Security Policy
Effective Date: June 3, 2026
Introducing SheetWhiz: SheetWhiz is a Chrome extension that brings Excel functionality to Google Sheets.
SheetWhiz’s Commitment to Security: Since our customers’ Google drives are some of their most extensive banks of confidential information, privacy and reliability have been at the core of our business since day one.
As an organization, SheetWhiz strives to build a secure application in accordance with security best practices to uphold the confidentiality, integrity, and availability of our customer’s data. In the spirit of transparency, this document describes the systems and best practices we have in place to protect your data.
SheetWhiz is SOC 2 Type 2 compliant (monitored by OneLeet).
We also successfully completed a 3rd party pen test in Q1 2026.
Access our Trust Center (trust.dimely.com) to learn more and request access to our pen test report and other core documents like Google OAuth verification and other company policies.

Architecture
-
Our infrastructure is hosted on Google Cloud, designed to provide 99.9% availability, with services hosted regionally
-
Features leverage Google APIs which are secured through Google’s OAuth process
-
Features that interact with your Sheets data run on Google App Scripts which is a service hosted on Google Cloud and is built on a distributed architecture
-
Certain AI-assisted features send the spreadsheet data you choose to submit to a third-party AI provider in order to generate your result. SheetWhiz passes this data through and does not store it on our systems, and under their standard API terms, our AI providers do not use it to train their models. Workspace administrators can have AI-assisted features disabled for their domain by contacting support@sheetwhiz.com.
-
Many features and functionality that do not need access to your Sheets data run locally in your browser through our Chrome extension. Certain account-based features, such as saved or shared shortcuts, may store shortcut configuration data on SheetWhiz systems or our service providers, such as Google Firebase, so those features can sync across devices or be shared with other users. SheetWhiz does not store the contents of your spreadsheets.
-
SheetWhiz uses PCI-DSS compliant credit card processors
Security Controls
-
All business systems follow the principle of least privilege. We only ask for permissions when we have to. More specifically, we ask for the minimum set of permissions when logging in. Only when using features that necessitate greater access do we request these permissions (such as for features that interact with your data)
-
SheetWhiz does not store the contents of your spreadsheets on our servers. For features that do not use AI, we access your spreadsheet only to display information back to you, and your data stays within Google. For AI-assisted features, the spreadsheet data you choose to submit is transmitted to a third-party AI provider to generate your result; SheetWhiz passes this data through without storing it, and under their standard API terms, our AI providers do not use it to train their models. In all cases, data in transit is secured through HTTPS and TLS.
-
We do not and do not need to access any of your data from your Sheets during our development process
-
Application source code is stored in a secure environment and changes go through a peer review process
-
SheetWhiz securely connects to Google Sheets through Google’s OAuth process. Administrators have the ability to configure security and privacy access to SheetWhiz through their Google Workspace accounts
Data Privacy
-
All data in transit is secured with TLS 1.2 and above encryption as well as an SSL Certificate. Data at rest, including account data, login data, product usage statistics, and shortcut configuration data for saved or shared shortcuts, is secured through Firebase, Mixpanel, and other applicable service providers using appropriate encryption and security controls
-
For AI-assisted features, we store only basic operational logs, such as account ID, timestamp, model, usage, and status to operate the feature, enforce usage limits, troubleshoot issues, prevent abuse, and improve the Services. We do not store spreadsheet contents, formulas, values, prompts, or AI responses as part of this usage tracking.
-
All API and client communication (desktop, web, and mobile) require HTTPS connections
Compliance
Google's Published Listing Review Process
-
Google’s review team checks the SheetWhiz extension for compliance with their developer program policies every time we update our extension, and, if any violations are found, take appropriate enforcement actions. The review process is illustrated in the “Google’s Published Listing Review Process” diagram
-
The review process uses a combination of manual and automated systems. Since launching, none of our updates have been rejected by the Google review team and we have submitted over 50 builds to the Chrome store
-
Google also periodically reviews our app regardless of whether we submit a new build or not. The “Google’s Periodic Review Process” diagram illustrates how policy violations are handled as part of this review process
-
Google also requires that the SheetWhiz Chrome Extension adhere to Google API Services User Data Policy, including the Limited Use requirements, as required by Google
-
The server that hosts our website holds an A rating from Qualys SSL Labs, a leading service that analyzes many security-related web server properties for millions of websites

Google's Periodic Review Process

Frequently Asked Questions (FAQ)
Can SheetWhiz see any details in my Google Drive? SheetWhiz does not store the contents of your spreadsheets on our servers. For most features, your data stays within Google and we access it only to display results to you. When you use an AI-assisted feature, the data you choose to submit is sent to a third-party AI provider to generate your result and is passed through without being stored by SheetWhiz. Under their standard API terms, our AI providers do not use your data to train their models.
What data is shared when I use AI features, and can I turn them off?
When you use an AI-assisted feature, SheetWhiz sends your prompt and relevant spreadsheet context (which may include cell values, formulas, labels, headers, and sheet names) to a third-party AI provider to generate your result. SheetWhiz does not store this data, and under the provider's standard API terms it is not used to train their models and may be retained by the provider for up to 30 days for abuse monitoring. AI features are optional and can be turned on or off at any time, and SheetWhiz works fully without them. Workspace administrators can disable AI for their entire organization by contacting support@sheetwhiz.com. Please do not use AI features with data you are not authorized to share, including sensitive personal data, passwords, API keys, health information, or payment card data.
Can I request SheetWhiz delete my data? Yes, send us a request here
What types of personal data does SheetWhiz store?
The main personal data we collect is email, which we collect when you log in to our tool. This information is collected so you can use account-based features, including saving shortcuts to your account and, where enabled, syncing or sharing shortcut configuration data. We may also collect troubleshooting and product improvement information, and payment information if you choose to purchase SheetWhiz Pro. We do not store the contents of your spreadsheets, including data you submit to AI-assisted features.
More information can be found on our Privacy Policy
What subprocessors does SheetWhiz have?
-
The tools we use are all highly reputable services. The subset of subprocessors can be found in our Data Processing Addendum. In general, services used at SheetWhiz include:
-
Firebase for authentication and storage of account-based feature data, such as saved or shared shortcut configuration
Mixpanel for analytics (security policy here)
-
Google APIs to support features
-
Wix for our website (security policy here). The server that hosts our website holds an A rating from Qualys SSL Labs, a leading service that analyzes many security-related web server properties for millions of websites.
-
Slack for internal communications (security policy here)
-
Google and OneSignal (security policy here) for email communications
-
Stripe (security policy here) and Wix for payments
-
OpenAI for AI-assisted features. Your data is passed through to generate your result and, under their standard API terms, is not used to train their models (enterprise privacy policy here)
-
Vercel for backend infrastructure (security policy here)
Where can I learn more?
Read our End User License Agreement, Terms of Service, Privacy Policy, and Data Processing Addendum for more details. You can also send us any questions here