Privacy Policy
Last updated: October 24, 2024 · Effective date: October 24, 2024
Summary for Quick Reference
- • Zero Persistent Data Storage: We never store, save, or cache your spreadsheet rows, cell values, or contents in any database.
- • Read-Only API Access: We only request read-only permissions to query Google Drive file lists and read Google Sheets data on your explicit command.
- • Secure Sessions: OAuth credentials are stored exclusively in encrypted, HTTP-only session cookies in your browser.
- • No Data Selling or AI Training: Your data is never sold, shared with third parties, or used to train artificial intelligence or machine learning models.
1. Introduction
Welcome to SheetSearch (accessible at https://sheetsearch.umairlab.com). We value your trust and are committed to protecting your personal information and spreadsheet data.
This Privacy Policy explains how SheetSearch accesses, uses, processes, and protects your information when you connect your Google Account and use our real-time search application.
2. Information We Access and Process
When you use SheetSearch, we interact with Google APIs solely to provide the search functionality. We access the following categories of data:
- Google Account Identity: Your email address and basic profile info (via OpenID Connect,
openid,userinfo.email,userinfo.profile) to identify your session and display your signed-in email address in the user interface. - Google Drive Metadata: Spreadsheet file metadata (such as file ID, file name, and modified timestamp) via the Google Drive API (
https://www.googleapis.com/auth/drive.readonly) to display the list of spreadsheets available for you to choose from. - Google Sheets Data: Sheet tab names and cell values within selected spreadsheets via the Google Sheets API (
https://www.googleapis.com/auth/spreadsheets.readonly) solely during an active search query to locate matching keywords.
3. How We Use Your Information
We use the data accessed from Google APIs strictly to operate and deliver the SheetSearch service:
- To authenticate your session securely using OAuth 2.0.
- To populate the spreadsheet selector list with files you have permission to view.
- To execute keyword searches across your selected sheets in real time and return matching row numbers and cell contents to your browser.
- To construct direct deep links enabling you to navigate directly to matching rows in Google Sheets.
4. Google API Services User Data Policy Compliance (Limited Use)
Google API Services User Data Policy Disclosure
SheetSearch's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not use Google user data to serve advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read your spreadsheet data unless you have given us explicit permission for troubleshooting or support purposes, or as required by law.
- We do not transfer or disclose Google user data to third parties, except as strictly necessary to provide or improve user-facing features.
- We do not use Google user data to train, evaluate, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models.
5. Data Storage, Retention, and Security
No Database Storage: SheetSearch operates without a persistent database. We do not store your spreadsheet data, search queries, or search results on our servers or hard drives.
In-Memory Processing: When you execute a search, spreadsheet rows are retrieved ephemerally into server memory, filtered against your query keyword, and streamed back to your client. Memory is released immediately after request completion.
Session Encryption: OAuth access and refresh tokens are stored exclusively inside encrypted, signed HTTP-only session cookies (powered by iron-session) on your own browser. Server secrets are required to decrypt tokens.
Data in Transit: All communications between your browser, our servers, and Google APIs are encrypted using industry-standard Transport Layer Security (TLS/HTTPS).
6. Third-Party Sharing and Disclosures
We do not sell, rent, trade, or monetize your personal data or spreadsheet contents. We will only disclose information if required by applicable law, regulation, or valid legal process.
7. Your Rights and Revoking Access
You maintain complete control over your Google Account and data access at all times:
- Sign Out: Clicking the "Sign Out" button immediately destroys your encrypted session cookie and disconnects your active session.
- Revoke Google Account Permissions: You can revoke SheetSearch's access to your Google Account at any time via your Google Account Third-party apps & services settings. Once revoked, SheetSearch can no longer access your Drive or Sheets files.
8. Cookies and Technical Tracking
SheetSearch uses strictly necessary, encrypted HTTP cookies for session management and CSRF protection. We do not use tracking cookies, analytics trackers, or third-party marketing cookies.
9. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect improvements to the service or regulatory changes. Any updates will be posted on this page with an updated "Last updated" date.
10. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact us at:
SheetSearch
Website: https://sheetsearch.umairlab.com
Email: privacy@umairlab.com (or contact via umairlab.com)