Privacy Policy
Last updated: September 6, 2026
Overview
SmoothSheet ("we", "our", or "us") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our service.
Information We Collect
Google Account Information
When you sign in with Google, we receive only:
- Your email address
- Your name and profile picture
Signing in does not give SmoothSheet access to any of your files.
Google Drive Access
Google Drive access is requested separately, the first time you choose a spreadsheet. Google shows a second consent screen at that moment, and you can decline it and still keep your SmoothSheet account.
- We ask for Google's drive.file permission. It is limited to the spreadsheets you pick in Google's file chooser and to files SmoothSheet creates. We cannot see, list, or search the rest of your Drive.
- For those spreadsheets we store an encrypted OAuth token so our servers can write rows while your upload runs. We do not store the spreadsheet itself.
- You choose the destination spreadsheet for every upload. Nothing is written to a file you have not picked.
To remove SmoothSheet's access at any time, open your Google Account, go to Security, then Third-party access, select SmoothSheet, and remove the connection (myaccount.google.com/permissions). Uploads already written to your spreadsheets stay where they are; SmoothSheet simply can no longer write to them.
Usage Data
We collect basic usage information including:
- Upload timestamps and job status
- Row counts and file types processed
- Error logs for troubleshooting
Your File Data
We do not store your file content. When you upload a file:
- The file is processed in memory on our servers
- Data is sent directly to your Google Sheet via Google's API
- The file is immediately deleted after processing
- We never view, analyze, or retain your actual data content
How We Use Your Information
- To authenticate you and provide the service
- To process your file uploads to Google Sheets
- To track your usage against tier limits
- To troubleshoot errors and improve the service
- To process payments (via Stripe)
Third-Party Services
We use the following third-party services:
- Google: Sign-in and, once you connect Google Drive, the Google Sheets and Drive APIs for the spreadsheets you pick. We receive your email, name, profile picture, and OAuth tokens.
- Stripe: Payment processing for Pro subscriptions. We share your email address with Stripe to create your customer account. Stripe collects payment details directly; we never see or store your card information.
Each service has its own privacy policy governing how they handle data.
SmoothSheet's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data Sharing and Restrictions
We do not sell your data. We only share your information with third parties when necessary to provide the Service:
- Stripe: Your email address is shared solely to process payments
- Google: Your uploaded data is sent directly to your Google Sheets
We do not use Google user data for:
- Targeted or personalized advertising
- Retargeting or interest-based advertising
- Selling to data brokers or information resellers
- Determining creditworthiness or for lending purposes
- Training artificial intelligence or machine learning models
- Any purpose other than providing or improving SmoothSheet
Data Security
- All OAuth tokens are encrypted at rest using AES-256-GCM
- All data transmission uses HTTPS/TLS encryption
- We follow security best practices for authentication and data handling
Data Retention and Deletion
We retain your data only as long as necessary to provide the Service:
- OAuth tokens: Stored encrypted while your account is active. They stop working the moment you remove SmoothSheet's access in your Google Account, and are deleted when you delete your account.
- Job history: Upload job records are retained for 90 days for troubleshooting purposes, then automatically deleted.
- Account data: When you request account deletion, all your data (profile, tokens, job history) is permanently deleted within 30 days.
- Uploaded files: Never stored. Files are processed in memory and immediately discarded after the upload completes.
To request deletion of your data, contact us at [email protected] or disconnect SmoothSheet from your Google account settings.
Your Rights
You can:
- Remove SmoothSheet's access to Google Drive at any time from your Google Account (Security, then Third-party access)
- Request deletion of your account and associated data
- Export your job history data
Cookies
We use essential cookies only for authentication and session management. We do not use tracking cookies or third-party advertising cookies.
Changes to This Policy
We may update this policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date.
Contact
If you have questions about this privacy policy, please contact us at [email protected]