Skip to content
Mergewrite
How it works Pricing Support

Mergewrite Privacy Policy

Effective: September 6, 2026

Mergewrite ("we", "us") helps Google Workspace users create personalized Docs, Slides, and PDFs from Google Sheets rows and Google Forms responses. Questions and deletion requests may be sent to support@mergewrite.com.

Data we handle

We store the account email and Google OAuth access and refresh tokens needed to provide the service. Both access and refresh tokens are encrypted with AES-256-GCM. We also store job configuration (template and folder IDs, mappings, delivery settings), usage and billing entitlement counters, and run metadata. Run logs contain only row index, outcome, warning/error, generated Drive file ID/link, and timestamps.

Spreadsheet cells, form questions/answers, template bodies, generated document content, and email bodies are processed transiently and are never retained server-side after a run finishes. A submission queued because the account has no credits is the sole operational exception: its answers are retained temporarily, only to perform the merge, for no more than seven days; answers are erased immediately after processing, failure, or expiry. Mergewrite does not place hidden state in a user's spreadsheet.

How data is used and shared

Data is used only to authenticate the user, execute configured merges, deliver emails, show run history and usage, prevent duplicate output, provide support, and maintain the user's paid entitlement. Google data is not sold, used for advertising, or used to train AI models. It is sent only to Google APIs at the user's direction and to service providers needed to operate Mergewrite: Google Cloud (Cloud Run and Firestore) and Lemon Squeezy (merchant of record). Payment-card data never reaches Mergewrite.

Mergewrite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and security

Run logs are retained for at least 90 days and then may be deleted. Queued form answers expire after seven days. OAuth tokens are encrypted at rest; transport uses HTTPS; access is least-privilege and audited. No system is perfectly secure, so suspected incidents should be reported to support@mergewrite.com.

Account deletion

The add-on's Usage → Delete account action performs a full account purge. A request may also be emailed to support@mergewrite.com. We complete verified deletion requests within 30 days. Jobs, triggers/associations, OAuth tokens, run logs and row records, usage records, notification state, and queued submissions are permanently deleted. Purchases made within the previous 30 days are refunded in full under our 30-day money-back guarantee. We keep only a keyed, irreversible account hash and deletion timestamp as an anonymized receipt. Generated files remain in the user's Google Drive and are not deleted because the user owns them.

User choices and legal matters

Users may revoke Google access in their Google Account, manage or cancel subscriptions through Lemon Squeezy, or request access/correction by contacting support. A canceled subscription remains active until its paid period ends. Depending on location, users may have additional privacy rights. We will post material policy changes at the stable policy URL and update the effective date.

© 2026 Mergewrite.

Terms Privacy Refund policy

Google Sheets™, Google Forms™, Google Docs™, Google Slides™ and Google Drive™ are trademarks of Google LLC. Mergewrite is not affiliated with or endorsed by Google.

support@mergewrite.com +66654726833