Last updated: July 22, 2026
CopydoWell is provided by Metalix ("we", "us", "our") as two related products: a Google Sheets add-on and a companion Chrome extension. This policy covers both — sections are marked where they apply to only one.
Google Sheets add-on
What it accesses
The add-on requests these Google OAuth scopes:
https://www.googleapis.com/auth/spreadsheets— read and write access to Google Sheets you open the add-on in, or that you explicitly point it to (via a spreadsheet URL/ID you enter into the sidebar).https://www.googleapis.com/auth/script.container.ui— to display its sidebar and menu inside Google Sheets.https://www.googleapis.com/auth/script.scriptapp— to create, list, and remove the installable triggers that power the optional Automation feature (run on edit, on form submission, or on a schedule), only when you explicitly enable it.https://www.googleapis.com/auth/userinfo.email— to identify the Google account you're signed in with, shown in the sidebar.
How it's used
- All spreadsheet data is processed entirely within Google's Apps Script infrastructure, running under your own Google account's authorization.
- Data is copied, sorted, and filtered only at your explicit request or via automation you personally configured and can disable at any time.
- Automation settings (source sheet, destination spreadsheet, sort/filter rules) are stored using Apps Script's Document Properties service, scoped to the specific spreadsheet you configured — this stays inside your own Google Workspace environment.
Chrome extension
What it accesses
The extension requests:
https://www.googleapis.com/auth/spreadsheets— same purpose as above, via the Sheets API directly. This is the only OAuth scope the extension requests.
It also uses these browser permissions:
- identity — to sign you into Google so the extension can access the Sheets API on your behalf.
- storage — to save your configured triggers (source, destination, filters, schedule) locally in your browser.
- alarms — to run your scheduled triggers at the times you set.
- notifications — to alert you if a scheduled trigger fails.
- Read-only access to the active tab's URL on
docs.google.com— only to detect which spreadsheet is open, so the destination is set automatically.
Donations
The Chrome extension is free. If you choose to make a voluntary donation, it is processed by Razorpay, a third-party payment processor. Your payment details (card number, UPI ID, billing information, etc.) are handled directly by Razorpay — CopydoWell and Metalix never receive, see, or store your payment card information. See Razorpay's privacy policy for how they handle payment data.
Website analytics
This informational website (copydowell.metalix.in) uses Google Analytics 4 to understand aggregate, anonymous visitor traffic — such as page views, approximate region, and referral source — so we can improve the site. Google Analytics sets cookies and processes this data on our behalf; see Google's Privacy Policy. We do not use this data for advertising or to identify individual visitors. Analytics cookies are disabled by default and are only enabled if you click "Accept" on our cookie banner (Google Consent Mode); you can decline, and your choice is remembered.
This analytics applies only to the website. The CopydoWell products themselves — the Google Sheets add-on and the Chrome extension — contain no analytics or tracking and send no usage data to us. You can opt out of Google Analytics across all sites with the Google Analytics Opt-out Browser Add-on.
How we protect sensitive data
CopydoWell accesses Google user data (your spreadsheet contents) only through Google's official APIs, under your own OAuth authorization. The mechanisms protecting that data:
- No server-side storage or processing. We operate no backend server. Spreadsheet data is processed only inside Google's own infrastructure (Apps Script, Sheets API) and, for the Chrome extension, in memory in your local browser session. Google user data is never transmitted to, stored on, or logged by any system we control.
- Encryption in transit. All communication with Google APIs uses HTTPS/TLS encryption end-to-end. There is no non-Google network destination in either product.
- Encryption and security at rest. The only data at rest is your own configuration: add-on automation settings are stored in Apps Script Document Properties inside Google's infrastructure (protected by Google's encryption at rest); extension trigger settings are stored in Chrome's extension storage on your own device, protected by your operating system's user account. Neither store contains your spreadsheet contents — only the settings you configured (source/destination references, filters, schedules).
- OAuth tokens are handled by Google. We never see, store, or transmit your Google password. Access tokens are issued, stored, and refreshed by Google's own Apps Script runtime (add-on) or Chrome's identity API (extension) — never by code or systems we operate.
- Least-privilege scopes. Each product requests only the narrowest scopes needed for its user-facing features — the extension requests only the Google Sheets scope, with no Gmail or Drive access at all.
- Limited internal access. Because no Google user data ever reaches us, there is nothing for Metalix personnel to access, and no third party receives Google user data from us.
- Incident response. In the unlikely event of a security issue affecting either product, we will notify affected users via the Chrome Web Store / Google Workspace Marketplace listing and this website, and can be reached at support@metalix.in.
CopydoWell's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. CopydoWell does not use any Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
What we do not do (in the products)
- We do not operate any backend server that receives, stores, or logs your spreadsheet or email data.
- We do not sell, rent, or share your data with third parties, beyond the payment processing described above.
- We do not use your data for advertising or profiling.
- We do not access spreadsheets you have not explicitly opened the product in or provided a link/ID for.
Data retention
Neither product transmits your spreadsheet or email data to any server we operate, so there is no off-Google, off-browser copy for us to retain. Add-on automation settings live in Apps Script's Document Properties inside your Google account; extension triggers live in your browser's local storage. Both persist until you remove the product or clear them yourself.
Your choices
You can revoke either product's Google access at any time via your Google Account permissions page. Uninstalling removes its menus/sidebar/side panel and any triggers it created.
Changes to this policy
We may update this policy as either product evolves. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy or either product's data practices can be sent to support@metalix.in.