1. Overview and Scope
This Privacy Policy applies to the SheetsDuty Google Workspace Add-on, global monitoring network services, licensing verification APIs, and associated web properties (collectively, the "Service"). This document explains what information we collect, how it is processed, and how your privacy rights are protected when using our Service.
2. Information We Collect
2.1 Account & Licensing Telemetry
When you install and activate SheetsDuty, we collect limited account metadata to manage subscription licensing, team collaborator seats, and quota limits:
- Email Address: Used as your unique account identifier to verify subscription tiers (Free vs. Pro).
- Google Spreadsheet ID Hash: Used to enforce attachment limits per account and verify team collaborator seat access.
- Subscription Status: Information regarding active subscription status, payment reference IDs, period end dates, and cancellation state.
2.2 Google Workspace Permissions & Scopes
SheetsDuty requests access to specific Google Workspace API scopes strictly necessary to deliver functionality:
https://www.googleapis.com/auth/spreadsheets: Required to create, format, and update the_INCIDENTS,_MONITORS, and_ALERTStabs in your spreadsheet.https://www.googleapis.com/auth/script.external_request: Required to dispatch HTTP health checks to uptime monitoring endpoints, verify subscription licenses, and communicate with payment processing endpoints.https://www.googleapis.com/auth/script.send_mail: Required to dispatch consolidated outage alert emails to configured recipients.
Note: SheetsDuty never reads, alters, or transmits content from unrelated Google Sheets or Google Drive files outside of the active spreadsheet where SheetsDuty is explicitly launched.
3. Data Storage and Retention
3.1 Local Spreadsheet Ownership
All target monitor URLs, status history, response latencies, HTTP status codes, and incident triage notes are stored exclusively in your own Google Sheet tab. You retain complete ownership and control over this data at all times.
3.2 Automatic Log Rotation
To optimize Google Sheets execution performance, SheetsDuty features an automated bottom-up log rotation
engine. Resolved incident logs older than 7 days are automatically pruned from the _INCIDENTS
sheet in your spreadsheet.
3.3 Encrypted Relational Account Storage
Our backend services maintain minimal relational records in encrypted cloud storage:
- Customer account records (Email, Payment Customer ID, Tier status).
- Attached spreadsheet binding records (Spreadsheet ID, Attachment timestamp).
- Sheet collaborator seat assignments (Sheet ID, Collaborator Email).
4. Third-Party Service Integrations
SheetsDuty integrates with trusted enterprise infrastructure providers to deliver payment processing, global health checking, and multi-channel messaging:
4.1 Payment Processing
Payments for Pro subscriptions are processed directly by certified third-party payment processors. SheetsDuty never sees, stores, or transmits credit card numbers or banking credentials. When you upgrade or click "Manage Subscription", you are redirected to PCI-DSS compliant checkout and Customer Portal interfaces.
4.2 Email Notification Delivery
Outage notifications dispatched via email are routed securely through high-deliverability transactional mail infrastructure to ensure rapid delivery.
4.3 Global Health Check Pinging
Website uptime checks are executed by high-concurrency global monitoring nodes. Ping requests adhere to strict 4-second timeout guards and Server-Side Request Forgery (SSRF) hostname sanitization to prevent internal network scanning.
5. Google Limited Use Requirements Disclosure
SheetsDuty's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data for developing, training, or fine-tuning machine learning or AI models.
6. Data Security Measures
We implement robust technical and organizational security controls:
- All API traffic between Google Workspace add-on components, monitoring engines, payment systems, and email infrastructure is encrypted using TLS 1.3.
- Backend authorization endpoints enforce cryptographic header verification and timing-attack defenses.
- Inputs across Google Sheets and backend APIs are sanitized against Formula Injection (regex matching
=,+,-,@).
7. Your Privacy Rights & Access Controls
You have full control over your data and permissions:
- Revoking Access: You can revoke SheetsDuty's permissions at any time via your Google Account Security Settings.
- Data Deletion: Deleting your spreadsheet permanently removes all stored incident logs. To delete your cloud account binding, submit a request to support@sheetsduty.com.
8. Contact Information
For questions or privacy inquiries regarding this policy, please contact our support and privacy compliance team at: