Privacy policy
This policy explains how JSON for Sheets handles information through its website, Google Sheets add-on, account system, and remote import service.
Plain-language summary
JSON you paste, open from a local .json file, or read from cells for local tools is processed inside the Google add-on session and is not intentionally sent to JSON for Sheets servers. When you ask JSON for Sheets to fetch a remote URL, the request and response must pass through the product service so it can perform the import, apply security checks, enforce limits, and return the result.
JSON for Sheets does not use or integrate with third-party or self-hosted artificial-intelligence or machine-learning models, model gateways, or model hubs. We do not transfer Google Workspace data to an AI/ML provider or use spreadsheet content, JSON payloads, API responses, or saved credentials to create, train, or improve AI/ML models.
The public JSON for Sheets website does not set advertising or analytics cookies, run analytics scripts, or send browser requests to third-party trackers.
Information we collect
- Google account identifiers and email address used to create and secure your JSON for Sheets account.
- Subscription status, plan, usage totals, transaction identifiers, and support correspondence.
- Technical metadata such as timestamps, response status, response size, duration, product version, and sanitized error details.
- Remote URL, request configuration, selected path and fields, and import options you submit for a remote import.
- Remote request and response data when needed to perform an import that you initiate.
We do not intentionally collect sensitive personal information. Do not use the service with data you are not authorized to access or process.
How JSON for Sheets uses Google user data
JSON for Sheets receives and uses Google user data only to provide the features the user requests inside Google Sheets. Specifically:
- Google account identity and email: used to sign the user in, associate the add-on with the correct product account, enforce plan and usage limits, display account status, prevent abuse, and respond to support requests.
- Data in the currently open spreadsheet: used to read user-selected cells, JSON text, import settings, paths, and request variables; preview and transform JSON; write the resulting table to the destination the user selects; update a previously written table; and export a user-selected range as JSON.
- Spreadsheet and sheet identifiers: used to identify the active destination and, only after explicit Google Picker authorization, reopen that same spreadsheet for a refresh schedule the user enables.
- Apps Script trigger and execution information: used to create, run, display, diagnose, and delete refresh schedules that the user controls.
- Spreadsheet values placed into a remote request: sent only when the user configures an API request that references those cells or runs a saved import containing those variables. The values are used to execute that request and return its result; they are not used for unrelated purposes.
Google user data is not used for advertising, user profiling, data brokerage, unrelated product development, or any purpose other than providing, securing, maintaining, and supporting the user-facing JSON for Sheets functionality described in this policy.
Google user data and OAuth scopes
JSON for Sheets requests the Google permissions needed for identity, spreadsheet editing, its user interface, product-service requests, and refresh schedules:
openidIdentifies the signed-in Google user so the add-on can connect to the correct JSON for Sheets account.
https://www.googleapis.com/auth/userinfo.emailIncludes the signed-in email address in the identity token for account matching and support.
https://www.googleapis.com/auth/spreadsheets.currentonlyReads and writes only the spreadsheet currently open while the user works with the add-on.
https://www.googleapis.com/auth/drive.fileGrants access to the currently open spreadsheet only after the user explicitly selects it in Google Picker when enabling scheduled refresh. JSON for Sheets does not receive or retain the Picker's file list.
https://www.googleapis.com/auth/script.container.uiAdds the JSON for Sheets menu, dialogs, and sidebar to the open spreadsheet.
https://www.googleapis.com/auth/script.external_requestConnects the add-on to JSON for Sheets services for account state and remote API imports.
https://www.googleapis.com/auth/script.scriptappCreates and manages the time-driven Apps Script trigger needed for refresh schedules the user enables.
JSON for Sheets does not search or enumerate Drive files, access non-Sheets Drive content, or request access to Gmail, contacts, or calendars. Interactive features operate only on the spreadsheet currently open. When a user enables a schedule, Google Picker displays a Google-hosted list of spreadsheets so the user can choose the file currently open. JSON for Sheets receives only the selected file identifier, rejects a selection that is not the current spreadsheet, and can later reopen only that explicitly authorized file. It does not receive or retain the other files shown by Google Picker. Google API information is used only to provide and improve user-facing product functionality, secure the service, provide support, and comply with law.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
No artificial-intelligence or machine-learning integrations
JSON for Sheets has no artificial-intelligence or machine-learning features or integrations. It does not call or integrate with third-party AI/ML providers, multi-model services, model gateways, model hubs, downstream models, or self-hosted or offline AI/ML models. Accordingly, there are no AI/ML providers, plans, tiers, platforms, or models to list.
