Whatsheet — WhatsApp to Google Sheets or Microsoft Excel
Last updated: August 2026
This policy explains what data Whatsheet collects when you connect a WhatsApp number and a Google account or a Microsoft account, why, and how it's handled. Whatsheet is available as a Google Sheets add-on and, separately, as a Microsoft Excel add-in — this policy covers both; which sections apply to you depends on which one you use.
| Category | What it includes |
|---|---|
| Account data | Name, email address, and password (stored as a salted hash, never in plain text) |
| WhatsApp connection data | Your WhatsApp number's session credentials, needed to keep your number linked (stored encrypted; see Security below) |
| Message content | Every WhatsApp message sent to your connected number is checked in real time against the extraction rules you've configured. Only messages that actually match are retained (a short preview alongside the extracted fields, for your own audit trail) — messages that don't match anything are not stored. If you enable AI extraction, a record of that call (cost and token usage) is kept regardless of match, but without the message text unless it matched. |
| Google account access (Google Sheets add-on only) | An OAuth token scoped only to the specific spreadsheet(s) you create or explicitly select — never your whole Google Drive |
| Microsoft account access (Excel add-in only) | An OAuth token scoped only to files Whatsheet creates or the specific workbook you're actively using — never your whole OneDrive or SharePoint |
| Extraction rules and (if enabled) AI prompts | The keyword rules or natural-language instructions you configure for what to extract from messages |
We do not sell your data or your contacts' message data to third parties.
Data is shared only with the services required to provide functionality you've enabled:
spreadsheets permission scope. This scope technically permits access to any spreadsheet in your Google account, but Whatsheet only ever reads or writes the one spreadsheet you set up through the add-on — it never browses, lists, or accesses any other spreadsheet or Drive fileFiles.ReadWrite permission scope, requested with the minimum other scopes needed to sign you in (openid, email, offline_access). Whatsheet only ever reads or writes the one workbook you set up through the add-in — it never browses or lists any other OneDrive or SharePoint fileWhatsheet's optional AI extraction tier sends the text of a WhatsApp message, and the column names you've configured, to a third-party AI model provider (Anthropic or OpenAI) to generate the extracted field values — which are then written to your Google Sheet or Excel workbook via the Google Sheets API or Microsoft Graph, whichever you're using.
Whatsheet's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
(Excel add-in only) The same commitments apply identically to data obtained through Microsoft Graph:
WhatsApp session credentials and Google/Microsoft OAuth tokens are encrypted at rest (AES-256-GCM). Passwords are hashed, never stored in plain text. All traffic to and from the platform is served over HTTPS.
We retain your data for as long as your account is active. You can disconnect your WhatsApp number or your Google/Microsoft account at any time from within the app, which stops further processing. To request full deletion of your account and all associated data, email [email protected] with the subject "Data Deletion Request" — we process verified requests within 30 days.
You can request access to, correction of, or deletion of your data by contacting us using the details below.
Whatsheet is a business tool and is not directed at or knowingly used by children.
We may update this policy as the product changes. Material changes will be reflected by updating the date at the top of this page.
Questions about this policy or your data: [email protected]