can’t see the rest of your Driveauth/script.projects: create Apps Script projects for recipe installationauth/userinfo.email: your email for authentication and account management
How we use it
We use Google user data only to sign you in, write transactions into the sheet you pick, and install the recipes you choose. We never use it for advertising, never sell it, and never use it for credit or lending decisions. SheetLink doesn’t use Google Workspace APIs or the data it gets from them to develop, improve or train generalized or non-personalized AI or machine learning models.
Data sharing
We do not sell data, share with advertisers, or send Google user data to any external analytics services. Disclosure is only made if required by law.
Data storage
- Google Sheets data: not stored on our servers; written directly to your sheet
- Apps Script projects: container-bound to your spreadsheet; we don’t store script content
- OAuth tokens: managed by Chrome extension storage; never transmitted to our backend
- User info: Google user ID and email stored in our database for authentication only
How it’s protected
The Google access token that writes to your sheet stays in your browser and never reaches our servers. At sign-in, our API checks Google’s ID token once to confirm who you are. Your Google user ID and email travel over HTTPS and are kept to sign you in and manage your account.
Retention and deletion
We keep your Google user ID and email while you have an account. Email support@sheetlink.app to delete your account, and we delete them along with everything linked to it. You can revoke SheetLink’s Google access at any time at myaccount.google.com/permissions.
- Revoke Google access at myaccount.google.com/permissions
- Delete your sheet data by removing the spreadsheet tab in Google Sheets
- Uninstall the extension to clear all local storage
JWT authentication & sessions
What tokens contain
- Your user ID (UUID)
- Your email address
- Expiration timestamp (4 hours)
- Cryptographic signature
What tokens don’t contain
- Google OAuth token
- Bank data or transactions
- Google Sheets information
- Any financial data
Session expiry: JWT tokens expire after 4 hours. Re-authentication is usually one click (Google remembers recent sign-ins). Tokens are stored in the extension’s local storage and never transmitted to third parties.
Client application disclosures
Chrome Extension
The extension does not collect browsing activity or track which websites you visit. It does not inject scripts into web pages. Transactions come through our API and are written to your sheet from your browser. JWT tokens are stored in chrome.storage.local and never transmitted to third parties. The Google access token that writes to your sheet stays in your browser; at sign-in, the extension sends Google’s ID token to our API once, to confirm who you are.
To measure and improve the product, the extension sends product usage events to our API: which screens are opened, and whether sign-in, bank connection, sheet linking and syncs succeed, with counts and timings. Events never include transaction data, amounts, balances, bank or account names, your email, or anything about your spreadsheet. They are linked to your SheetLink account and deleted after 13 months.
Excel Add-in Pro and Max
The add-in is a Microsoft Office task pane application hosted at sheetlink.app/excel/. It uses the same backend API and Plaid integration as the Chrome extension.
- Auth: Google OAuth via
Office.context.ui.displayDialogAsync, a Microsoft-managed dialog - Token storage: JWT stored in the task pane’s
localStorage, scoped to the add-in, until you sign out or it expires - Data destination: Transactions written directly to your workbook via Office.js; no data sent to Microsoft servers by SheetLink
CLI & API keys Max
Max subscribers can create API keys, which let the sheetlink CLI and the SheetLink MCP server run without a browser sign-in, for example on a schedule.
- Auth: API key sent as a bearer token over HTTPS, never stored in plaintext
- Data destinations: Postgres, SQLite, JSON, CSV: data is written directly to your chosen destination and never cached on our servers
- Logs: The CLI produces local logs only; no request bodies or transaction data are logged server-side
- Claude: If you use SheetLink with Claude, Claude Desktop runs the SheetLink MCP server on your computer, fetches your data from SheetLink with your API key, and sends it to Anthropic as part of your conversation. SheetLink itself doesn’t send data to Anthropic. Subject to Anthropic’s privacy policy.
Encryption & transparency
Fernet encryption
Plaid access tokens are encrypted at rest using Fernet (AES-128-CBC + HMAC). The encryption key lives in environment variables. Even database access wouldn’t expose your tokens without it. Tokens are only decrypted during sync operations. The same encryption protects the account display info we cache (account names, the bank’s official account name, masked last 4 digits, and account type); balances and transactions are never stored.
Open source client
SheetLink’s browser extension is open source on GitHub. The published release builds are the exact packages we ship to the Chrome Web Store, so you can inspect exactly how your data flows before installing. Our CLI and MCP server are open source too. The backend API is private for security reasons.
Privacy middleware
Our backend includes middleware that automatically suppresses detailed logging for all Plaid-related endpoints. Only high-level request metadata is logged (e.g. “POST /plaid/sync”), never request bodies or transaction data.
Your rights
- Disconnect anytime: removes encrypted token from our DB immediately
- Delete your sheet: we have no copy
- Uninstall: clears all local storage
- Audit the code: extension is open source
Third-party services
Plaid
Securely connects to your bank and retrieves transaction data. Your banking credentials are handled exclusively by Plaid, never by SheetLink.
We write data to your Google Sheet via the Sheets API. You control who can access your sheet.
Microsoft
The Excel Add-in uses the Office.js API to write transactions. SheetLink does not transmit workbook data to Microsoft.
Anthropic (Max)
Max subscribers can query their transaction data in Claude Desktop through the SheetLink MCP server. Claude Desktop sends the data it fetches to Anthropic as part of your conversation; SheetLink itself doesn’t send data to Anthropic.
Questions about privacy?
Email us at privacy@sheetlink.app
Security architecture ›Terms of Service ›
This policy may be updated from time to time. Material changes will be communicated via email or through the extension. Continued use after updates constitutes acceptance.