Legal

Privacy Policy

Effective date: August 18, 2026

This Privacy Policy explains how SheetRender handles personal information when you use our website and document-generation service. If you use SheetRender for an organization, you are responsible for making sure you have the authority to provide the information you upload or ask us to process.

Information we collect

We collect information you provide directly, including your name, email address, password, profile details, and support requests.

We also process the spreadsheets, example documents, templates, chat instructions, generated PDFs, delivery-recipient details, and schedule settings you add to the Service. This content can include personal information about your customers, employees, or other contacts.

We collect limited service, security, and analytics information, such as account activity, usage and product events, pages visited, referral and campaign information, browser and device attributes, request-error data, and session cookies used to keep you signed in.

How we use information

We use information to operate the Service, generate and deliver documents, maintain your account, enforce usage limits, secure the Service, provide support, and improve reliability.

When you ask SheetRender to create or edit a template, we send the information needed to fulfill that request to our AI provider, Anthropic. This can include spreadsheet column names and a limited sample of spreadsheet rows so the requested template can use your fields correctly. Anthropic processes that information on our behalf to provide the requested feature. Neither SheetRender nor Anthropic uses your uploaded content or Google user data submitted through SheetRender to train or improve generalized AI or machine-learning models.

Google accounts, Google Drive™, and Google Sheets™

If you connect Google Drive™ from the SheetRender website, we receive a stable Google account identifier, your connected Google account email, and authorization to access only files and folders you select for use with SheetRender or create through SheetRender. We use that access to read a selected spreadsheet tab, refresh its stored snapshot when you request a refresh or before a scheduled run, and save generated documents to a selected Google Drive™ folder when you ask us to. We store the Google refresh token in encrypted form while the connection is active. SheetRender does not modify the contents of a source spreadsheet.

If you connect the SheetRender add-on from Google Sheets™, Google provides an identity token that we use to verify your Google account and create or link the corresponding SheetRender account. We receive the Google account's stable identifier, verified email address, and name when Google provides it. SheetRender issues an account-link credential; Google Apps Script™ stores that credential and the last SheetRender project and dataset identifiers for each pushed tab in your per-user script properties, while SheetRender stores only a hash of the credential.

After you connect the add-on, it reads the spreadsheet name and visible-tab names and dimensions through Apps Script™ to display its tab chooser. That chooser metadata is not sent to SheetRender merely by opening the sidebar. Sheet data is sent only when you choose an explicit action such as Send, Update data, Create PDFs, or Send as a new project. Create PDFs first uploads the current rows and then renders them with the project's saved design. A transmission includes the spreadsheet and selected-tab names and identifiers, column headers, and cell values from the selected tab. It does not send cell values from other tabs or modify the spreadsheet. SheetRender stores the sent data as a project snapshot for document generation. Scheduled runs reuse the latest pushed snapshot.

Disconnecting Google Drive™ revokes and removes its stored authorization credential. Disconnecting the add-on from its sidebar or revoking it in SheetRender Settings removes the server-side add-on credential; an unused add-on credential also expires after 90 days. The sidebar clears its per-user credential and remembered tab-to-project mappings when you disconnect there or when it next detects a revoked credential. The Google identifier used to link or authenticate your SheetRender account remains with that account until account deletion. Disconnecting either integration does not delete previously imported or pushed snapshots.

SheetRender uses Google user data only to provide, secure, and support the user-facing features described above. SheetRender personnel do not access Google user data unless you ask us for support and authorize that access, access is necessary to investigate a security or abuse issue, access is required by law, or the data has been aggregated for permitted internal operations. SheetRender's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Analytics and payments

We run a self-hosted instance of HitKeep to understand use of the website and product. HitKeep uses cookieless, anonymous sessions stored in your browser's session storage. It processes page paths, referrers, campaign parameters, product events, browser and device attributes, and transient IP-address information used to derive coarse location and network-provider data, apply exclusions, and filter spam. HitKeep stores the derived analytics information rather than the raw IP address.

Stripe processes checkout, subscriptions, invoices, and payment methods for paid plans, and acts as the seller of record for them. SheetRender does not receive your full payment-card number. When checkout starts, we place the visitor IP address, browser user-agent, and, when available, an anonymous HitKeep session ID in Stripe subscription metadata. This lets an invoice-paid webhook attribute the confirmed purchase and later renewals to the original visit. Those metadata remain with the relevant Stripe billing records under Stripe's retention practices.

Because Stripe is the seller of record, it collects information from you at checkout that SheetRender does not request and does not receive: a name and a billing address, which it needs to calculate the tax it charges and remits. That information is held by Stripe and is associated with the customer record in our Stripe account; the application does not copy it into its own database. Stripe may also offer to save your details as a Link account, which is an account with Stripe rather than with SheetRender.

We honor browser Do Not Track and Global Privacy Control signals for analytics. Browser tracking is disabled when either signal is active, and the choice is carried through checkout so server-side purchase events receive the same privacy treatment.

Service providers and disclosures

We use carefully selected providers to operate the Service. Depending on the features you use, this includes Anthropic for AI processing, Google for sign-in, Apps Script™, and user-authorized Google Sheets™ and Google Drive™ access, Stripe as seller of record for paid plans and for payment and subscription processing, object-storage providers for uploaded and generated files, Resend or an SMTP provider for email delivery, and Sentry for error monitoring. HitKeep is operated by SheetRender on our own infrastructure rather than as an advertising network.

We may also disclose information when required by law, to protect the Service or its users, or in connection with a corporate transaction.

We do not sell personal information or use uploaded content for advertising.

Retention and deletion

Generated documents are automatically retained according to the plan associated with the account: currently 30 days on Free, 90 days on Starter, 365 days on Pro, and no fixed document-retention period on Business. You can delete a project and its associated snapshots and generated documents from the Service, and authenticated account owners can delete their account from Settings.

Google Drive™ authorization credentials are retained only while the Google Drive™ connection is active. Add-on account-link credentials are retained until revoked or until they expire after 90 days without use. Imported and pushed spreadsheet snapshots, including superseded snapshots needed for generation-job history, remain with the project until you delete that project or your account. Snapshots that are not referenced by job history can be removed sooner when you replace project data.

Deletion removes information from active Service records. Limited copies can remain in system backups or provider systems for a short period while they are rotated or deleted under normal backup and retention procedures.

Security

We use reasonable technical and organizational measures designed to protect information, including TLS encryption in transit, authenticated and access-controlled accounts, restricted render-network access, provider-managed storage protections, encrypted Google Drive™ refresh tokens, and one-way hashes rather than raw add-on credentials in SheetRender's database. No online service can guarantee absolute security.

Your choices and rights

You can update account information in Settings, delete your account, and contact us to ask about access, correction, or deletion. You can disconnect Google Drive™ and revoke Google Sheets™ add-on connections in Settings, and you can disconnect the add-on from its sidebar. You can also manage SheetRender's access from your Google Account and enable Do Not Track or Global Privacy Control in a supported browser to opt out of analytics tracking. Depending on where you live, you may have additional privacy rights under applicable law.

Changes and contact

We may update this Policy as the Service changes. We will post the updated version here and revise the effective date.

For privacy questions, contact contact@sheetrender.com.

Google Sheets™, Google Docs™, Google Drive™, Google Workspace™, and Apps Script™ are trademarks of Google LLC.