SheetMind AI: Privacy Policy

Last updated: August 3, 2026

SheetMind AI ("we," "our," "the extension") is a Chrome extension that helps you perform AI-assisted operations on Google Sheets, and optionally send WhatsApp messages to leads in your spreadsheet. This page explains exactly what data we access, what we send to third parties, and what we store.

Information we collect

Google account data

When you sign in, we request the following Google OAuth scopes:

extension on, so we can read the data needed to build a preview and apply the change you confirm.

with this extension; we cannot see any other file in your Drive.

account and usage/subscription status.

We do not have blanket access to your Google Drive or any spreadsheet you haven't opened with the extension.

Spreadsheet data sent to our AI feature

When you ask the "Ask for a change" assistant to do something, we send our backend, and it forwards to Anthropic's Claude API:

We never send your full spreadsheet contents to Claude or to our backend. Row-level computation (finding duplicates, splitting names, validating data, reformatting phone numbers, etc.) happens entirely inside the extension, on your device, using the full data your browser already has direct access to via the Sheets API. Only the schema and small sample above ever leave your machine for AI planning purposes, and only while you're actively submitting a request.

WhatsApp data

SheetMind AI offers two ways to message leads from your spreadsheet, with different data handling:

and message text are read directly from your sheet in the browser and used to open a wa.me link. They are never sent to our backend or stored anywhere by us.

Business Account, phone numbers and template variable values you submit for a bulk send are sent to our backend, which relays them to Meta's WhatsApp Cloud API on your behalf. We persist the send job's results (phone number, sent/failed status, and any error returned by Meta) so that job progress survives a backend restart and so you can review what happened. This data is retained as part of your account's job history and deleted if you delete your account. Your WhatsApp Business access token is encrypted before storage and used only to send messages on your behalf.

Shopify Order Automation data (optional, paid feature)

If you connect your Shopify store to enable Order Automation, we process the following for each new order, for the sole purpose of notifying your customer (by WhatsApp, email, or both, whichever channel(s) you enable) and syncing the order to your chosen Google Sheet:

and email address** (email channel): used to personalize and send the order confirmation via your own connected WhatsApp Business Account or your own configured email account, and written to the destination row in your Google Sheet.

as sheet-row values.

been processed, so it isn't confirmed or synced twice.

This data is never sold, shared with advertisers, or used for any purpose beyond sending that one notification and writing that one sheet row. It's delivered to places you already control: your own connected WhatsApp Business Account (via Meta's Cloud API), your own configured email account (via your own SMTP credentials), and your own chosen Google Sheet (via the Google Sheets API). We do not keep a separate copy of the customer's name, phone number, email address, or order total in our own database once that message is sent and that row is written. The only order-related information we retain ourselves is the order ID, its processing status (succeeded/failed), and, if a step failed, a diagnostic message with the customer's name, phone number, and email address stripped out before it's stored, so a failed send never leaves a copy of their contact details sitting in our logs.

To perform this, we also hold (encrypted, same as other access tokens described in this policy): your Shopify app access token, your SMTP credentials if you enable the email channel, and a separate Google OAuth connection scoped only to Sheets access, authorized once so we can write to your sheet without you needing to keep the extension open during order processing.

Systeme.io Order Automation data (optional, paid feature)

If you connect your Systeme.io account to enable Order Automation, we process the following each time a contact opts in (joins a funnel or submits an application inside Systeme.io), for the sole purpose of notifying that contact and syncing them to your chosen Google Sheet:

if you've configured the WhatsApp channel: used to personalize and send the notification, and written to the destination row in your Google Sheet.

opt-in events for the same contact within a short rolling window.

Just like Shopify Order Automation above, this data is delivered only to places you already control (your own WhatsApp Business Account, your own SMTP account, your own Google Sheet), and we do not keep a separate copy of the contact's name, email, or phone number in our own database once the notification is sent and the row is written. We retain only the contact ID, processing status, and a diagnostic message with the contact's name, phone number, and email stripped out if a step fails. Your Systeme.io API key is stored encrypted, the same as every other access credential described in this policy.

