Privacy Policy
Effective date: 7 August 2026
HourSync is a Google Sheets™ add-on that imports your Clockify time entries into your own spreadsheet. This page explains exactly what it accesses, why, and what you can do about it.
HourSync is developed and operated by Daniele Barbieri Luigi, an independent developer. Contact: danibarbers13@gmail.com.
The short version. There is no HourSync server and no HourSync database. The add-on runs inside Google Apps Script under your own Google account, calls the Clockify API directly with the key you paste in, and writes the result into the one spreadsheet you opened it in. Your time entries are never sent to us, because there is no "us" for them to be sent to.
Website analytics
The public HourSync website uses Google Analytics 4 to understand aggregate site use and measure clicks from the website to the Google Workspace Marketplace listing. Google receives standard web analytics data such as page views, browser and device information, referral information, approximate location inferred from IP address, and the Marketplace-click event.
This website analytics is separate from the HourSync add-on. It does not collect Clockify API keys, spreadsheet content, imported time entries, or the Google account data used by the add-on. Google processes website analytics data under its own privacy policy; you can limit this collection with your browser's privacy controls or opt out using Google's Analytics opt-out tools.
What the add-on does
HourSync imports your time-tracking data from Clockify into the Google Sheets™ spreadsheet you run it in, creating a tab named Hours. Optional Pro features add filters, a per-project Summary sheet, and a scheduled daily refresh.
What Google user data HourSync accesses
HourSync accesses the following Google user data, and nothing else:
- The content of the single spreadsheet you open the add-on in. Under the
spreadsheets.currentonlyscope, HourSync reads and writes the cells, sheets and sheet names of that one spreadsheet only. It cannot list, open, read or modify any other file in your Google Drive, and it is not able to access your Drive file index at all. - Your primary Google account email address. Under the
userinfo.emailscope, HourSync reads the email address of the signed-in Google account — for examplename@example.com. This is the only identity attribute the add-on reads. - Google profile information: accessed by the platform, not read by HourSync. The consent screen lists the
userinfo.profilescope because the Google Workspace Marketplace platform includes the email and profile scopes by default for every listed add-on. It is not requested in HourSync's own manifest, and the HourSync code contains no call that reads profile data. No name, profile photo, locale, gender, birthday or any other profile attribute is read, used, stored or transmitted. - Your Google account's Apps Script trigger list — Pro only. Under the
script.scriptappscope, HourSync creates and deletes one time-driven trigger belonging to the add-on, and only when you switch the Pro daily refresh on or off. It does not read, modify or delete triggers created by other scripts.
HourSync does not access your Gmail messages, Google Calendar, Google Contacts, Google Drive file list, Google Photos, location data, device identifiers, or any other Google user data of any kind.
How HourSync uses Google user data
Each item of Google user data is used for one purpose only, described below. There is no other processing, and no secondary use.
- The current spreadsheet is used solely to write the time entries imported from Clockify: a sheet named Hours containing one row per time entry, and on the Pro plan a Summary sheet with per-project totals. Existing cells outside those two sheets are not read or altered.
- Your email address is used solely as the lookup key to ask Stripe whether that address has an active HourSync Pro subscription or trial, and to pre-fill the Stripe checkout form so you do not have to retype it. It is not used for marketing, newsletters, profiling or advertising, is not sold, and is not disclosed to anyone other than Stripe for that single check.
- The trigger is used solely to re-run your own import once a day while the spreadsheet is closed, when you have explicitly turned the Pro daily refresh on.
HourSync does not use any Google user data to develop, improve or train generalized artificial intelligence or machine learning models. No Google user data is used for advertising, resale, credit scoring, or any purpose other than providing the features described on this page.
Clockify data
Separately from Google user data, HourSync handles data you hold in Clockify:
- Your Clockify API key. You paste it in yourself, into a masked field. It is stored using Google Apps Script's Properties Service (user properties), which keeps it tied to your own Google account on Google's infrastructure. It is never transmitted to or stored on any server we control. It is used only to call the Clockify API on your behalf, to read your workspaces, projects and time entries.
- Your Clockify time-tracking data. Time entries, project names, durations, start and end times and billable status are fetched from Clockify and written into your Google Sheets™ spreadsheet, under your Google Account™. No copy is kept anywhere else.
Every OAuth scope HourSync requests
These are all of them. Google shows you this list on the consent screen before you install; you can compare it line by line.
| Scope | What it allows | Why HourSync needs it |
|---|---|---|
spreadsheets.currentonly |
Read and write only the spreadsheet the add-on is open in | To write the imported rows into the Hours sheet, and the Summary sheet on Pro. It cannot reach any other file. |
script.container.ui |
Display third-party web content in prompts and sidebars inside Google applications | To draw the HourSync panel in the sidebar of your spreadsheet. That panel is the entire interface. |
script.external_request |
Connect to an external service | To call the Clockify API for your data, and the Stripe API to check your subscription status. |
script.scriptapp |
Allow the script to run automatically when you are not present | Only for the Pro daily refresh, which updates your hours once a day even when the spreadsheet is closed. |
userinfo.email |
See your primary Google account email address | Sent to Stripe solely to check whether that address has an active Pro subscription. |
userinfo.profile |
See your personal info, including any personal info you have made publicly available — shown on the consent screen as “See your profile info” | Added automatically by the Google Workspace Marketplace platform, which includes the email and profile scopes by default for every listed add-on. It is not requested in the add-on's own manifest, and HourSync does not read, use or store any profile data — the only identity call in the code reads your email address, for the subscription check described above. |
HourSync deliberately does not request full Google Drive access, full Spreadsheets access, Gmail, Calendar or Contacts. Three of the scopes above — script.container.ui, script.external_request and script.scriptapp — are classified by Google as sensitive scopes. HourSync requests no restricted scopes. The protections that apply to sensitive data are described in the next section.
