PasteSheet icon PasteSheet logo mark — a spreadsheet grid with a curly brace on a green rounded square PasteSheet

Privacy Policy

Effective date: August 13, 2026

PasteSheet ("PasteSheet", "we", "us", or "our") operates a service that turns a Google Sheet into a cached REST API and an MCP server endpoint for AI agents (the "Service"). This Privacy Policy explains what information we collect when you use the Service, how we use and share it, and the choices you have.

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

1. Information We Collect

Account information

When you register with an email address and password, we collect your name, email address, and a securely hashed (bcrypt) password. When you sign in with "Continue with Google," we instead receive your name, email address, a link to your Google profile photo, and a unique Google account identifier from Google — we never receive or store your Google password. This sign-in step alone does not grant us any access to your Google Drive or Sheets; reading a private sheet requires a separate, explicit connection described under "Connecting a private Google Sheet" below.

Sheet and endpoint information

When you connect a Google Sheet, we store the sheet's identifier and URL, the endpoint title you give it, the list of tabs, any column aliases or type configuration you set, your chosen cache duration, and whether the endpoint is public or private. You can connect a sheet in one of two ways: by pasting the link to a sheet you have shared publicly ("anyone with the link can view"), which we read through Google's keyless public export; or by connecting a private sheet through your Google account, described next.

The actual row data from your connected sheet is fetched from Google and cached temporarily to serve your API and MCP endpoints quickly; it is not stored in our primary database as a permanent record.

Connecting a private Google Sheet

If you choose to connect a private sheet, we ask Google for permission using the "drive.file" scope and Google's own file picker. This scope is deliberately narrow and file-scoped: it limits the connection to the specific file (or files) you select in the picker — never to your whole Google Drive, and never to any other file you have not explicitly chosen. Although Google describes this scope as permitting actions on selected files, PasteSheet uses the connection only to read the selected sheet's cells and tab structure so we can serve them through your endpoint; the app never modifies, creates, or deletes your Drive files.

To keep reading a connected private sheet on your behalf after you leave the page, we store the OAuth refresh and access tokens Google issues for that connection. These tokens are stored encrypted at rest and are used solely to fetch the sheets you connected. You can revoke this access at any time — see "Data Retention & Deletion" below.

Usage and technical information

We record the number of requests made to each of your endpoints per day in order to enforce plan limits and to power your in-app Usage dashboard. We also store your session's IP address and browser user-agent string, which is standard practice for keeping your login session secure. If you create API keys for private endpoints, we store a one-way cryptographic hash of the key (never the plaintext key itself, which is shown to you only once) along with when it was last used.

Billing information

If you subscribe to a paid plan, your subscription and billing is handled by our payment processor, Polar.sh. We share your email address (and, where applicable, your name) with Polar to create a customer record and process checkout. We do not collect or store your payment card details — Polar handles that as the merchant of record. We store limited billing metadata on our side, such as your subscription status and plan.

2. How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the Service, including your API and MCP endpoints.
  • Authenticate you and keep your account secure.
  • Enforce the request, row, and feature limits associated with your plan.
  • Send you transactional email (email verification, password resets) and a short onboarding email series when you first sign up.
  • Process payments and manage subscriptions through Polar.sh.
  • Diagnose problems, prevent abuse, and improve the Service.

3. Third-Party Services We Share Data With

We work with a small number of third-party service providers to operate PasteSheet. We do not sell your personal information to anyone.

Google

Used for "Continue with Google" sign-in (via your name, email, and profile photo), to fetch the public content of Google Sheets you connect through Google's public export endpoint, and — when you connect a private sheet — to read the specific files you select via the "drive.file" scope. We never request full Google Drive access; the "drive.file" scope limits us to the individual files you pick.

PasteSheet's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use data obtained through Google Sheets or Drive scopes for advertising, we do not sell it, and we do not share it with third parties except as needed to provide and secure the feature you requested (for example, our hosting infrastructure), or as required by law.

Anthropic (Claude AI)

When you connect a new sheet, PasteSheet automatically detects column types and suggested aliases using Anthropic's Claude AI models. To do this, we send a sample of your sheet — the header row and up to 10 rows of data — to Anthropic's API. This means any content in the sample rows of a sheet you connect is disclosed to Anthropic for the sole purpose of this classification task. Do not connect a sheet containing sensitive data you are not comfortable sharing with our AI provider for this purpose.

Polar.sh

Our billing and subscription processor. Polar receives your email address (and, where applicable, your name) to manage checkout, subscriptions, and receipts, and acts as merchant of record for all payments.

4. Data Retention & Deletion

We retain your account and endpoint data for as long as your account is active. You can permanently delete your account at any time from Settings → Security, which removes your account and associated endpoints, API keys, and usage records. Some records, such as billing history required for accounting or legal purposes, or logs of billing-provider webhook events, may be retained for a limited period after deletion where necessary to comply with our legal obligations or resolve disputes.

If you have connected a private Google Sheet, you can disconnect that Google account at any time from your dashboard. Disconnecting asks Google to revoke the access we hold, deletes the stored OAuth tokens for that connection, and removes the private endpoints that were read through it (public endpoints you connected are unaffected and keep working). This action cannot be undone. Deleting your PasteSheet account likewise revokes and removes every Google connection associated with it. You may also review or revoke PasteSheet's access independently at any time from your Google account's security settings.

5. Cookies

PasteSheet uses only the standard session and CSRF-protection cookies required to keep you securely signed in and to protect forms from cross-site request forgery. We do not use analytics cookies, advertising cookies, or any third-party tracking or analytics scripts (such as Google Analytics or similar tools) on the Service today.

6. Data Security

Passwords are stored using industry-standard one-way bcrypt hashing, and API keys are stored as one-way SHA-256 hashes — in both cases, we cannot recover your original password or key from what is stored. All access to the Service is served over HTTPS in production. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Children's Privacy

The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above. Your continued use of the Service after a change becomes effective constitutes acceptance of the revised policy.

9. Contact Us

If you have questions about this Privacy Policy or how your information is handled, contact us at [email protected].