This Privacy Policy explains what information the Punchlist Chrome extension ("Punchlist", "we", "us") accesses, how it is used, and the choices you have. Punchlist is a tool for pinning review feedback to web pages, where each website you review is backed by a Google Sheet stored in your own Google Drive.
The short version
Punchlist has no servers of its own. Your reviews live in spreadsheets in your Google Drive, and requests go directly from your browser to Google's APIs. We never receive, store, or transmit your data to ourselves or any third party.
Information Punchlist accesses
When you connect your Google account, Punchlist requests the following, and only to provide its features:
Your email address (via the userinfo.email / openid scopes) — shown in the extension so you know which account is connected, and recorded as the owner/creator on reviews you make.
Google Sheets and Drive files that Punchlist creates or that you open with it (drive.file, spreadsheets) — to create each site's review spreadsheet, read and write review items and member lists, and share a review with people you invite.
Read-only Drive metadata (drive.metadata.readonly) — to list Punchlist spreadsheets (including ones shared with you) so you can pick a shared review to join. This is used to read file names and Punchlist's own markers only; it is never used to read the contents of your other files.
How your information is used
To create, read, and update the review spreadsheet for each website you review.
To display which Google account is connected.
To share a review spreadsheet with the teammates you explicitly invite, and to record members and item assignments.
To locate an existing Punchlist review so it reopens automatically across sessions and machines.
Punchlist does not use your data for advertising, profiling, or any purpose unrelated to the features above, and does not sell or transfer it to third parties.
Where your data is stored
In your Google Drive. Review content (items, notes, statuses, member lists) is stored in spreadsheets owned by your Google account. You can open, edit, export, or delete them at any time.
Locally in your browser (chrome.storage). Punchlist keeps a small amount of local state: a cache mapping each site to its spreadsheet, an optional OAuth client ID you may enter, and a short-lived access token used to talk to Google. This never leaves your device except as requests to Google's APIs.
Punchlist operates entirely client-side. There is no Punchlist backend that receives or stores your information.
Sharing
The only parties your data reaches are:
Google, as the provider of the Drive and Sheets APIs that store and serve your reviews, under Google's Privacy Policy.
People you explicitly invite to a review — when you add a member, Punchlist asks Google Drive to share that specific spreadsheet with them.
Google API Services User Data Policy
Punchlist's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Punchlist only uses Google user data to provide and improve its user-facing features, does not transfer or sell it, and does not use it for advertising or to train generalized AI/ML models.
Data retention and deletion
Review content stays in your Drive until you delete it. From Punchlist you can move a review's spreadsheet to the Drive trash; you can also delete or manage these files directly in Google Drive.
Local data is cleared when you sign out, and is removed when you uninstall the extension.
Punchlist communicates with Google exclusively over HTTPS and stores access tokens only in the browser's extension storage. Because your data resides in your own Google account, its security is also governed by your Google account's protections.
Children
Punchlist is not directed to children under 13 and does not knowingly collect information from them.
Changes to this policy
We may update this policy as the extension evolves. Material changes will be reflected here with a new "Last updated" date.