Trust

Security

What the add-on can access, where your keys live, and the one thing that reaches our servers. We don't hold SOC 2 or ISO certifications yet.

Google OAuth scopes

The published Apps Script project requests only these scopes (confirm on the consent screen at install):

  • spreadsheets.currentonly: read and write only the spreadsheet the add-on is opened from
  • script.external_request: outbound HTTPS to Lemon Squeezy, Polar, Gumroad, Stripe, and our license API
  • script.scriptapp: install time-driven triggers for scheduled refresh
  • script.container.ui: sidebar and menu UI inside Sheets

We do not request Google Drive, Gmail, Contacts, or Calendar scopes. See the privacy policy for Limited Use disclosure.

API keys stay in your Google account

Source API keys and tokens you paste in the sidebar are stored with PropertiesService.getUserProperties() for your Google account, not in sheet cells, and not in our license database or marketing backend. Sync calls leave Apps Script and go straight to the source APIs over HTTPS.

How to rotate a key.

What reaches RevenueSheet servers

From the add-on sync path, the only RevenueSheet endpoint contacted is the license verify API (POST /api/license/verify). The add-on sends the license key (and, when configured, a shared x-license-secret header). The response is tier, status, and limits: enough to enforce Free / Pro / Business caps. Store rows and source API keys are not uploaded to us for sync.

Separately, when you buy a paid plan on the website, Stripe Checkout and webhooks process billing email and subscription state so we can issue a license. That is checkout, not the revenue sync pipeline. Vercel may also retain standard HTTP logs for the marketing site and APIs.

Encryption in transit

Source API calls and license checks use HTTPS from Apps Script (UrlFetchApp). The website and APIs are served over TLS on Vercel. Spreadsheet contents remain under Google’s account controls; we do not operate a separate ledger copy on our servers.

Subprocessors

  • Vercel: hosts the marketing site and API routes
  • Upstash: Redis store for license records in production
  • Stripe: Checkout, Customer Portal, and payment methods (card data never touches our servers)

Google Workspace / Apps Script and Google Sheets are the runtime for the add-on and your spreadsheet data. Source platforms (Lemon Squeezy, Polar, Gumroad, Stripe) receive the API calls you authorize with your own keys.

What we do not claim

  • No SOC 2, ISO 27001, HIPAA, or similar certification claims
  • No guarantee that a mis-shared spreadsheet cannot expose rows or keys to editors
  • No promise that source APIs stay unchanged forever

Questions: see Privacy or FAQ.