Security & Privacy

LetMeTakeCare asks for access to your Smartsheet account, so you are entitled to know exactly what that access is used for and what happens to your data. This page answers that in plain English — no vague assurances, no “industry-standard security” filler.

Last updated 8 August 2026

The short version

  • Your sheet data is never stored. Sheets are read to build a preview, changes are written back, and the contents are discarded when the request ends. Nothing from your sheets is saved to our database.
  • Uploaded spreadsheets are never kept. An uploaded .xlsx is processed in memory and the updated copy is streamed straight back to your browser. A larger upload is briefly buffered to a temporary file while it is being received, which is deleted when the request ends.
  • Your access token is encrypted and held server-side. It is never placed in your browser, and it is deleted the moment you log out.
  • Logging out revokes the token at Smartsheet. Not just locally — the token stops working entirely.
  • We store very little: your email address and display name, and a per-day counter of how many bulk write operations you have run.

1. Which Smartsheet permissions we ask for, and why

When you connect, Smartsheet shows you a consent screen listing the permissions below. The consent screen is served by Smartsheet, not by us — we never see your Smartsheet password, and we cannot grant ourselves a permission you did not approve.

Smartsheet’s permissions are granular rather than hierarchical: each one grants exactly the capability it names and nothing more. The names in the table below are Smartsheet’s own, defined in their OAuth documentation — so you can check our explanations against the source rather than taking our word for it. Smartsheet documents 18 scopes in total; we request six.

One prerequisite before any of this: connecting requires a Smartsheet plan that includes API access — currently Business, Enterprise or Advanced Work Management. Smartsheet’s Pro and free plans cannot authorise third-party API applications, so LetMeTakeCare has no way to connect to them. This is Smartsheet’s own restriction, stated in their API introduction.

Smartsheet OAuth permissions requested and their purpose
PermissionWhat it lets us doWhy it is needed
READ_SHEETS Read the contents of sheets you have access to Every tool previews before it changes anything. Reading is how the dry run shows you the exact before/after and the row counts.
WRITE_SHEETS Change cell values and delete rows The actual work: applying a find & replace, filling looked-up values, removing duplicate or empty rows.
CREATE_SHEETS Create new sheets Tools that produce a new sheet rather than editing yours — the merge target, the generated bank-holiday sheet, and the finance ledger.
ADMIN_SHEETS Modify a sheet’s columns Column-level operations that cell access cannot perform: renaming columns and updating a dropdown column’s list of options.
ADMIN_WORKSPACES List and organise workspaces and folders Browsing your workspaces so you can pick which sheets a tool runs against, and creating the folder a generated sheet is filed into.
SHARE_SHEETS Change who a sheet is shared with Used only by the Sharing Auditor when you explicitly choose to revoke a share or downgrade an Editor to Viewer. Reading the audit needs no such permission.

Two optional user-management permissions

READ_USERS lets us list the users in your Smartsheet organisation, while ADMIN_USERS lets a System Admin remove a selected user from a selected plan. Neither is part of the standard connection. They are requested together only if you opt in to User Management, which requires a separate consent screen.

What the write permission is used for: only the explicit “Remove from plan” action. We do not add users, create groups, or access your Smartsheet account settings.

2. Is your OAuth token stored, and how is it protected?

Yes, it is stored — it has to be, or you would have to re-authorise on every single click. Here is precisely how:

  • It is held on our server, not in your browser. The token lives in our Redis store. Your browser only ever holds an opaque random session id that means nothing on its own and cannot be turned back into a token.
  • It is encrypted before it is stored. The token is encrypted with Fernet (AES-128-CBC with an HMAC signature) before it is written. Someone who obtained a dump of the database would not get usable tokens out of it.
  • It expires automatically. The stored token is deleted 30 days after it is issued, whether or not you log out.
  • It can be revoked instantly. Because the token is server-side, deleting it immediately kills access for every device — something a token kept in a browser cookie could never guarantee.
  • Your login session is separate and shorter. The session cookie is valid for 12 hours of inactivity, and is set HttpOnly (unreadable by JavaScript), Secure (HTTPS only), and SameSite=Lax (not sent on cross-site requests).

Smartsheet access tokens expire after about seven days — 604,799 seconds, per Smartsheet’s OAuth documentation. Rather than forcing you to reconnect every week, we store the accompanying refresh token — encrypted the same way — and use Smartsheet’s standard refresh grant to renew the access token transparently in the background.

3. Are your sheet contents stored, or processed transiently?

Transiently. Sheet contents are never written to our database.

The lifecycle of a bulk operation is: you pick the sheets, we fetch them from Smartsheet over HTTPS, compute the preview in memory, show you exactly what would change, and — once you confirm — write the changes back to Smartsheet. When the request finishes, the sheet data is gone from memory. There is no copy, no cache of your cell values, and no backup on our side.

The one thing that outlives the request is a job status record. Because a large bulk apply runs in the background, we keep a small record so your browser can poll for progress. It holds counts, status and the Smartsheet row IDs the operation touched — how many rows were written, whether the job finished, and any error message. No cell values are kept in it: the before/after examples you see in the preview are computed in memory for that screen and are deliberately dropped before the record is saved. It is deleted automatically one hour later.

