Privacy Policy
Effective October 11, 2026. Operator: Jonathan Day, Arizona, USA. Contact: support@statsheets.app.
The short version
- Your spreadsheet data never leaves Google. Every calculation runs inside Google Apps Script, in your own spreadsheet.
- StatSheets can only open the spreadsheet you are using it in. It cannot see your other files.
- We do not sell, share, or advertise with any data.
- If you use Pro, we check your license using a keyed hash of your email address, not the address itself.
What StatSheets accesses
When you run a tool, StatSheets reads the cells you selected and writes a results table into the same spreadsheet. This happens inside Google's servers under your Google account. StatSheets does not copy, transmit, log, or store your spreadsheet contents anywhere else.
The add-on requests these Google permissions:
- View and manage spreadsheets that this application has been installed in (
spreadsheets.currentonly): to read your selected data and write results. - Display and run third-party web content in prompts and sidebars (
script.container.ui): to show the StatSheets sidebar. - See your primary Google Account email address (
userinfo.email): Pro license check only, as described below. - Connect to an external service (
script.external_request): Pro license check only, as described below.
Pro license checks
To tell whether you have a Pro or classroom license, the add-on computes a keyed hash of your email address inside Apps Script (HMAC-SHA256 with a secret key that only StatSheets holds) and sends that hash, plus a class code if you entered one, to our license server. This happens a few times a day at most: answers are remembered for six hours, and again when you click Refresh or enter a class code. Without our secret key, the hash cannot be matched to your email address, even by someone who has a list of addresses. No spreadsheet content is ever included.
When you buy Pro, payment is handled by Stripe. Stripe receives the details you enter at checkout, under Stripe's privacy policy. From Stripe we store: the keyed hash of the purchasing email, the plan, its expiry date, and Stripe's customer and payment identifiers (so a refund or dispute can end the right license). We never see or store your card number.
Information we keep
- License records: keyed email hash, plan, expiry, Stripe customer and payment identifiers, and class membership (the keyed hash of each student who entered a class code). Kept while the license is active, then deleted automatically 12 months after it ends.
- Support email you send us: kept as long as needed to answer it, then deleted within 12 months.
- Server logs on the license server: request time and response status, kept 30 days.
We do not use cookies or analytics trackers in the add-on.
Google API Services User Data Policy
StatSheets's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train AI or machine-learning models, and do not allow humans to read it except with your explicit consent for support, for security purposes, or to comply with law.
Children
StatSheets is a general-purpose tool intended for users 13 and older. We do not knowingly collect personal information from children under 13. The free tools send nothing to us at all. Pro license checks send only the keyed email hash described above; schools that want to use Pro with students under 13 should contact us first.
Your choices
- Uninstall the add-on at any time from Extensions > Add-ons > Manage add-ons, and revoke its access at myaccount.google.com/permissions.
- Email support@statsheets.app to ask what we hold about you or to have it deleted. We answer within 30 days.
Changes
If this policy changes, we will update the effective date above and, for material changes, note it in the add-on's sidebar.