SheetFlow ("we", "our", or "the app") is a privacy-first personal finance tracker. This policy explains how we handle your information.
Our Privacy Commitment
SheetFlow is designed with privacy as a core principle. We do not operate servers that store your financial data. Your transaction data lives exclusively in your own Google Sheets spreadsheet and on your device.
Information We Access
When you use SheetFlow, we access the following through Google Sign-In:
- Basic profile information: Your name, email address, and profile photo from your Google account. This is used to personalize your experience within the app.
- Google Sheets data: We access only the spreadsheet that SheetFlow creates for you in your Google Drive. We read and write transaction data to sync between the app and your sheet.
Google API Permissions (OAuth Scopes)
We request the following specific permissions from your Google account:
- drive.file — Access only to files that SheetFlow creates or that you explicitly open with SheetFlow. This does not grant access to your other Google Drive files.
- userinfo.email — Your email address, used for account identification.
- userinfo.profile — Your name and profile photo, used for display within the app.
How Your Data Is Stored
- On your device (SQLite database): Transaction data, budgets, and recurring transaction rules are cached locally in a SQLite database on your device to enable offline access and fast performance.
- On your device (Secure Storage): Your Google authentication tokens and basic profile information (email, name, photo) are stored in your device's secure storage (Keychain on iOS, Keystore on Android).
- On your device (Preferences): App settings such as theme preference, haptic feedback toggle, analytics opt-in state, category customizations, and connected sheet configuration are stored locally.
- In your Google Sheet: Your financial data is stored in your own Google Sheets spreadsheet, which you own and control.
- No server storage: We do not transmit or store your financial data on any external servers. There is no "SheetFlow cloud" — your data stays with you.
Google API Usage
SheetFlow uses Google APIs to authenticate you and sync data with your spreadsheet. Our use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request the minimum permissions needed (see OAuth Scopes above)
- We do not share your Google data with third parties
- We do not use your data for advertising
- We do not sell your data
Data Security
- Authentication tokens are stored securely using your device's secure storage (Keychain on iOS, Keystore on Android)
- All communication with Google APIs and third-party services uses HTTPS encryption
- We do not have access to your Google account password
Analytics
We use PostHog to collect usage analytics that help us understand how the app is used and improve the experience. Analytics data is processed on servers located in the European Union (eu.i.posthog.com).
Analytics data includes:
- Pseudonymous identifier: A one-way cryptographic hash (SHA-256) of your email address is used to associate events with a user. This hash cannot be reversed to recover your email address.
- Usage events: We track categories of actions such as onboarding completion, transaction creation/editing/deletion, sync operations (start, completion, failures), feature usage (insights, budgets, recurring transactions), settings changes (theme, haptics, analytics toggle), and paywall interactions.
- App lifecycle events: Basic app open/close events are captured automatically.
- App environment: Whether you are using the development or production version of the app.
Analytics data does not include your financial data (transaction amounts, categories, notes), your Google Sheet content, or your Google account credentials.
Opt-in: Analytics is not enabled until you explicitly consent. On first use, the app asks whether you'd like to help improve SheetFlow by sharing anonymous usage data. You can change your choice at any time in Settings.
For more information, see the PostHog Privacy Policy.
Crash Reporting
We use Sentry to collect crash reports and error diagnostics. Crash data is processed on servers located in Germany (ingest.de.sentry.io).
Crash reports may include:
- Error details: Stack traces, error messages, and diagnostic breadcrumbs leading up to the error.
- Screenshots: An automatic screenshot of the app at the moment of the error (this may capture visible UI content but does not capture data outside the app).
- View hierarchy: The structural layout of UI elements on screen at the time of the error (element types and positions, not content).
- Performance data: A sample (20%) of app transactions is monitored for performance diagnostics.
Crash reports do not include your Google account credentials, authentication tokens, or Google Sheet data. We do not attach your name or email to crash reports.
For more information, see the Sentry Privacy Policy.
Your Rights and Controls
- Access: Your data is always accessible in your Google Sheet and within the app.
- Deletion: You can delete all local app data using the "Delete Account & Data" option in Settings. This removes all cached transactions, budgets, recurring rules, app settings, authentication tokens, and profile information from your device. Your Google Sheet remains untouched — you retain full ownership of your spreadsheet data. Note: analytics events and crash reports that were previously transmitted to PostHog and Sentry cannot be retroactively deleted from those services.
- Disconnect: You can disconnect your Google account at any time, which removes your credentials from the app. Your Google OAuth access token expires automatically (typically within one hour).
- Analytics opt-out: You can disable analytics at any time in Settings.
- Revoke access: You can revoke SheetFlow's access to your Google account at any time via your Google Account permissions.
Data Processing Locations
- Your device: Financial data, settings, and credentials (SQLite, Secure Storage, local preferences).
- Google Cloud: Your Google Sheet data, processed via Google APIs under your own Google account.
- European Union: Analytics data processed by PostHog (eu.i.posthog.com).
- Germany: Crash reports processed by Sentry (ingest.de.sentry.io).
- Adapty: Subscription data processed per Adapty's Privacy Policy.
Third-Party Services
SheetFlow integrates with the following third-party services:
- Google Sign-In: For authentication ( Google Privacy Policy)
- Google Sheets & Drive API: For bidirectional data synchronization with your spreadsheet
- PostHog: For usage analytics ( PostHog Privacy Policy)
- Sentry: For crash reporting and error diagnostics ( Sentry Privacy Policy)
- Adapty: For subscription and in-app purchase management. Your email address is used as your subscription profile identifier so that your subscription follows your Google account across devices and reinstalls ( Adapty Privacy Policy)
Children's Privacy
SheetFlow is not intended for children under 13. We do not knowingly collect information from children under 13.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any significant changes through the app or by updating the "Last updated" date above.
Contact
If you have questions about this privacy policy, please contact us at: omerrguzel@gmail.com