Last updated: 2026. Operated by Harry Fair ("we", "us"). Contact: vser17os@gmail.com.
RefreSync ("the Service") is a Google Workspace add-on that fetches your Meta
(Facebook) Ads data and writes it into your Google Sheets. This policy explains what
data we access, why, and how we handle it.
Information we access
Google account identity — your Google user ID and email address
(via openid and userinfo.email), used only to identify you
and link you to your stored Meta connection.
Google Sheets — the Service writes Meta Ads report data into the
spreadsheets you use it with (the spreadsheets scope). We do not read or
retain the contents of your spreadsheets; we only write the report you request.
Meta (Facebook) Ads data — advertising metrics fetched from the
Meta Marketing API on your behalf and written to your sheet. This data passes through
our service to your sheet and is not retained on our servers.
Your Meta access token — stored so the Service can fetch your
Meta data on your behalf. It is encrypted at rest (Google Cloud KMS) and held only
until you disconnect.
How we use it
Solely to provide the Service — fetching the Meta Ads data you request and writing
it to your chosen sheet. We do not use your data for advertising, we do
not sell or share it, and no human reads your Google or Meta data except
as strictly necessary for support you request, security, or to comply with the law.
Google API Services User Data Policy — Limited Use
RefreSync's use and transfer of information received from Google APIs adheres to the
Google API
Services User Data Policy, including the Limited Use requirements.
Data protection & security
We apply the following safeguards to protect your data, including sensitive data such as
your Meta access token and the Google account data we receive:
Encryption in transit. All traffic between the add-on, our backend,
Google, and Meta is sent over HTTPS/TLS.
Encryption at rest. Your Meta access token is envelope-encrypted with
Google Cloud Key Management Service (KMS) before it is stored in Firestore; the plaintext
token exists only transiently in memory while serving your request.
Least-privilege access. The Service runs on Google Cloud (Cloud Run)
under a dedicated service account holding the minimum IAM permissions required. Application
secrets are kept in Google Secret Manager, never in source code or configuration.
Data minimization. We do not read or retain the contents of your
spreadsheets, and Meta Ads data passes through the Service to your sheet without being
stored on our servers. The Google access token used to write to your sheet is short-lived
and is never persisted.
Access control & isolation. Stored data is keyed to your Google
account and is not accessible to other users. Administrative access is restricted, and no
human accesses your Google or Meta data except as strictly necessary for support you
request, security, or to comply with the law.
Retention & your choices
Disconnect in the add-on to delete your stored Meta connection
immediately. See Data deletion.