What reviews have found

Every review of the script so far and every finding, including the ones that were wrong and the ones that were true and left alone. Nothing is removed. A wrong finding stays with the reason, because it will be raised again.

findings
33
true and fixed
24
true and kept
6
wrong
3

7 reviews·5 September 2026·versions 4.5 to 4.8 in one day

Showing 33 of 33

Round 15 September 2026, morning·ChatGPT, run by the founder

Blotter had just been posted to r/UTAustin and the first substantive comment was a security objection. The founder pasted the published script into ChatGPT and asked whether the code matched the website. It had only the script, not the permissions file, which explains the one thing it got wrong.

1.1

The whole calendar was being sent, not just events with your contacts.

The script read every event on your calendar, a year back and six months ahead, and sent all of them to the server: titles, times and everyone invited. The server used the few that involved your contacts and threw the rest away, but the rest had already left your account. The website said, in two places, that the server receives events with your contacts.

Fixed in codeVersion 4.5Raised by ChatGPT

Events are now filtered inside your sheet, before anything leaves. This was the finding that made the audit page exist.

1.2

Five values from the server reached your sheet without a formula check.

A cell that begins with = is a live formula. The server's answers were guarded against that in most places and not in five of them.

Fixed in codeVersion 4.5Raised by ChatGPT

All five guarded. The guard had to be made aware of dates, because the simple version turned them into text and broke the Next call column.

1.3

The script's header said a failed run writes nothing. It can stop partway.

Once writing has begun, a failure leaves the sheet part-updated. The next run finishes the job, but the header claimed more than that.

Fixed in wordingRaised by ChatGPT

The header now says what happens.

1.4

The privacy page called its list of what is sent complete, and it was not.

It left out the row number of each contact and the addresses you had rejected on the Found tab.

Fixed in wordingRaised by ChatGPT

Both added.

1.5

The terms said Blotter was not open to other people.

It was, by then.

Fixed in wordingRaised by ChatGPT

Removed.

1.6

The Gmail permission is full mailbox control.

The reviewer guessed the permission was https://mail.google.com/, which would let a script send, delete and change mail.

WrongRaised by ChatGPT

It is gmail.readonly, which cannot send, delete or change anything. The reviewer had only the script and not the permissions file, and a script that searches mail looks like a script that needs more. That is why every audit package now includes the permissions file, and why the Code page prints it.

Round 25 September 2026, afternoon·Four AI reviews we ran ourselves, on Claude

Run with the exact package the audit page puts on your clipboard, each given only what a stranger gets. Four separate sessions on two models, each asked in a different way. All four led with the same finding.

2.1

The switch for turning off usage counting did not turn it off.

The Settings cell says 'Clear this cell to switch it off.' Clearing it stopped counting on runs that worked. Runs that failed were still counted, to the default address, forever.

Fixed in codeVersion 4.6Raised by Two of four reviews

Both paths now read the same cell. Sixteen automated checks make sure it stays that way.

2.2

The counting address was not checked at all.

The main server address was required to start with https. The counting address was not, so a value in that cell could have sent counts anywhere, unencrypted.

Fixed in codeVersion 4.6Raised by One review

Counting can now only be sent to blotterib.com over https. Blank still means off.

2.3

Setting up the sheet added a formatting rule every time and never removed one.

Every Step 1 left another identical rule behind. A sheet set up a dozen times carried a dozen copies, which is slow and eventually hits Google's limit.

Fixed in codeVersion 4.6Raised by One review

It removes its own rule before adding it.

2.4

Calendar events with no contact on them were still being sent.

After the first fix, an event was sent if any word in its title matched a contact's first name. Track someone called Sam and 'Dinner with Sam' left your account, with its full guest list, for the server to discard. A contact typed in as 'The Blackstone team' put the word 'the' on the match list and sent nearly the whole calendar.

Fixed in codeVersion 4.8Raised by All four reviews

The sheet now runs exactly the same test the server does: the first name and the firm both have to appear in the title. A test runs both versions of the rule over 280 name-and-firm pairs and fails if they ever disagree.

2.5

The sheet's own diagnostics said Blotter is never given your email address.

Blotter → Check this sheet printed that your name and email address are never given to Blotter. Your addresses are sent on every run; that is how it tells your messages from theirs.

Fixed in wordingVersion 4.8Raised by Two reviews

The sentence now says what is true: the Blotter ID is a random number made from nothing about you, and Blotter does have the addresses you typed into Settings. It never has your password.

2.6

Where your sheet sends data is an ordinary cell, and nothing showed it.

Settings → Server URL was checked only for starting with https. Setting up the sheet did not reset it, handing a sheet on did not clear it, and nothing in the sheet displayed it. Blotter is passed round by copying a sheet.

