Product-specific privacy disclosure

Privacy Policy

OilPriceAPI for Google Sheets™

Last updated: July 29, 2026

Plain-language summary

  • The add-on works only in the spreadsheet where the user opens it; it does not request broad Google Drive access.
  • It reads only inputs needed for a user-invoked feature and writes requested OilPriceAPI results, formulas, or conversion tables to the current spreadsheet.
  • It sends the user's OilPriceAPI key and requested market identifiers or filters to api.oilpriceapi.com over HTTPS. It does not send general spreadsheet contents.
  • The sidebar never reveals a stored API key. The user can remove the stored key and request diagnostic with “Delete API Key.”

1. Who operates the add-on

OilPriceAPI operates OilPriceAPI for Google Sheets™ (the “Add-on”). Questions about this policy or the Add-on can be sent to [email protected].

This disclosure supplements the general OilPriceAPI privacy policy for the product-specific behavior described below.

2. Google permissions and user data

spreadsheets.currentonly

This permission lets the Add-on work only in the spreadsheet where it is open. When the user invokes a feature, the Add-on can read user-selected inputs required for that feature, such as market identifiers or add-on-generated data rows, and can write requested market-data tables, formulas, formatting, and conversion outputs. It does not grant broad access to files in Google Drive.

script.container.ui

This permission displays the Add-on menu, API-key sidebar, price-selection dialog, informational alerts, and recovery messages inside the current spreadsheet.

script.external_request

This permission allows the Apps Script runtime to send HTTPS GET requests to api.oilpriceapi.com for data explicitly requested by the user. It does not itself grant access to Google profile, identity, Drive, or spreadsheet data.

Default identity scopes

Google may display default email and profile identity scopes in the Cloud configuration. The Add-on does not use the email or profile scopes for product behavior and does not read, store, or transmit a user's Google account email, name, profile photo, or profile details.

3. Other data the Add-on processes

  • OilPriceAPI API key: provided by the user and stored in Apps Script document properties associated with the current spreadsheet. The Add-on returns only whether a key is configured, never the stored value.
  • Requested market identifiers and filters: values the user supplies through formulas, the sidebar, or dialogs to identify the requested OilPriceAPI dataset.
  • Market-data responses: requested records, timestamps, units, source fields, and freshness fields returned by OilPriceAPI and written to the current spreadsheet or held in short-lived Apps Script user cache.
  • Request diagnostic: endpoint path, outcome code, HTTP status when available, duration, request identifier when available, and timestamp. Diagnostics exclude the API key and query string.

4. How data is used

The Add-on uses the data described above only to:

  • perform the formula, table, or conversion action the user requested;
  • authenticate the request to the user's OilPriceAPI account;
  • write the requested result and source context to the current spreadsheet;
  • reduce duplicate calls with short-lived cache entries; and
  • provide actionable diagnostics and recovery messages.

OilPriceAPI does not use Google user data for advertising, retargeting, sale to data brokers, creditworthiness or lending decisions, or training general-purpose machine-learning or artificial-intelligence models.

5. Data transfers and service providers

Google hosts the Apps Script runtime, document properties, and short-lived cache used by the Add-on. Google's own terms and privacy policy govern those services.

OilPriceAPI receives the user's API key and the reviewed market identifiers or filters required for the requested endpoint. It does not receive general spreadsheet contents, unrelated cells, Google profile data, or Google account email from the Add-on.

OilPriceAPI does not sell Google user data or transfer it to advertising platforms, data brokers, or information resellers.

6. Storage, retention, and deletion

  • The API key and minimal diagnostic remain in Apps Script document properties until the user chooses “Delete API Key,” replaces the key, or deletes the spreadsheet.
  • “Delete API Key” removes both the current-spreadsheet API key and the stored request diagnostic. It also removes a legacy user-property key if one exists from an older release.
  • Cached market responses expire automatically according to the short cache period configured for each requested dataset.
  • Results written into spreadsheet cells remain in the user's spreadsheet until the user clears or deletes those cells or sheets.

Uninstalling the Add-on does not guarantee that Apps Script document properties or generated cells are immediately removed. Users who want to remove the stored API key should choose “Delete API Key” before uninstalling.

7. Google API Services User Data Policy

OilPriceAPI's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Security

  • Requests to OilPriceAPI use HTTPS.
  • The API key is sent in the Authorization header, not a URL.
  • Generic requests are restricted to a reviewed endpoint catalog and reject credential-shaped query parameters.
  • The sidebar clears the input after saving and never displays the stored API key.

9. User choices and contact

Users can stop processing by not invoking Add-on actions, remove the stored key and diagnostic with “Delete API Key,” clear generated cells or sheets, and uninstall the Add-on.

For access, correction, deletion, or privacy questions related to an OilPriceAPI account, contact [email protected].

10. Changes to this policy

Material changes to how the Add-on accesses, uses, stores, or shares Google user data will be reflected here before the changed practice is used. If new Google user data use requires consent, the Add-on will request that consent through the applicable Google authorization flow.