Privacy Policy
This Privacy Policy describes how Protomated ("we," "our," or "us") collects, uses, and protects information when you use the Legal Billing & Time Tracker plugin ("the Service"). The Service connects Claude Cowork to your Google Sheets account so you can manage billable hours, invoices, and trust account records by chat.
1. Google API data we access
When you connect your Google account, the Service requests the following OAuth scopes. We use each scope only for the purpose listed — no broader processing.
-
https://www.googleapis.com/auth/spreadsheets— Read and write billing data (time entries, trust records, invoice status) to the Google Sheet you designated as your billing sheet. We do not read any other spreadsheet. -
https://www.googleapis.com/auth/drive.file— Create a new billing spreadsheet in your Google Drive from our template, if you choose to create one during setup. We access only files created by the Service. -
openid,email,profile— Identify you so we can link your Google account to your billing sheet configuration. We store your email address to confirm identity; we do not use it for marketing.
2. Google API Limited Use disclosure
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the Legal Billing service.
- We do not use Google user data to serve advertisements.
- We do not allow humans to read your Google user data unless you explicitly request support, a security investigation requires it, or we are required by law.
- We do not sell, transfer, or share your Google user data with third parties, except as necessary to provide the Service (e.g., our hosted database) or as required by law.
3. What we store
When you authenticate, we store the following in our private PostgreSQL database, keyed by
your Google user ID (sub):
- Your Google OAuth2 access token and refresh token (encrypted at rest)
- Your Google email address
- The URL and ID of your designated billing spreadsheet
Your billing data itself lives in your Google Sheet — not on our servers. We never copy time entries, invoice records, or trust account data into our database. All reads and writes go directly from our server to your Google Sheet on your behalf, in real time.
4. Data sharing
We do not sell or rent your data. We do not share your information with third parties except:
- Infrastructure providers — our hosted database and server (Dokploy) to store tokens and serve the Service.
- Legal obligation — if required by law or a valid court order.
5. Data retention and deletion
You can remove your data at any time directly from Claude:
- Disconnect Google — say "disconnect Google" in Claude. This revokes our OAuth token and clears your sheet reference from our database. Your Google Sheet and its data are untouched.
- Delete account — say "delete my account" in Claude. This permanently removes your tokens, email, and sheet reference from our database. Again, your Google Sheet is not modified or deleted.
We retain data only for as long as you have an active account. After deletion, data is removed from our database within 30 days.
6. Security
OAuth tokens are stored encrypted. Our server communicates with Google APIs over HTTPS. Sessions are in-memory and expire when you close your Claude conversation — you re-authenticate at the start of each new session via Google's one-click flow.
7. Children's privacy
The Service is intended for attorneys and legal professionals. We do not knowingly collect data from individuals under the age of 18.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the revised policy.
9. Contact
Questions or requests regarding this Privacy Policy: [email protected]
Protomated · protomated.com