Information used to run your workspace
Gatherow stores account details such as your email address and display name, password and recovery-code hashes, session information, and optional authenticator security settings. It also stores workspace membership, project organization, source and table settings, published endpoint settings, usage counters and administrative activity.
When you check or collect a source, Gatherow processes its records and field names. The fields you choose to keep are saved with the source snapshot. Tables, saved versions and available result explanations can also contain data derived from those records. Choose sources and fields that you are authorized to process.
Google Sheets permissions and connections
Google account connections are optional and depend on the service’s Google configuration. A workspace editor or owner can connect an account. Gatherow requests basic Google identity information through openid and email to identify that connection, plus the read-only Google Sheets permission https://www.googleapis.com/auth/spreadsheets.readonly.
This Sheets permission can read spreadsheets the connected Google account can access; it is broader than permission for a single chosen file. Gatherow uses it to inspect the spreadsheet link you provide, list its worksheets and import the worksheet you select. It does not browse and import all of your spreadsheets. The connector requests no Google Drive-wide scope and cannot write changes back to your sheets.
Google access and refresh tokens are encrypted in the application database. They are used on the server to read the selected spreadsheet and renew authorized access for later collections; access tokens are not returned to the browser. Gatherow also saves the connection’s Google account identifier and email address so workspace members can recognize the shared account.
Gatherow’s use and transfer of Google user data comply with the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
You can instead use the public-link option for a sheet already accessible without signing in, or upload an authorized export. You do not need to make a private sheet public to use a configured Google account connection.
Who can use collected data
Workspace owner, editor and viewer roles control administration, editing and inspection within a workspace. Projects organize its sources, tables and APIs; they do not create separate membership roles. A connected Google account is shared across the workspace. Any workspace owner or editor can provide a link and import any spreadsheet that account can read. Connect an account only if those members should have that access. Imported rows for the fields you choose to keep are stored in Gatherow and can be used in the tables and published APIs your workspace chooses.
Publishing an API makes the configured result fields available to holders of an authorized API key. These responses do not include saved connection credentials or internal source evidence. Workspace owners control membership and API-key access; service administrators operate the application and its infrastructure.
Optional AI drafting
When you request AI help and the feature is enabled, Gatherow sends OpenAI your written prompt and clarification answers, source names, saved table names, selected field names and types, and supported configuration and matching structure. The application excludes collected source rows, example record values, connection URLs and credentials. Existing saved filter values are represented by references.
Anything you type into the prompt is part of that request, so leave sensitive record values out of it. OpenAI processes this information to propose a configuration; Gatherow validates the proposal and calculates the data preview locally. Applying, saving and publishing remain separate actions.
Gatherow does not use collected Google Sheets data to train general-purpose AI models. Normal API reads and scheduled collections do not invoke AI.
Storage, saved copies and backups
The service is hosted on DigitalOcean, with daily provider backups enabled. Saved source credentials and Google tokens use authenticated encryption; passwords and API keys are stored as hashes. Collected records and derived results are stored so the application can serve and explain saved results.
Captured source data, derived tables, saved versions and result evidence can remain until the relevant saved objects are deleted. Deleting a connection does not automatically delete data already captured in a source or table, and deleting one object does not necessarily remove copies retained by another.
Deletion from the live application does not immediately erase backup copies. Data may remain in provider backups until those copies expire or are removed. This notice does not specify a fixed backup retention period; contact us if you need help understanding or arranging deletion.
Disconnecting and requesting deletion
You can revoke Gatherow’s Google access in your Google account settings. Revocation prevents future collections that require that authorization; it does not erase records already imported into Gatherow. Public-link sources do not use the Google account grant.
Disconnecting Google in Gatherow removes this workspace’s saved Google credentials and pauses linked sources. Collected data and derived tables stay saved. Connecting an account again does not automatically resume those sources; reconnect and check each source before collecting again. Review saved sources, tables, versions and published APIs separately when deciding which data and access to remove. A workspace owner can help with membership and keys.
For account or data-deletion assistance, contact info@tallinio.com. Describe the account or workspace and the action you need. Do not send passwords, API keys, Google tokens or private datasets in your message.