Privacy Policy
Last updated: August 9, 2026
Bulk Image Importer ("the app," "we," "us") is a Google Sheets add-on
that lets you insert multiple image files into a spreadsheet at once.
This policy explains, in four parts, exactly what Google user data we
access, how we use it, who we share it with, and how we protect it โ
plus the other standard disclosures below.
Who this covers
This policy applies to anyone who installs or uses Bulk Image Importer.
It does not apply to other Google products or third-party sites you may
reach through links in our materials.
1. What Google user data we access
The app requests the following Google OAuth scopes, and accesses only
the data each one covers โ nothing more:
| Scope |
Google user data it covers |
Why the app needs it |
spreadsheets.currentonly |
The content (cell values, structure) of the single Google
Spreadsheet you have the add-on open in at the time โ nothing
broader, and no other spreadsheets in your Drive. |
To insert the images you select into the cells you choose. |
drive.file |
Only files/folders the app itself creates in your Google Drive โ
never your existing Drive contents. |
Used only in "true in-cell" insertion mode: images are uploaded to
a folder the app creates (named "Sheets Bulk Image Importer
Uploads") so Sheets can render them as true in-cell values. In
"anchored image" mode this scope's write capability is unused โ
images go directly from your computer into the sheet, no Drive
access at all. |
script.container.ui |
No Google user data โ this scope only permits the app to render
its own interface (the sidebar) inside Google Sheets. |
This is how the file picker and options form are shown to you.
The sidebar is a single first-party HTML page bundled with the
app; it does not load any third-party or external content. |
userinfo.email |
Your Google account's email address. |
To identify which account is asking, so the app can check
whether that account has an active paid license for true in-cell
mode (see the Monetization section below). |
The image files you select to insert are read locally
from your computer by your browser (standard file-picker behavior) and
sent to the script over Google's own infrastructure โ this is data you
provide directly, not Google user data pulled from your account.
2. How we use your Google user data
- Spreadsheet access (
spreadsheets.currentonly) is used
exclusively to write the images you select into the cells you
specify โ the app does not read or analyze the rest of your
spreadsheet's content beyond what's needed to locate the target
cell(s) and validate the sheet's current dimensions.
- Drive access (
drive.file) is used exclusively to
create and manage the single "Sheets Bulk Image Importer Uploads"
folder and the image files placed in it, only when you choose true
in-cell mode.
- Your email address (
userinfo.email) is used
exclusively to look up license/subscription status for the paid
in-cell-mode feature. It is not used for marketing, profiling, or any
purpose beyond that license check.
- We do not use any Google user data to serve ads, and we do not use
it to train generative AI/ML models, in compliance with Google's API
Services User Data Policy, including the Limited Use requirements.
3. Who we share your Google user data with
- We do not sell, rent, or share your Google user data with
any third party, and we do not transfer it off of Google's
own infrastructure to any server we operate โ we do not currently
operate a separate backend server or database at all.
- One disclosure that isn't "sharing" in the usual sense, but
is worth stating plainly: in true in-cell mode, each
uploaded image's Google Drive sharing setting is set to "anyone with
the link can view," because that's what lets Google Sheets' own
rendering service display it as an in-cell value. This means anyone
who obtains that file's direct link could view the image โ it is not
indexed or publicly listed, but it is not private in the way a normal
Drive file is. This is a property of how Sheets renders in-cell
images, not a transfer of your data to us or to any third party; we
never see or receive a copy of the image ourselves. If you're
inserting confidential or client-sensitive images, anchored mode
avoids this entirely, since it never uploads to Drive or changes any
sharing setting.
- Payment processing: if you purchase the paid
in-cell-mode license, payment is handled entirely by Stripe, our
payment processor โ we never see or store your card details. Stripe
sends us only a confirmation that includes your email address and
subscription status, which we use solely for the license check
described above. Stripe's handling of your payment data is governed
by Stripe's own privacy policy, not this one.
4. How we protect your Google user data
- All data in transit โ including the images you upload and any
Drive/Sheets API calls โ travels over HTTPS/TLS, using Google's own
Apps Script infrastructure end to end. We do not route your data
through any server of our own.
- We do not store copies of your images, spreadsheet content, or
Drive files outside of your own Google account. The only data we
retain ourselves is a small internal record per paying customer
(email address, license status) needed to check who has an active
subscription โ stored in Google Apps Script's own project storage,
not a separate database.
- Files the app creates in your Drive (in-cell mode) are created
under your own Google account and subject to your account's own
access controls, with the one explicit exception described in
section 3 above (the "anyone with the link" sharing needed for
Sheets to render them).
- Access to the app's source code and configuration is limited to
the developer; there is no multi-person team or third-party
contractor with access to any user data.
Data retention and deletion
- Images inserted directly into your sheet (anchored or in-cell)
remain part of that spreadsheet, governed by your own Google
Drive/Sheets retention and deletion choices.
- Images uploaded to the "Sheets Bulk Image Importer Uploads" Drive
folder (in-cell mode only) remain there until you delete them
yourself โ the app does not automatically delete them, since removing
them would break the in-cell image's link. You can delete the folder
at any time from your Drive; doing so will break any in-cell images
that reference files in it.
- The internal license record tied to your email (paid users only)
is retained for as long as you maintain an active or past
subscription, so support requests and renewals can be handled
correctly; contact us to request deletion once you're no longer
using the app.
Children's privacy
This app is not directed at, and we do not knowingly collect data from,
children under 13.
Changes to this policy
If this policy changes, the "Last updated" date above will change, and
material changes will be reflected in the app's listing before taking
effect.
Contact
Questions about this policy or your data:
lam.chris.clam@gmail.com
This document is a starting draft prepared to accurately describe the
app's actual technical behavior as of the date above. It has not been
reviewed by a lawyer. Before relying on it for a paid, publicly listed
product, have it reviewed by counsel familiar with Google Workspace
Marketplace requirements and applicable privacy law (e.g. CCPA/GDPR, if
you'll have users in those jurisdictions).