The read-only audit tools are the one exception, and deliberately so. A sharing audit, published-items audit, workflow inventory or user list exists to tell you who has access to what — so its findings, including collaborator names, email addresses and the names of the sheets involved, are what the job record has to hold for your browser to collect them. The Health Check keeps less: counts per check, and the names of at most a handful of affected sheets or reports per finding — never collaborators, publication links or cell contents. Nothing is written that you were not already being shown, it is never combined with anything else, and it expires on the same one-hour timer.

A support snapshot (the file you can generate at /support to attach to a support request) is built on demand and not stored at all: it holds build and job identifiers, statuses, counts and timestamps, and never cell values, names, email addresses, links or tokens. You see the exact file before you download it, and only you decide who receives it. If you choose to share it by Diagnostic ID instead, that exact document is stored encrypted for 7 days so that LetMeTakeCare Support can open it; every read is recorded and shown to you, you can revoke it at any time, and logging out deletes every snapshot you have shared.

The public Smartsheet support-request builder is separate from these snapshots. Its form and generated report stay in this page's memory: the builder does not send them to our server or to Smartsheet, save a draft in browser storage, or upload files. You choose what to copy, download and share. Reloading or leaving can lose your draft. Descriptions and links may contain sensitive information, so review the report before sharing it. Site display preferences are stored separately and contain no report content.

The Sheet Backup tool works the same way: the zip containing data.csv, comments and attachments is assembled entirely in memory and streamed to your browser. We never keep a copy.

4. What happens to uploaded Excel and CSV files?

When you use Sync to Excel, your workbook is read into memory, updated there, and the result is streamed back to you as a download. We never store your workbook — there is no uploads folder, nothing is written to our database, and no copy is kept once the response has been sent.

One detail we would rather state plainly than round off. Uploads arrive as a stream, and the web framework buffers each one while it is being received: small files stay in memory, and anything over about 500 KB is buffered to a temporary file instead, so that a large upload cannot exhaust the server's memory. That temporary file is unnamed from your point of view, is never moved anywhere durable, is not readable by any other request, and is deleted when the request finishes — including when the sync fails partway. We previously described uploads as never touching disk; that was true of how we process your workbook, but not of how it is received, so we have corrected it.

File attachments are the one case that briefly touches disk. When you attach a file to a Smartsheet row through our uploader, the file is written to a temporary location purely because the Smartsheet upload API requires a file handle, and it is deleted immediately once the upload completes — including if the upload fails.

5. What we actually store, and for how long

The complete list. If it is not in this table, we do not keep it.

Data stored by LetMeTakeCare and its retention period
WhatWhyKept for
Email address and display name Identifies your account. Taken from your Smartsheet profile when you first connect. Until you ask us to remove it
Smartsheet access & refresh token Lets tools act on your behalf without re-authorising every click. Encrypted. Deleted on logout; auto-expires after 30 days
Login session Keeps you signed in between pages. 12 hours of inactivity
Daily activity counter A per-day count of bulk write operations, enforcing the fair-use limit. A number and a date — not a record of what you did. Rolling daily counter
Background job status Progress and result counts so your browser can poll a running bulk job. For the read-only audit tools this also holds the audit's findings — collaborator names, emails and asset names — because those findings are the result being collected. 1 hour, then deleted automatically
Support snapshot you chose to share Only if you tick the consent box on the support page: the exact snapshot you previewed (build and job identifiers, statuses, counts, timestamps — never contents, names, emails, links or tokens), stored encrypted so support can open it by Diagnostic ID. Each read is recorded and shown to you. 7 days; revoke any time; deleted on logout
Scratchpad save receipts Sheet and row IDs, completed-upload indexes, and a request digest prevent duplicate notes during retries. No note text or attachment contents are stored in the receipt. 13 hours after the last receipt update; retry tokens expire after 12 hours
Server logs Diagnosing errors. Bulk job logs record counts, durations and outcomes — deliberately never cell values. Per our hosting provider’s retention
Your sheet contents Not stored at all —
Uploaded spreadsheets Not stored at all —
Payment details Never collected —

6. AI features and your data

A small number of optional features use an AI model: the scratchpad’s rewrite, summarise and tag-suggestion actions, the dashboard copilot, and the weekly report generator. When you trigger one of these, the relevant text is sent to our AI provider (Google’s Gemini via Google AI Studio, or OpenRouter, depending on configuration) to generate the response.

This matters, so to be explicit: the bulk Smartsheet tools do not use AI and send nothing to any AI provider. Find & Replace, Remove Duplicates, Cross-Sheet Lookup, Clean Up Sheets, Rename Columns, Merge Sheets, Sharing Auditor, Sheet Backup and Sync to Excel are all ordinary deterministic code. AI is only ever involved in the features named above, and only when you actively invoke them.

