Privacy Policy
Last updated: September 11, 2026
This page is available in English only; the English version prevails.
The short version
SheetPilot writes rows from your browser directly to your own Google Sheet using Google's official API — the saved data never passes through our servers and is never stored by us. Our servers see page content only when you explicitly run an AI action (extract, list capture, cleanup, translation) on that page, and only to produce the result. We never read pages in the background.
Who is responsible
SheetPilot is a product of Xeviora, a brand operated by LIU HU, a sole proprietor, who is the controller of the personal data described in this policy. Contact: support@xeviora.com
Google account access
To write into your spreadsheet, the extension asks Google for the spreadsheets permission via Chrome's built-in sign-in. The resulting access token stays inside the extension on your device; it is sent only to Google's own API endpoints and never to our servers. We cannot see, list or open your spreadsheets. You can revoke this access anytime at myaccount.google.com/permissions. SheetPilot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Data we collect
- Account data. When you create an account: email address, name, and — if you sign in with Google or GitHub — the basic profile those providers share.
- AI requests. When you run an AI action, the relevant text of that page (your selection, extracted text, and a compact outline of page elements), plus the page URL, title and any instruction you type, are sent to our server and forwarded to our AI service providers to produce the rows. See “AI processing” below.
- Recipes. When AI learns a page layout, the resulting rule (site hostname, column names, CSS selectors) is stored in your account so it can sync across devices. Recipes contain the pattern only — never the data extracted with them.
- Credits and referrals. A ledger of credit grants and charges (amount, reason, date), and — if you use an invite link — which account invited yours, so referral bonus credits can be awarded.
- Usage analytics. Pages you open on this website, clicks on outbound links, and anonymous performance metrics, via Google Analytics 4. This covers the website only — the extension sends no analytics at all, and no page you visit with the extension is ever reported. See “Analytics and cookies” below.
- Newsletter. If you enter your email into a subscribe box, that address goes straight to MailerLite, our email provider, and is not stored in our database. See “Email newsletter” below.
- Billing. We store your plan, subscription status and the Paddle customer and subscription identifiers. See “Payment processing” below.
What we never collect
- The rows you save — they go from your browser straight to your Google Sheet.
- Your Google access token, or any ability to open your spreadsheets ourselves.
- Your browsing history — the extension reads a page only when you ask it to.
- Anything from idle usage — no background telemetry.
- Your full card details — payments are handled by Paddle.
Payment processing
Payments are processed by our reseller and Merchant of Record, Paddle.com ("Paddle"). Paddle collects and processes your payment and billing information (such as name, email, billing address, country and payment details) as an independent data controller in order to process your order, calculate taxes, prevent fraud and meet its legal obligations. We never receive or store your full card details. We receive limited order information from Paddle (such as your email, country, plan and transaction status) to provide the service. See Paddle's Privacy Notice: https://www.paddle.com/legal/privacy.
AI processing
To provide AI extraction, list capture, cleanup and translation, the content you submit is sent to our AI service providers (OpenRouter and the model providers it routes to) for processing. We do not use your content to train models, and our providers process it only to return results to you. We do not keep the page content after the request completes.
Extension permissions and why they are needed
These are exactly the permissions declared in the extension's manifest — no more, no fewer. If a permission is ever added or removed, this list changes with it.
identity— obtains the Google sign-in token used to write rows into your own spreadsheet. The token never leaves your device except to Google's API.storage— remembers your saving targets (which spreadsheet and columns), interface language, panel settings, local save history and cached recipes. Nothing in storage is sent to a server except recipes you sync to your account.unlimitedStorage— lets the local save history and recipe cache grow without hitting the browser's default quota. This storage is on your device only.sidePanel— SheetPilot has no popup; its whole interface is a Chrome side panel opened beside the page.contextMenus— adds right-click items so you can save a selection to a target sheet without opening the panel.tabs— reads the active tab's title and URL so the panel can show which page it is about to act on, and addresses the extraction request to that exact tab. Your other tabs are not enumerated and no browsing history is collected or transmitted.activeTab+scripting— after you invoke SheetPilot on a tab (right-click, shortcut or toolbar), injects the reader into that one tab if it was opened before the extension was installed.clipboardWrite— copies extracted rows when you click a copy action.- Host access to sheets.googleapis.com — writes rows and creates spreadsheets in your Google account, directly from your browser.
- Host access to sheet.xeviora.com — the extension calls our API for AI actions, recipe sync and your account status, reusing your normal site session cookie.
- Content script on all sites — SheetPilot saves data from whichever page you are currently viewing, and that page can be on any website, so the script must be declared broadly. It has no user interface, does nothing on page load, and reads the page only when you invoke SheetPilot on that tab.
Data retention and deletion
Recipes persist until you delete them from the dashboard or the extension. Local save history can be cleared inside the extension anytime. You can delete your entire account yourself from Settings → Danger zone: type the confirmation code shown there and your account, every recipe and your credit history are removed immediately and permanently. No email request and no waiting period. Rows already written to your Google Sheet are yours and are unaffected. Paddle keeps its own transaction records as required by law.
Email newsletter
Subscribing is entirely optional and separate from having an account. Addresses are processed by MailerLite, which hosts the list and sends the emails; we do not keep a copy in our own database. Every subscription is double opt-in — you get a confirmation email first and are added only after you click the link — and every email we send carries a one-click unsubscribe link. We never connect newsletter addresses to your purchase history, credit usage or extracted data, we never sell or share the list, and uninstall survey answers stay anonymous even if you leave an email on that page (the two are sent as separate requests).
Service providers
We use these processors, each receiving only the minimum data needed for its function:
- Vercel — website and API hosting.
- Neon — database (account, recipes, credit ledger, subscription status).
- Paddle — checkout, payments, invoicing and refunds (as an independent controller).
- OpenRouter and the model providers it routes to — AI processing, only when you run an AI action.
- Resend — transactional email (password-reset messages).
- Google Analytics 4 with Consent Mode — website usage measurement.
- MailerLite — newsletter, only if you subscribe.
- Google and GitHub — sign-in, only if you choose to sign in with them.
Writes to your spreadsheet go directly from your browser to Google's Sheets API.
Analytics and cookies
We use a first-party session cookie for authentication, and a referral cookie if you arrive through an invite link — both scoped to sheet.xeviora.com only.
This website also uses Google Analytics 4 to count page views, outbound clicks and page performance. IP addresses are truncated before storage, we do not run advertising or cross-site tracking, and we never send analytics the content of a page, the rows you extract, or your spreadsheet. If you are in the EEA, the UK or Switzerland, Google Consent Mode is set to deny analytics and advertising storage by default: no analytics cookie is written unless you have consented, and measurement falls back to cookie-less signals. A browser-level tracker blocker or “Do Not Track” extension also stops it entirely — nothing on this site breaks when it is blocked.
Payment events reach analytics from our server (amount, plan and transaction id, keyed to your account id) so that revenue can be reported accurately even when checkout happens on xeviora.com. The extension itself contains no analytics code.
Your rights
You can ask to access, correct, delete or export the personal data we hold about you, and you can object to or ask us to restrict its processing. Most of this you can do yourself from your dashboard (including deleting your account); for anything else, email support@xeviora.com and we will respond within 30 days. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Children
SheetPilot is not directed at children under 16 and we do not knowingly collect their data.
Contact
SheetPilot is a product of Xeviora, operated by LIU HU. Questions about this policy: support@xeviora.com