WhatsApp Inbox data (optional, paid feature)

WhatsApp Inbox lets you view and reply to messages customers send to your connected WhatsApp Business number directly from the extension's sidebar. This is deliberately not a permanent message history or CRM:

buffer for 48 hours, after which it is permanently deleted. We never retain a customer's message content beyond that window.

to this feature.

list and to enforce Meta's own 24-hour customer-service-window rule (which free-form replies are and aren't allowed, independent of our own 48-hour retention window): the customer's phone number and name, an unread-message count, and the timestamps of their last incoming and your last outgoing message. We never retain the content of what was said past 48 hours.

local storage (chrome.storage.local) for a responsive UI; this is cleared if you uninstall the extension.

Whop subscription/billing data

If you subscribe to the paid plan, Whop (our billing provider) handles checkout and payment directly. We never see or store your card number or other payment details. Whop sends us a webhook confirming your subscription status, plan, and renewal date, which we store to determine your access level and usage limits. This is the only subscription SheetMind AI has. Order Automation for Shopify and for Systeme.io are both unlocked by the same SheetMind AI Pro subscription, with no separate or additional charge for either.

Usage data

We track how many AI operations you've used (a lifetime count on the free plan, a monthly count that resets each billing cycle on the paid plan), your subscription status, and aggregate metadata about each AI request (model used, token counts, which spreadsheet ID (not its contents) the request was for). This is used only for enforcing usage limits and diagnosing issues.

What we do NOT do

advertising or any other purpose beyond what's described in this policy.

sample described above, and only while actively generating an AI plan.

via chrome.storage.sync and are never sent to our servers.

Third parties we share data with

prompt to generate a structured operation plan or text answer. See anthropic.com/privacy.

content only if you use the WhatsApp Business API feature (including Order Automation's confirmation messages, Systeme.io's opt-in notifications, and WhatsApp Inbox replies), to deliver your messages. See Meta's privacy policy.

webhooks (customer name/phone or email, order number/total) from your store, and send a tag update back to Shopify once an order is confirmed. See Shopify's privacy policy.

webhooks (contact name, email or phone) from your Systeme.io account, and send a tag update back once a contact is processed. See Systeme.io's privacy policy.

us your subscription status. See whop.com/privacy.

Google's privacy policy.

Data retention

Data Retained
Account record (Google user ID, email, usage counters, subscription status)While your account is active
AI request/response payloads (schema, sample rows, prompts)Not persisted beyond generating the response
WhatsApp Business connection (access token, encrypted)Until you disconnect or delete your account
WhatsApp bulk-send job results (phone numbers, send status)Until you delete your account
Shopify connection (app access token, encrypted)Until you disconnect or uninstall the app
Shopify order processing records (order ID, status, sanitized error text, never customer name/phone/email/total)Until you delete your account
Systeme.io connection (API key, encrypted)Until you disconnect
Systeme.io opt-in processing records (contact ID, status, sanitized error text, never contact name/phone/email)Until you delete your account
WhatsApp Inbox conversation metadata (customer phone/name, unread count, last-message timestamps, never message content)Until you disconnect WhatsApp Business or delete your account
WhatsApp Inbox message content (encrypted)Maximum 48 hours, then permanently deleted
Google Sheets background-sync connection (refresh token, encrypted)Until you disconnect
Usage/event logs (metadata only, never spreadsheet contents)While your account is active

Your rights

You can request deletion of your account and all associated data (usage counters, WhatsApp connection, job history) at any time by contacting us below. Deleting your Google account connection or uninstalling the extension stops all future data collection immediately.

Contact

For data deletion requests or privacy questions, contact: contact@sheetmindai.com

Changes to this policy

We will update this document and the version number in manifest.json whenever data handling changes materially.