Fixed in codeVersion 4.8Raised by Three reviews across two rounds

Blotter → Check this sheet now shows 'Sends to:' with the address, and says so plainly if it is not blotterib.com. The founder chose to show it rather than lock it, so a sheet can still be pointed at a test server on purpose.

2.7

'Every 15 minutes' was wrong for nine hours a day.

Between 10pm and 7am the script checks every two hours. The menu said so. The script header and the privacy page did not.

Fixed in wordingRaised by Two reviews

Both now say every 15 minutes through the day and every two hours overnight.

2.8

The sheet can be restyled remotely, and nothing disclosed it.

When the server says a new design exists, the sheet fetches it. That can change colours and widths, and it can rewrite the text of the Start here tab, including the part that describes what Blotter can see. Nothing about you goes out on that connection.

Fixed in wordingRaised by Two reviews

Disclosed on the audit page as one of the things we already know. The description you read inside your sheet is something we can change, and the code cannot promise otherwise.

2.9

The bounce exception was described more narrowly than it works.

The site said the one email Blotter opens is a delivery-failure notice from Google's mail system, and that only the address travels. The check is on the sender's name before the @ being mailer-daemon or postmaster, at any company, and every address found in the notice travels, not one.

Fixed in wordingRaised by Two reviews, and two more in round 3

The wording now says 'a mail system' and 'the addresses it finds'. The code stays as it is on purpose: a real bounce comes back from the recipient's mail server, not from Google, so restricting it to Google would break the Bounced status for every address at a company that does not use Google's mail.

2.10

The list of what is sent was still not complete.

Missing: your own email addresses, the sheet's random id, the Blotter key, which row a contact is on, whether Closed is ticked, Gmail's own reference numbers, who organised an event, and who declined it.

Fixed in wordingRaised by Three reviews

The privacy page's third step now lists all of it. The Code page publishes the full shape, field by field, and the Status page links to it.

2.11

Whole conversations are read, and nothing said so.

One message involving a contact pulls every message in that conversation. Somebody else copied in has their name, address and the subject line read and sent, even though they are not one of your contacts.

Fixed in wordingRaised by All four reviews

The privacy page and the audit page now say it. The wording in the script's own header is still being decided.

2.12

'Blotter never touches a conversation that does not involve one of your contacts.'

False for calendar at the time, and 'touches' was doing more work than the code could defend for mail.

Fixed in wordingRaised by All four reviews

Now 'never opens'. Weaker on purpose: opens is what the code does.

2.13

'Delete the spreadsheet and nothing of yours is left anywhere.'

The counting rows, a random id with run times and contact counts, outlive the sheet by design and are disclosed two paragraphs earlier.

True, keptRaised by Three reviews

Left as it is. The counting rows are disclosed in the same section, and none of them identifies a person.

2.14

'There is no third party in the middle.'

Read plainly, blotterib.com is a party in the middle. The sentence meant no connection provider, and the next paragraph said so, and two reviews still tripped on it.

Fixed in wordingRaised by Two reviews

Now 'There is nobody else in this but Blotter. No connection provider, no data broker, no other company handling your mail on the way through.'

2.15

'Every one of them is read-only apart from the spreadsheet.'

Two of the five permissions are not permissions on your data at all, and one of them is precisely what lets data leave your account.

Fixed in wordingRaised by One review

The privacy FAQ now names all five and what each one is for. The first draft of the audit page had made the same mistake and was corrected the same afternoon.

2.16

'Your recruiting information lives in one place: your own spreadsheet.'

It travels to the server every run. Whether it is kept there cannot be proven; that it travels can be.

Fixed in wordingRaised by One review

Now 'is kept in one place', with a sentence saying the facts go to the server to be worked out and are not kept there.

2.17

'It writes only to Blotter's own columns, never to a cell you typed in.'

When you tick Add? on the Found tab, Blotter writes a name and an email into the Name and Email columns, which are yours. Setting up the sheet also sets the font and row heights across your columns.

Fixed in wordingVersion 4.8Raised by Two reviews

The header now says it never changes something you typed, fills its own columns, adds a row when you ask, and standardises font and row height throughout.

2.18

A refused run writes one line before it stops.

If the server refuses a run and sends a reason, the reason is written to the banner at the top of the Contacts tab. The header says a run that fails before writing leaves the sheet untouched.

True, keptRaised by One review

Left as it is. The one thing written is the notice telling you why, and nothing of yours is touched. The founder judged the sentence is about your data and is true of it.

2.19

Use Google's headers-only Gmail permission instead.

