Privacy policy

Effective date September 3, 2026/Last updated September 3, 2026

Blotter is built and working, and it is not yet open to other people. It is running today on the account of the person who made it, and nobody else has been given a copy. When that changes, this page changes with it.

The short version of how it handles your data: Blotter is a Google Sheet with a script inside it. The script runs in your own Google account, on your own permission. It reads only the conversations that already involve someone in your contact list, and the text of an email never leaves your account. Blotter’s server keeps no database and stores nothing about you. Section 3 sets out the two small things that are recorded, and section 5 sets out exactly what Google will ask you for.

01Who this policy is from

This policy explains how Blotter handles information when you connect your Google account and use Blotter to maintain your recruiting tracker.

Blotter is referred to here as “Blotter”, “we” and “us”. You can reach us at blotterib@gmail.com.

02What this policy covers

It covers the Blotter product and this website. It does not cover Google, your email provider, or any other service you connect to or reach through a link, each of which has its own policy.

03What happens today

Blotter is still being built. The connection to Gmail, Calendar and Google Sheets described in the rest of this policy is not active, and nothing has access to your Google account.

Three things do happen now.

If you give us your email address at the end of the sign-up flow, we store it, together with what you told us about what you are recruiting for and your recruiting window, which link you arrived through, and how far through the flow you went. It is stored in our database, run by Supabase in the United States.

We record how this site is used through PostHog, in the United States: pages viewed, which steps of the sign-up flow were reached, your device and browser type, approximate location derived from your IP address, and where you arrived from. Your email address is never attached to this usage data.

If you send us a message using the contact form, we store the message, the address you gave us to reply to, your name if you chose to give one, and which page you were on when you wrote. It is stored in the same database, run by Supabase in the United States, and it is used to answer you and for nothing else.

If you install Blotter in a spreadsheet, that copy generates a random identifier, a string of characters that identifies the sheet and nothing about you, and sends it to us each time it runs, together with the time of the run, how long it took, how many contacts were in the sheet, whether it succeeded, and which version of Blotter it is. That is the whole list. No name, no email address, no subject line, no message, no contact, and no firm ever goes with it. We use it to see how many sheets are running and to notice when a version starts failing, so that a widespread problem is not something we first hear about from the person it broke. It is stored in the same database, run by Supabase in the United States. You can switch it off by clearing the usage-counting address in the sheet’s Settings tab; nothing else stops working if you do.

No payment has been taken from anyone and no card details are collected anywhere on this site. If paid access is switched on later, a key issued to you would be stored against that same identifier so we can tell whether a sheet has access. Nothing else about you would be stored with it, and this page will say so before it happens.

If you would like the email address you gave us deleted, write to blotterib@gmail.com and we will remove it.

04Information we collect

Less than you would expect, and the reason is architectural rather than a policy we have adopted.

There is no Blotter account. You do not sign up, choose a password, or hand us a login. Blotter is a spreadsheet you copy, and the script inside it runs on the permission you give it in your own Google account.

Your Google data does not come to us and is not stored by us. The script reads your mail and calendar inside your own account. To work out what each conversation means it sends us a short list of facts, set out in full in section 6, and we send back the answer and keep no record of either.

What we do hold is the three things section 3 lists — an email address if you gave us one, website usage through PostHog, and a message if you sent one — plus the anonymous per-sheet identifier and run counts described there. Your email address is never sent to analytics.

05What we access in your Google account

The permissions Blotter requests, and the limits on each, are the following.

Gmail

Blotter can:

  • Read the outside of your emails: who wrote, who it went to, when, and the subject line.
  • Look at conversations with the people in your Contacts tab.

Blotter cannot:

  • Read the text of an email.
  • Send an email.
  • Reply to anything.
  • Change or delete anything in your mailbox.
  • Touch a conversation that does not involve one of your contacts.

Google Calendar

Blotter can:

  • Read your events, and only read them, to find calls and coffee chats with your contacts.

Blotter cannot:

  • Create an event.
  • Change an event.
  • Cancel an event.
  • Accept or decline an invitation for you.

Google Sheets

Blotter can:

  • Update the one spreadsheet it lives in, the copy you made.