JSON for Sheets never transfers raw, aggregated, anonymized, or derived Google Workspace API data to an AI/ML service. Google user data, spreadsheet content, JSON payloads, API responses, saved credentials, and usage metadata are not used to create, train, fine-tune, evaluate, or improve foundational, generalized, personalized, or other AI/ML models.
Who we share, transfer, or disclose Google user data to
JSON for Sheets processes information to authenticate users, execute requested imports, transform JSON into spreadsheet output, enforce quotas, process payments, prevent abuse, diagnose errors, and respond to support requests.
We disclose Google user data only to the following recipients and only for the stated purposes needed to operate JSON for Sheets:
- Google: Google processes your account identity, spreadsheets, Apps Script execution, add-on interface, and time-driven refresh triggers. Spreadsheet content remains within Google for local paste, file, cell, transformation, and export features unless you explicitly include it in a remote request or saved import.
- Supabase: Supabase processes and stores your Google account identifier and email, authentication and account records, plan and usage totals, subscription status, installation records, saved-import configuration, schedule metadata, spreadsheet and sheet identifiers needed to reopen an enabled schedule, and encrypted saved credentials. Supabase does not store remote API response bodies in a response cache.
- DigitalOcean: DigitalOcean hosts the remote-import service. For a remote import it processes your authenticated product request, destination URL, method, parameters, permitted headers, optional body, saved credential in memory when used, spreadsheet-derived variables you explicitly include, the upstream response, and the transformed table returned to Apps Script. The launch service processes responses in memory and does not intentionally retain remote response bodies after the request completes.
- The remote API or website you choose: The destination receives the HTTP request you configure, including any spreadsheet-derived variables, headers, body fields, or saved connection credential that you direct JSON for Sheets to send. This disclosure is made at your instruction; the destination's own privacy policy and terms govern its processing. Cross-origin redirects do not receive the original credentials, caller headers, or request body.
- Stripe: Stripe receives your billing email, an internal account identifier, selected plan, subscription metadata, and payment information needed for checkout, invoicing, and billing management. Stripe does not receive spreadsheet content, imported JSON, remote API responses, or saved connection credentials from us.
- Vercel: Vercel hosts the website and may process account-page requests, essential session cookies, IP addresses, and ordinary hosting and security logs. The website does not send Vercel spreadsheet content, imported JSON, remote API responses, or saved connection credentials.
These providers act only as infrastructure, payment, or data-processing providers for the purposes described above and operate under their applicable terms and privacy commitments. We do not sell Google user data, transfer it to advertising platforms or data brokers, use it for personalized advertising, or use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
We may disclose information when required by law, valid legal process, or a good-faith need to protect users, JSON for Sheets, or the public from fraud, abuse, or security threats. If JSON for Sheets is involved in a merger, acquisition, financing, reorganization, or sale of assets, Google user data may be transferred to the successor only where legally permitted, subject to this policy and any required notice or consent. We do not otherwise share or transfer Google user data to unrelated third parties.
Retention and deletion
Account data remains until you close the account or it is no longer required to provide the service. Remote responses are processed in memory for the requested import and are not retained in a response cache or durably stored by the launch service. Operational and security records are retained only as long as reasonably needed for security, reliability, support, and legal obligations. Billing records may be retained longer when required for tax, accounting, dispute, or legal obligations. Deleted information may remain temporarily in provider backups until those backups rotate under the provider's retention schedule.
To request deletion, email jacob@codeprint.io. We may retain limited records when legally required or necessary to document a completed billing transaction or security incident.
Security
We use access controls, encryption in transit, secret-management systems, logging redaction, and product-scoped authorization. Saved third-party credentials are encrypted in Supabase Vault and are resolved only between product services for a request; raw credentials are not returned to Apps Script or written to saved request metadata. Saved credentials remain bound to the original request origin: cross-origin redirects lose credentials and request data, and response-driven pagination cannot switch origins. No internet service can guarantee absolute security, so users should revoke affected access and contact us promptly if they suspect unauthorized access.
Your choices and rights
You may remove the add-on, revoke Google access, disconnect the add-on, cancel a subscription, or request access, correction, export, or deletion of account information. Depending on where you live, additional privacy rights may apply. We will verify requests before acting on them.
Contact and policy changes
JSON for Sheets is operated by its parent company, Codeprint. Privacy questions and requests should be sent to jacob@codeprint.io.
Material changes will be posted here with a new effective date. When appropriate, we will also provide notice through the product or account email.