There is a narrower Gmail permission that returns headers only and refuses bodies at Google's end. Using it would make 'cannot read the text' a limit Google enforces rather than a promise.

WrongRaised by One review

That permission forbids search queries, and searching for your contacts' addresses is the entire mechanism. There is no narrower permission that works. This one will be raised again by every reviewer who knows the permission exists, which is why the privacy FAQ now explains it.

2.20

Handing a sheet on leaves the old owner's id behind.

The Clear-to-hand-on step blanks the id from the Settings tab but not from the script's own stored properties, so the next owner's runs would use the same id.

WrongRaised by One review

The script's own storage belongs to the script attached to that one spreadsheet. When you make a copy of the spreadsheet, the copy gets its own script with empty storage, so the id does not travel. The step tells you to make a copy and send that. It would be true only if somebody handed over the original sheet, which the flow does not ask for.

2.21

The server address could redirect the request onward.

The request follows redirects, so an https server could bounce the data to a second address.

True, keptRaised by Two reviews

True of the mechanism and changes nothing: the destination is already whatever the Server URL cell says. Folded into 2.6.

2.22

A fallback image formula leaves a remote-loading cell in the sheet.

If a picture on the Start here tab cannot be placed, an =IMAGE formula pointing at Blotter's own address is used instead, and it reloads whenever the sheet recalculates.

True, keptRaised by One review

True and harmless: the address is ours, and the quotation marks are removed from it before it goes into the formula, so it cannot turn into any other formula. The reviewer rated it low itself.

Round 35 September 2026, evening·Two more AI reviews on Claude, one told to re-check the fixes without trusting them

The review told to re-check the fixes found the worst thing in the whole day. Neither of the earlier rounds had raised it. Two of its findings, 3.5 and 3.6, raised 2.6 and 2.9 again and are recorded there, which is why the numbers skip.

3.1

A stranger could have run a formula in your sheet by getting suggested as a contact.

Names on the Found tab are guarded against formulas when they arrive. The guard is a leading apostrophe, which Google Sheets treats as a text marker rather than part of the value, so when you ticked Add? the name was read back bare and written into Contacts unguarded. A Found name is the display name off an email, which the sender chooses. So: email a conversation involving one of your contacts, put a formula in your own display name, wait to be suggested, and the student ticking Add? runs it in their own account.

Fixed in codeVersion 4.7Raised by The review told to re-check the fixes

Guarded on the way into Contacts as well. Ten automated checks make sure it stays guarded in both places. This was the worst thing found in three rounds, and it was found by the review that was not looking for new problems.

3.2

Approving a suggested contact could blank your own notes.

Adding a contact wrote a whole row of empty cells with the name and email dropped in. 'The first free row' was only free of names and emails, so anything you kept below your last contact in a column of your own was wiped.

Fixed in codeVersion 4.7Raised by One review

It writes the two cells it means to write and clears only Blotter's own columns on that row.

3.3

The counting switch still failed on one path.

After the first fix, the address started out as the default and was only replaced a few steps into the run, so a failure before that point would have sent a count the student had switched off.

Fixed in codeVersion 4.7Raised by Both reviews, independently, quoting the same three lines

It starts out empty, which means off. The only runs given up are ones that died before the spreadsheet could be opened at all.

3.4

Ticking Closed does not stop Blotter reading that person's mail.

A closed contact's conversations are still fetched and sent every run. The sheet says Blotter leaves the row alone.

True, keptRaised by One review

The rules say a closed row keeps its history: the status reads Closed and the days show a dash, but last contact, attempts and the call dates are still worked out and shown. Stop reading their mail and those columns go blank, which the same rule forbids because a row of empty cells reads as broken. The disclosure point is fair, and it is on the audit page, row 2.4.

3.7

The image fallback builds a formula from text.

Same mechanism as 2.22, raised again.

True, keptRaised by One review

The reviewer checked it and cleared it in the same breath. Recorded because it looks alarming and will be raised again.

Standing limits

A careful review will find these. Each is how it works rather than a bug, and each is on the audit page beside the claim it limits.

  1. 01The Gmail permission is your whole mailbox. No narrower one allows searching. Row 2.3
  2. 02Whole conversations are read, so anyone copied in has their name, address and the subject line read too. Row 2.3
  3. 03Subject lines reach our server. Row 2.3
  4. 04The text of the Start here tab can be rewritten from our side. Section 05
  5. 05Nobody has paid for an audit. The reviews are ours and whoever reads the code next, and Google has not verified the app. Section 05
  6. 06What the server does cannot be proved from the code. Row 2.5

Found something? Email blotterib@gmail.com or use the contact form. It goes in here either way.

New here? Start with the audit page.