How HourSync protects your data
These are the concrete measures that protect the Google user data and sensitive-scope access described above.
- No HourSync server and no HourSync database. This is the primary protection: there is no central store of user data that could be breached, leaked or subpoenaed. The add-on's code runs inside Google Apps Script, under your own Google account, on Google's infrastructure. Your time entries, your spreadsheet contents and your email address never reach any machine operated by the developer.
- Encryption in transit. Every network call the add-on makes is HTTPS with TLS. The only two external hosts contacted are
api.clockify.meandapi.stripe.com, both of which are HTTPS-only. No data is ever transmitted over an unencrypted connection. - Encryption at rest and isolated storage. The only values HourSync stores are your Clockify API key and your add-on settings. They are held in the Apps Script Properties Service under user properties, which stores them on Google's infrastructure — where data is encrypted at rest — scoped to your own Google account. Another user of the add-on cannot read them, and neither can the developer.
- Least privilege. HourSync requests the narrowest scope that makes each feature possible. It uses
spreadsheets.currentonlyinstead of the full Spreadsheets or Drive scope, so access is technically limited by Google to the one document you opened, rather than limited only by our promise not to look. - Credential handling. Your Clockify API key is entered into a masked input field, is never displayed again after entry, is never written into the spreadsheet, and is never logged. It can be cleared from within the add-on at any time.
- No analytics, no tracking, no third-party SDKs. The add-on contains no analytics library, no tracking pixel, no advertising identifier and no error-reporting service. No usage data about you is collected.
- Sensitive-scope discipline.
script.external_requestis restricted in code to the two hosts named above.script.container.uiis used only to render the add-on's own sidebar.script.scriptappcreates exactly one time-driven trigger, only on explicit user action, and deletes it when the feature is switched off. - Access is revocable at any time, by you. Removing HourSync at myaccount.google.com/permissions immediately and permanently ends all access to your Google account. Deleting the API key inside Clockify immediately ends all access to your Clockify data.
- Limited personnel access. HourSync is developed and operated by one named individual. Because no user data is ever stored outside your own Google account, there is no dataset for any employee, contractor or subprocessor to access — the question does not arise.
Limited Use disclosure
HourSync's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Payment data
Pro subscriptions are processed by Stripe, Inc. Card and billing details are entered on Stripe's own checkout page and handled by Stripe under Stripe's privacy policy. Your full card details are never seen or stored by HourSync. The only thing kept is Stripe's yes-or-no answer about your subscription, cached briefly inside your own Google account so the add-on does not have to re-ask on every click.
Data sharing
Your data is not sold, and not shared with third parties except:
- Clockify (COING Inc.) — API calls made with your own key, to fetch your own data.
- Stripe, Inc. — your email address for subscription verification, and payment processing when you upgrade.
- Google LLC — the add-on runs on Google's platform and stores its settings there.
- Google LLC (Google Analytics). The public website sends the website analytics data described above, including Marketplace-click events.
Data retention and deletion
No Google user data is retained by HourSync. Your spreadsheet content is read and written in memory during a single run and is never copied elsewhere. Your email address is held only for the duration of the Stripe subscription check; the only thing kept afterwards is Stripe's yes-or-no answer, cached briefly inside your own Google account so the add-on does not have to re-ask on every click.
The only values stored at all are your Clockify API key and your add-on settings, in your own Google account. They stay there until you clear them in the add-on or uninstall it; uninstalling removes the add-on's stored properties for your account. You can delete everything yourself at any moment, without contacting us, by clearing the key in the add-on and revoking access at myaccount.google.com/permissions.
Any rows already written into your sheet stay in your sheet, under your control — nothing is deleted, and the spreadsheet keeps working even if HourSync disappears tomorrow.
Your choices
- Clear your Clockify API key at any time from within the add-on, or uninstall the add-on.
- Revoke the add-on's access to your Google account at myaccount.google.com/permissions.
- Delete the API key in Clockify under Preferences → Advanced → Manage API keys.
- Cancel Pro at any time from the link in your Stripe receipt; your data remains yours.
Children
HourSync is a tool for professional time tracking and is not directed at children under 16.
Changes to this policy
This policy may be updated from time to time. The effective date above always reflects the current version.
Contact
Daniele Barbieri Luigi — danibarbers13@gmail.com
Via Cavour 43, 18039 Ventimiglia (IM), Italy