Privacy Policy

Last updated: 6 August 2026

The short version. Your documents never leave your Google account. MergeSheet runs entirely inside Google's Apps Script platform, on Google's servers, using your own Google session. There is no MergeSheet server that receives, stores, or processes your spreadsheet data or your finished documents. We could not read them if we wanted to.

Where your data actually goes

MergeSheet is a Google Workspace add-on. It is not a website you upload files to, and it is not a service that connects to your Google account from the outside. The entire product is code that runs on Google's own Apps Script infrastructure, inside your Google session, under your own permissions.

In practice that means: when you generate a document, your spreadsheet row is read by Google, the template copy is made by Google, the PDF is written to your Google Drive by Google. At no point does any of that content travel to a server we own or control. We operate no database of customer documents, because there is nowhere for such a database to live.

The only outside party involved in the product at all is Stripe, and only for payment. See Payment information below.

The permissions we ask for, and why

Google shows you a consent screen listing the permissions MergeSheet requests. Here is every one of them and the exact feature it exists for. We request no permission that is not used by a shipping feature.

PermissionWhat it is used for
See, edit, create, and delete only the specific Google Drive files you use with this app Copying your template, saving the finished PDF into your chosen folder, and removing the temporary working copy. This permission is deliberately the narrow one: it gives MergeSheet access only to files the add-on itself created and files you explicitly chose through Google's file picker. It does not grant access to the rest of your Drive.
See, edit, create, and delete all your Google Docs documents Opening the temporary copy of your template and replacing the tags in it. Google does not offer a narrower Docs permission that works for a copy made on your behalf from a spreadsheet, which is why this broader one is required. In practice MergeSheet only ever opens two kinds of document: a copy it just made, and the template you picked.
See, edit, create, and delete only the current spreadsheet Reading the row you are merging, and writing the result link and status back into that row. Limited to the spreadsheet you have open.
Display and run third-party web content in prompts and sidebars Drawing the MergeSheet sidebar and the file picker dialog.
Connect to an external service Used solely to communicate with Stripe for subscription billing: creating a checkout session when you upgrade, creating a billing-management session when you manage your plan, and verifying your subscription status. This is the add-on's only outbound network connection. No spreadsheet data, template, or generated document is ever sent to Stripe or any other external service. If you never upgrade to the paid plan, this permission is never used.
Allow this application to run when you are not present Only used if you switch on "Generate automatically on form submit". It creates the trigger that runs a merge when a new Google Form response arrives. Turning the setting off deletes the trigger.
See your primary Google Account email address Matching your subscription. This is how we know whether your account is on the free or paid plan.
See your primary Google Account language preference Showing the add-on in the same language as the rest of your Google account.
MergeSheet does not request any Gmail permission. It cannot read, send, or access your email in any way. If a future version adds emailing, it will require a new consent screen that you would have to approve, and this policy will be updated first.

What we store

MergeSheet keeps a small amount of configuration, saved using Google's own Apps Script properties storage, which lives in your Google account rather than in a database of ours:

We do not store the contents of your spreadsheet, your templates, or the documents you produce. We do not log the values you merge.

Payment information

Paid subscriptions are processed by Stripe. Payment is the one part of MergeSheet that involves a third party, and card details go directly to Stripe. We never see, receive, or store your card number.

Stripe receives your email address so your payment can be matched to your account. Stripe's handling of your information is governed by Stripe's privacy policy.

Sharing and selling

We do not sell your data. We do not rent it, trade it, or share it with advertisers, data brokers, or analytics companies. The only third party that receives anything is Stripe, and only the minimum needed to process a payment you chose to make.

We will disclose information only where legally compelled to do so, and only the information actually demanded.

AI and model training

Your documents and spreadsheet data are not used to train any machine learning model, ours or anyone else's. As described above, we do not receive that content in the first place.

Deleting your data

Because MergeSheet stores so little, deletion is straightforward:

If you are in a jurisdiction with a statutory right of access, correction, portability, or erasure, such as the UK or EU under GDPR or California under the CCPA, write to us at the address below and we will honour the request. Given how little we hold, most such requests can be answered the same day.

Children

MergeSheet is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes to this policy

If this policy changes in a way that affects what we access or store, we will update the date at the top and, where the change is significant, describe it in the add-on itself. Any new permission requires a fresh Google consent screen that you must approve before it takes effect.

Contact

MergeSheet is operated from New York State, United States. Questions about this policy, or about your data, go to [email protected]. A person reads that inbox and will usually reply within two business days.