Legal
Privacy Policy
Effective date: July 28, 2026
Overview
SaveToSheets (“SaveToSheets,” “we,” “us,” or “our”) turns emails you forward to a personal SaveToSheets address into rows in the Google Sheet you connect. This policy explains what information we handle, why we handle it, and the choices available to you.
If you have a privacy question or want to make a request, email [email protected].
Information we collect
- Account information: your name, email address, Google account identifier, and the OAuth tokens needed to keep your Google Sheets connection working while you are away.
- Connected-sheet information: the spreadsheet identifier, its name, the selected destination, and the current header row used to map emails into columns.
- Forwarded-email information: sender address, subject, body text, extracted fields, processing status, and processing errors. We also record attachment count and file type when provided. We do not parse attachment contents in the current service.
- Billing information: subscription, plan, invoice, and Stripe customer identifiers. Payment-card details are handled by Stripe, not stored by SaveToSheets.
- Usage information: limited, aggregated website analytics from Plausible, such as pages visited and referral information.
- Communications: information you include when you contact support.
How we use information
We use information to provide the service: authenticate you, create and maintain your forwarding addresses, verify approved senders, read a connected sheet’s header row, extract data from forwarded email bodies, append a row to the selected sheet, administer subscriptions, prevent abuse, troubleshoot, and respond to support requests.
We do not sell personal information or use it for targeted advertising. We do not use forwarded email content or Google user data to build advertising audiences or train general-purpose AI models.
How information is shared
We share information only as needed to run the service, including with these service providers:
- Google: for sign-in and the Google Sheets API. The service reads the header row and appends rows to the sheets you connect.
- Postmark: to receive forwarded email webhook deliveries.
- OpenRouter: to process the forwarded email subject and body against your sheet’s columns and return structured fields.
- Stripe: to process subscriptions and payments.
- Plausible: to provide privacy-focused website analytics.
We may also disclose information when required by law, to protect the service or its users, or as part of a corporate transaction, subject to applicable law.
Google user data
We request the Google Sheets scope so the service can read headers and append rows to sheets you connect, and basic profile information to create your account. OAuth tokens are encrypted at rest in our application database. We use Google user data only to provide and improve SaveToSheets’ visible, user-facing functionality.
The use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention
We retain forwarded-email records, including their stored body text and extracted fields, for up to 90 days after receipt for processing, support, troubleshooting, and optional backfill requests. A scheduled cleanup deletes those records after that period. We may retain account, billing, security, and legally required records for as long as necessary for the purposes described above or as required by law.
Your Google Sheet is your own Google content. Rows written to it remain in the sheet until you delete them or otherwise change access through Google.
Your choices and requests
You can change a sheet’s columns directly in Google Sheets, remove approved senders from the dashboard, disconnect by revoking SaveToSheets access in your Google Account, and cancel a paid subscription through the billing portal. To request access, correction, deletion, or export of personal information we hold, contact us at [email protected]. We may need to verify your request and may retain limited information where legally permitted or required.
Security
We use reasonable technical and organizational measures designed to protect information, including encryption for stored Google OAuth tokens. No system or transmission is completely secure, and we cannot guarantee absolute security.
International processing and changes
Our service providers may process information in countries other than yours. We will update this policy when our practices change and will post the revised effective date on this page. Material changes to how we use Google user data will be communicated and, where required, subject to renewed consent.