Last updated: July 7, 2026
SheetMind AI ("we," "our," "the extension") is a Chrome extension that helps you perform AI-assisted operations on Google Sheets, and optionally send WhatsApp messages to leads in your spreadsheet. This page explains exactly what data we access, what we send to third parties, and what we store.
When you sign in, we request the following Google OAuth scopes:
spreadsheets — read and write access to Google Sheets you open theextension on, so we can read the data needed to build a preview and apply the change you confirm.
drive.file — limited to files you've explicitly opened or createdwith this extension; we cannot see any other file in your Drive.
userinfo.email — your Google email address, used to identify youraccount and usage/subscription status.
We do not have blanket access to your Google Drive or any spreadsheet you haven't opened with the extension.
When you ask the "Ask for a change" assistant to do something, we send our backend, and it forwards to Anthropic's Claude API:
We never send your full spreadsheet contents to Claude or to our backend. Row-level computation (finding duplicates, splitting names, validating data, reformatting phone numbers, etc.) happens entirely inside the extension, on your device, using the full data your browser already has direct access to via the Sheets API. Only the schema and small sample above ever leave your machine for AI planning purposes, and only while you're actively submitting a request.
SheetMind AI offers two ways to message leads from your spreadsheet, with different data handling:
and message text are read directly from your sheet in the browser and used to open a wa.me link — they are never sent to our backend or stored anywhere by us.
Business Account, phone numbers and template variable values you submit for a bulk send are sent to our backend, which relays them to Meta's WhatsApp Cloud API on your behalf. We persist the send job's results (phone number, sent/failed status, and any error returned by Meta) so that job progress survives a backend restart and so you can review what happened — this data is retained as part of your account's job history and deleted if you delete your account. Your WhatsApp Business access token is encrypted before storage and used only to send messages on your behalf.
If you subscribe to the paid plan, Whop (our billing provider) handles checkout and payment directly — we never see or store your card number or other payment details. Whop sends us a webhook confirming your subscription status, plan, and renewal date, which we store to determine your access level and usage limits.
We track how many AI operations you've used (a lifetime count on the free plan, a monthly count that resets each billing cycle on the paid plan), your subscription status, and aggregate metadata about each AI request (model used, token counts, which spreadsheet ID — not its contents — the request was for). This is used only for enforcing usage limits and diagnosing issues.
advertising or any other purpose beyond what's described in this policy.
sample described above, and only while actively generating an AI plan.
via chrome.storage.sync and are never sent to our servers.
prompt to generate a structured operation plan or text answer. See anthropic.com/privacy.
content only if you use the WhatsApp Business API feature, to deliver your messages. See Meta's privacy policy.
subscription status. See whop.com/privacy.
| Data | Retained |
|---|---|
| Account record (Google user ID, email, usage counters, subscription status) | While your account is active |
| AI request/response payloads (schema, sample rows, prompts) | Not persisted beyond generating the response |
| WhatsApp Business connection (access token, encrypted) | Until you disconnect or delete your account |
| WhatsApp bulk-send job results (phone numbers, send status) | Until you delete your account |
| Usage/event logs (metadata only, never spreadsheet contents) | While your account is active |
You can request deletion of your account and all associated data (usage counters, WhatsApp connection, job history) at any time by contacting us below. Deleting your Google account connection or uninstalling the extension stops all future data collection immediately.
For data deletion requests or privacy questions, contact: mohamedlaminebhaje@gmail.com
We will update this document and the version number in manifest.json whenever data handling changes materially.