Privacy Policy
Effective date: July 10, 2026 · Last reviewed: July 10, 2026
drive.file Google scope, access limited to the spreadsheet this app creates for you,
nothing else in your Drive. We do not keep copies of your individual transactions on our servers.
Bank Statement Genie ("Bank Statement Genie," "the Service," "we," "our," or "us") is a product of Very Big Machine, a software company based in New York. This policy describes what information the Service collects, how we use it, and the choices you have. It supplements, and is governed by, the master Very Big Machine Privacy Policy. Where this product-specific policy and the master policy differ, this policy controls for Bank Statement Genie.
1. What the Service does
Bank Statement Genie connects to your bank or card accounts (through Plaid, a regulated financial-data provider) and writes your transaction history into a Google Sheet that the Service creates in your Google Drive™. It keeps that sheet up to date on a schedule. An optional Google Sheets sidebar add-on acts purely as a launcher and status display; it does not read or write your spreadsheet content.
2. Information we collect and store
We practice data minimization. On our own servers (Google Cloud™ Firestore) we store only what is needed to operate the sync:
| Category | What it includes | Why |
|---|---|---|
| Account identity | Your name and email address from your Google account; a Google OAuth refresh token | To identify you and to write to the Google Sheet™ we created for you |
| Bank connection data | Plaid access tokens, institution name, and account metadata (account names, types, and masked numbers such as "•••• 1234") | To retrieve transactions and label the tabs in your sheet |
| Sync bookkeeping | The ID and URL of your Google Sheet™, a sync cursor, and per-sync log entries (counts of rows added / changed / removed, timestamps, and any error) | To keep the sheet in sync and to diagnose failures |
| Contact messages | The name, email, and message you submit through our contact form | To respond to you |
3. Information we do not store
- Your individual transactions. Transaction details (date, amount, merchant, category, etc.) are written into the Google Sheet in your own Drive. We do not retain a copy in our database. Features such as the spending analytics view read those rows live from your sheet at the time you request them; they are not stored on our side.
- Your bank login credentials. You enter those with Plaid, never with us. We never see or store your online-banking username or password.
- Payment card numbers. If and when paid plans launch, billing is handled by Stripe; we do not receive or store raw card data.
- Any other file in your Google Drive™. The
drive.filescope only grants access to files this app creates or that you explicitly open with it.
4. Google API Services, scopes and Limited Use
Bank Statement Genie requests only these Google scopes, all of which are non-sensitive:
| Scope | Sensitivity | Why we request it |
|---|---|---|
openid, email, profile | Non-sensitive | Sign you in and identify your account |
drive.file | Non-sensitive | Create and update only the spreadsheet this app makes for you |
The optional Sheets add-on additionally uses the non-sensitive script.container.ui,
userinfo.email, and script.external_request scopes to display a sidebar and
identify you to our backend. We do not request the sensitive spreadsheets
(all-spreadsheets) scope, the sensitive or restricted Gmail™ scopes, or full Drive access.
5. Plaid
We use Plaid Inc. to connect your financial accounts and retrieve transactions. When you link an account, the information you provide goes directly to Plaid under Plaid's own End User Privacy Policy. We receive a Plaid access token and transaction data through Plaid's API. Plaid is a sub-processor for the Service.
6. How we use your information
- To authenticate you and operate the transaction sync into your Google Sheet™.
- To send you service messages (for example, a sync-failure notice or a reply to your contact message).
- To secure the Service and diagnose errors.
- To enforce plan limits if you are on a paid plan.
We do not sell or rent your personal information, and we do not use it for advertising.
7. Security
The Service runs on Google Cloud™ Platform and Firebase. Data is encrypted in transit (TLS) and at rest. Access tokens and refresh tokens are stored in access-controlled Firestore, reachable only by our server-side functions, never by the browser or the add-on. For more on our security posture, see the Very Big Machine security overview.
8. Retention and deletion
We keep your account data while your account is active. You can:
- Disconnect a bank at any time from your dashboard, which deletes the associated Plaid access token and stops syncing that institution.
- Revoke Bank Statement Genie's Google access at any time from your Google Account™ permissions page.
- Request full account deletion by emailing us. We delete or anonymize your personal data within 30 days, except where retention is legally required. The Google Sheet in your Drive belongs to you and remains under your control.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. The master Very Big Machine Privacy Policy describes these rights (including GDPR and CCPA/CPRA) and how to exercise them. To make a request specific to Bank Statement Genie, contact us below.
10. Children
The Service is not directed to individuals under 13 (or the age of digital consent in your jurisdiction), and we do not knowingly collect their information.
11. Changes
We may update this policy. When changes are material, we will update the "Last reviewed" date above and, where appropriate, notify you by email.
12. Contact
Questions or requests about this policy or your data:
- Bank Statement Genie, operated by Very Big Machine, New York, United States
- Through our contact form, or by email at [email protected]
- Security reports: [email protected]