7. Who else your data passes through

We run on hosted infrastructure rather than our own hardware. The providers involved are:

  • Smartsheet — your data’s actual home; we are a client of their API. Their handling of it is governed by their own Privacy Notice, and their security posture, certifications and compliance programmes are documented in the Smartsheet Trust Center.
  • Heroku — hosts the application and the Redis store holding encrypted tokens and job records.
  • Appwrite — stores the account record (your email address and display name).
  • Google AI Studio / OpenRouter — only for the AI features described above.
  • Google Fonts — serves the web font used across the site.

We do not sell your data, share it with advertisers, or use it to train any model. The site runs no advertising trackers and no third-party analytics.

8. Encryption in transit and at rest

In transit

Every connection is HTTPS. The site sends an HSTS header with a one-year duration covering all subdomains, which instructs your browser to refuse to connect over plain HTTP even if a link tries to. All calls to the Smartsheet API are likewise made over HTTPS.

At rest

Your Smartsheet tokens are encrypted with Fernet (AES-128-CBC plus an HMAC signature that detects tampering) before they are written to storage. Since your sheet contents and uploaded files are never written to storage at all, there is no data-at-rest question for them to answer.

The application also sets a strict Content Security Policy, and a nonce-based script policy that blocks injected scripts from executing — the defence that matters most for a tool holding an API token.

9. What disconnecting actually does

Clicking Log Out performs four distinct actions, in this order:

  • Revokes the token at Smartsheet. We call Smartsheet’s token revocation endpoint, so the token stops working immediately and permanently — not merely on our side.
  • Deletes the stored token from our Redis store.
  • Destroys the server-side session held by Appwrite.
  • Clears the session cookie in your browser.

Afterwards, LetMeTakeCare has no means of reaching your Smartsheet account. Reconnecting requires a fresh trip through Smartsheet’s consent screen.

You do not have to take our word for it

You can revoke our access from your own side, without involving us at all. In Smartsheet, go to Account → Apps & Integrations, find LetMeTakeCare, and select revoke — Smartsheet documents the process in Review, manage, and sign in to apps and integrations. That cuts off access at the source, which is the guarantee that matters: it does not depend on us behaving correctly.

What logging out does not do: it does not undo changes already applied to your sheets — those are real edits in Smartsheet, and you should use Smartsheet’s own cell history to revert them. It also does not delete your account record (your email address and display name); see below.

10. Deleting your data

Most of what we hold removes itself. Logging out revokes and deletes your token; job records expire within the hour; scratchpad retry receipts expire 13 hours after their last update; sessions lapse after 12 hours; sheet contents and uploaded files were never kept in the first place. Logging out therefore removes essentially everything that matters.

What remains is the account record — your email address and display name — and your activity counter. There is currently no self-service delete button for these. To have them erased, contact us using the details below and we will remove them. If you would like confirmation once it is done, say so in your message and we will reply.

11. Who operates LetMeTakeCare

LetMeTakeCare is built and operated by Daniel, an independent developer based in the United Kingdom. It is not a venture-backed company and has no staff beyond its developer — which is precisely why this page spells out the technical specifics rather than gesturing at a compliance department.

In data-protection terms, that developer is the data controller for the small amount of personal data described in section 5. If you are in the UK or the EU, you have the right to access, correct, or request erasure of that data, and to complain to your data protection authority — in the UK, the Information Commissioner’s Office.

12. Contact

For any question about security, privacy, or data deletion — or anything else — use the contact form. It reaches the developer directly. Please say if your message concerns privacy or security so it can be prioritised.

If you believe you have found a security vulnerability, please report it through the same form with enough detail to reproduce it, and allow a reasonable window for a fix before disclosing it publicly. Reports made in good faith are welcome and will not be met with legal threats.

13. Terms of use

LetMeTakeCare is provided as-is, without warranty. The bulk tools make real, immediate changes to your Smartsheet data, which is why every one of them shows a preview before it writes and why we recommend running the Sheet Backup tool before a large operation. You remain responsible for the changes you choose to apply, and Smartsheet’s own cell history is the authoritative record for reverting them.

We may suspend access that abuses the service — for instance attempting to bypass the fair-use limits on bulk write operations. Your use of Smartsheet itself remains governed by your own agreement with Smartsheet, to which we are not a party.

As a third-party application built on the Smartsheet API, LetMeTakeCare is also bound by Smartsheet’s Developer Agreement, which sets requirements on developers for data security and the handling of end-user information. That is an obligation we owe to Smartsheet in addition to the commitments made on this page.

This page is the current, authoritative statement of how LetMeTakeCare handles your data. Material changes will be reflected here along with the revision date at the top.

14. References

Every technical claim on this page can be checked against Smartsheet’s own documentation. If anything here contradicts these sources, trust them and tell us so we can correct it.

LetMeTakeCare is an independent third-party application. It is not affiliated with, endorsed by, or operated by Smartsheet Inc., and linking to their documentation above does not imply otherwise.

Ready to connect?

You will see Smartsheet’s own consent screen listing exactly the permissions described above.

Connect Smartsheet