Blotter cannot:

  • See that any other file in your Drive exists.
  • Open, change or delete any other file.
  • Create a new file anywhere.

Google will show you a screen headed Select what Blotter can access with five checkboxes on it. These are those five, in the words Google uses, with what each one is for. All five are required, none of them is ticked by default, and nothing on that screen tells you either of those things. There is a Select all link above them, and that is the one to use.

  • Gmail gmail.readonly
    Google shows: “View your email messages and settings.”
    Without it: Everything. Blotter cannot read any mail, so no status is ever right.
  • Google Sheets spreadsheets.currentonly
    Google shows: “View and manage spreadsheets that this application has been installed in.”
    Without it: Everything. Blotter cannot write to the sheet it lives in.
  • Google Calendar calendar.readonly
    Google shows: “See and download any calendar that you can access.”
    Without it: Scheduled calls, completed calls and cancelled calls all stop working.
  • Connecting out script.external_request
    Google shows: “Connect to an external service.”
    Without it: Everything. This is how the sheet reaches Blotter’s server to ask what your contacts’ statuses are.
  • Running on a timer script.scriptapp
    Google shows: “Allow this application to run when you are not present.”
    Without it: The 15-minute updates. You would have to run Blotter by hand every time.

Three of the five are read-only. Blotter has no permission to send an email, reply to one, change or delete anything in your mailbox, or create, change or cancel a calendar event. Not as a promise, but because those permissions were never requested and cannot be used without being granted.

The Gmail permission is worded broadly because Google does not offer one limited to the people in your contact list. What limits it is not a promise about our processing: the reading happens inside your own Google account, and the only thing that leaves it is the short list of facts in section 6.

The spreadsheet permission is narrower than it may sound. spreadsheets.currentonly grants the one spreadsheet the script is installed in, which is the copy you made. Blotter cannot see that any other file in your Drive exists, cannot open one, and cannot create one.

You may also see a line reading “Learn why you’re not seeing links to Blotter’s Privacy Policy or Terms of Service”. That is because Google only shows those links for apps it has reviewed, and it has not reviewed a script you installed into your own account. This page is that privacy policy, and there is a link to it from every page of this site.

06What Blotter reads, and what it cannot

Blotter follows conversations, not senders. A thread counts if any message in it has one of your contacts on the From, To or Cc line — which is what lets an assistant replying on a banker’s behalf update that banker’s row. A conversation with none of your contacts in it is never opened.

It runs inside your Google account. Blotter lives inside your own copy of the spreadsheet and runs on your Google account’s own permission. There is no Blotter account, and Blotter never holds a login or a password for your Google account.

It only looks at conversations with your contacts. Every 15 minutes through the day, and every two hours overnight, it checks for conversations with the people in your Contacts tab. A conversation that does not involve one of them is never opened. One that does is read whole, so anyone else copied into it has their address and the subject line read as well.

Blotter reads facts, not text. To work out where each conversation stands, Blotter’s server is sent, for each email in a conversation with one of your contacts: who wrote it, everyone it went to, when, and the subject line. Names as well as addresses, where the email carried a name. For a calendar event: the title, the times, everyone invited, who declined and who set it up. From your Contacts tab: each person’s name, firm and email, whether you have ticked Closed, and which row they are on. It is also sent your own email addresses, the addresses of anyone you rejected on the Found tab, this sheet’s random id, and Google’s own reference numbers for the conversations it read. The body of an email is never sent.

The answer goes into your sheet, and nowhere else. The server works out each contact’s status and sends it back to your spreadsheet. Blotter does not store your mail, your contacts, or the answer.

This is the complete list of what is sent to us, per message: who it was from, who it was addressed to, who was copied, the date and time, the subject line, and whether you sent it. For calendar events: the title, the start and end time, who was invited, who organised it, and who declined. For your contacts: the name, firm and email addresses you typed into the sheet yourself.

The body of an email is never sent. It is not sent and discarded — it is not sent. Our server rejects any request that arrives carrying message text, before it looks at anything else. The one exception proves the rule: when an email bounces, the delivery-failure notice from the mail system is read inside your own account to find which address failed, and only that address is sent.

