Privacy Policy

Form Link for Sheets™ — Google Workspace™ add-on

Last updated: August 4, 2026

This policy covers Form Link for Sheets™, the Google Workspace™ add-on that fills PDF forms from Google Sheets™ data. (It is separate from the Form Link iOS app and Chrome extension, which are covered by the main Form Link Privacy Policy.) It explains what the add-on accesses and how it handles your data.

What we access

With your authorization, Form Link for Sheets accesses:

  • the data in the spreadsheet you have open, to read the values you map into a PDF and to write back a link to the generated file;
  • the PDF template you explicitly select via the Google Picker; and
  • a folder in your Google Drive™ that the add-on creates and you name, where generated PDFs are saved.

The add-on requests per-file Drive access (drive.file) and active-spreadsheet access (spreadsheets.currentonly) only — it cannot access your other files or spreadsheets.

How we use it

Your spreadsheet data, your PDF template, and the documents generated from them are used solely to generate the PDFs you request. That processing happens entirely within Google Apps Script, using a locally bundled copy of the open-source pdf-lib library — there is no remote code execution. Generated PDFs are stored only in your own Google Drive.

What we transmit to form-link.ai, and why

The add-on contacts one server outside Google: form-link.ai, which we operate. It does so at two moments.

  • When you open the sidebar — to confirm that you have an active Form Link account and to show your plan in the sidebar. The add-on sends a Google-signed identity token, from which we read your email address and, if you are on a Google Workspace account, your organization's domain. (Consumer Google accounts have no such domain, and none is sent.) The answer is cached for 12 hours, so this happens at most about twice a day per user.
  • After you generate PDFs — to count usage. At the end of a Generate run the add-on sends one batch of usage records, along with the same email address and organization domain. If that request fails, the records stay on your own device and are re-sent on a later run.

Each usage record contains only:

  • whether the PDF was newly created or re-generated;
  • a hashed template identifier — a truncated one-way hash of the template's Drive file ID, which lets us group activity by template but cannot be turned back into a file, a file name, or a link;
  • the number of form fields filled;
  • the number of pages in the generated document;
  • the time the PDF was generated; and
  • a random one-time event ID, so that a retry is not counted twice.

We use this to confirm your entitlement to use the add-on, to answer support questions about your own account, and to understand how much the product is used in aggregate.

What we never transmit

We never send the contents of your spreadsheet, your forms, or your documents to form-link.ai or to any other non-Google server. Specifically, and without exception: no spreadsheet cell values, no form field contents — neither the names of the fields nor the values filled into them — and no PDF bytes or generated documents of any kind. We also never send your template's file name or a usable link to any file in your Drive. This is enforced at both ends: the add-on builds each usage record from counts and identifiers only, and our server accepts only that fixed list of fields and discards anything else it receives.

Apart from form-link.ai, the only other network request the add-on makes is to Google's own Drive API over HTTPS, to read the bytes of the template you selected.

How we protect your data

PDF generation happens entirely within Google's infrastructure (Google Apps Script), which encrypts data in transit (HTTPS/TLS) and at rest by default. Your spreadsheet data, PDF templates, and generated documents are never sent to, stored on, or processed by any system we control: they are processed transiently in memory during each run, and generated PDFs are written only to your own Google Drive, protected by your Google account's own security controls.

The account and usage data described above is sent to form-link.ai over HTTPS/TLS and is authenticated by a token that Google signs and we verify — an unsigned email address authorizes nothing. It is stored in an access-controlled database that no browser, no other user, and no client-side code can read; only our server can, using credentials that never leave it.

We limit access to your Google account using least-privilege scopes — per-file Drive access (drive.file) and current-spreadsheet-only access (spreadsheets.currentonly) — so the add-on can reach only the specific files you open or create and the single spreadsheet you have open, and nothing else in your Google account.

What we do not do

We do not sell or share your data, use it for advertising, use it to train machine-learning or AI models, or transfer it to others except as needed to operate the add-on. We run no advertising, cross-site, or behavioral tracking, and the add-on sets no tracking cookies. The usage records described above are counts of your own activity, kept for the purposes stated above and nothing else. Form Link for Sheets' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, none of the data we transmit or retain is derived from the contents of your Google user data — only from counts of the actions you choose to take.

What we retain, and for how long

We retain no copies of your spreadsheet data, your templates, or your generated documents on any server we control — they are never sent to us in the first place. Generated documents persist only in your own Google Drive, under your control, and you can delete them at any time.

What we do retain is the account and usage data described above: your email address, your Workspace domain if you have one, and one record per PDF generated. We keep these for as long as your Form Link account is active, because they are what entitles you to use the add-on and what lets us answer support questions about your own usage. They are not automatically expired, and we delete them when you ask us to.

How to delete your data, and how to revoke access

To have your usage records and account data deleted, email [email protected] from the Google account you use with the add-on, or from your Form Link account's email address. We will delete them within 30 days and confirm when it is done.

You can revoke the add-on's access to your Google account at any time at myaccount.google.com/permissions. Revoking access stops the add-on from running and stops all further transmission to form-link.ai immediately. It does not by itself delete records we have already received — to have those deleted, email us as described above.

Contact

Questions about this policy? Email [email protected].

Google Sheets™, Google Drive™, and Google Workspace™ are trademarks of Google LLC. Form Link is an independent add-on and is not affiliated with, sponsored by, or endorsed by Google LLC.