Security

API keys

Source keys (Lemon Squeezy, Polar, Gumroad, or Stripe) are required for sync. Treat them like passwords for your storefront data.

Where keys are stored

When you paste a key in the sidebar, RevenueSheet writes it to Apps Script User Properties for your Google account (not into sheet cells). Keys are not sent to www.revenuesheet.app marketing servers and are not stored in our license database. Sync calls go from Apps Script to the source APIs directly.

License keys vs source keys

A license key from Checkout proves your Free / Pro / Business tier. A source API key proves access to Lemon Squeezy, Polar, Gumroad, or Stripe. They are different credentials: never paste a license key into a source field or the reverse.

Rotation

  1. Create a new token in the source dashboard.
  2. Paste it in the RevenueSheet sidebar and save.
  3. Revoke the old token at the source.

Rotate immediately if a spreadsheet was shared with Edit access to people who should not see store data, or if a laptop with an open sheet was lost.

What we never ask for

  • Google account passwords
  • Stripe secret keys for your customer payments (Checkout for RevenueSheet licenses is separate)
  • Gmail, Contacts, or Google Drive scopes