What Google’s permission screen will say. Google words the Gmail permission broadly, because it uses the same wording for every app that asks. Blotter uses it to read who wrote, who it went to, when, and the subject line, for conversations with your contacts. Google also asks for two things that are not services: permission to contact Blotter’s server, and permission to run while you are away, which is what keeps the sheet current every 15 minutes. All five are required, none is ticked by default, and nothing on that screen tells you so.

07How we use the information

We use it to operate Blotter: to work out the status, timing and scheduled calls for the contacts in your sheet, to answer you if you write to us, and to see whether Blotter is working for the people using it.

We do not use your Google account data to build advertising profiles, and we do not sell personal data.

Blotter’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

08What we keep

Nothing about your mail. The part of Blotter that works out each contact’s status keeps no record of the facts it was given or the answer it sent back.

Your recruiting information is kept in one place: your own spreadsheet, in your own Google Drive. The facts above go to the server to be worked out and are not kept there.

One thing is counted. Each copy of the sheet generates a random id that identifies the sheet and nothing about you, and sends it with the time of each run and how many contacts were in it, so a broken version can be noticed before people have to write in. No name, address, subject line or message goes with it.

Calendar events are read to find calls and coffee chats with your contacts. Blotter never writes to your calendar. The permission it asks for is read-only.

The email address you gave us, and any message you sent us, we keep until you ask us to delete them. Ask, and we will.

If paid access is switched on later, the server would also check whether a sheet’s key is active before answering it. That is a look-up rather than a record: it reads a row and writes nothing.

09What we do not do

Each of these can be checked. The audit page shows how.

  • Blotter cannot send an email, and never asks for permission to
  • Blotter cannot create, change or cancel a calendar event
  • Blotter does not access Google Contacts
  • Blotter cannot see that any other file in your Drive exists
  • Blotter does not sell your data
  • Blotter’s server cannot receive the text of an email
  • Blotter never opens a conversation that does not involve one of your contacts
  • You can remove Blotter’s access from your Google account at any time
  • Delete the spreadsheet and nothing of yours is left anywhere

10Where Blotter runs

There is nobody else in this but Blotter. No connection provider, no data broker, no other company handling your mail on the way through. Blotter runs inside your own copy of a Google Sheet, on your own Google account’s permission. On a personal Gmail account, Google says so on the way in: it shows an unverified-app screen and names you as the developer, because the copy is yours. A university account does not see that screen.

Blotter’s own server does one job. It is sent the facts about conversations with your contacts, works out where each one stands, and sends the answer back. It holds no login for your Google account and no copy of your mail.

For this website and the small amount of information section 3 describes, we rely on Supabase for database storage and PostHog for website analytics, both in the United States, and Vercelto host the site and the server that works out your contacts’ statuses. If paid access is switched on later, card payments would be handled by Stripe directly and Blotter would never receive or store card details. No payment is being taken from anyone today.

We do not sell your data. We may disclose information if we are legally required to, or to protect the rights and safety of users and the public.

11Your choices

You can remove Blotter’s access whenever you like, from your own Google account’s security settings, and it stops that moment. Your spreadsheet is yours. Nothing about it was ever copied anywhere else, so deleting it is the end of it.

That is done from your own Google account’s security settings, under the list of apps with access — not from anything of ours, and without telling us. It takes effect immediately.

You can also simply delete the spreadsheet. It is an ordinary file in your own Google Drive, nothing about it was ever copied anywhere else, and deleting it is the end of it.

You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it, and we will. Depending on where you live you may also have rights under local privacy law to object to or restrict some processing; contact us and we will honour them.

12Keeping information safe

We use technical and organisational measures intended to protect the information we hold.

Blotter holds no security certification and has had no third-party audit, and we would rather say so than imply otherwise. Google has not reviewed or verified Blotter. If you install it into a personal Gmail account, Google says so on the way in, on a screen headed “Google hasn’t verified this app”. The developer it names is you, because the copy is yours. A university account does not see that screen: Google waives it when the owner of the copy and the person running it are in the same organisation, and you are both.

What carries the weight here is not a certificate. It is that there is very little to protect: your mail is never copied out of your Google account, the text of an email never reaches us, and our server keeps no database. The small amount described in section 3 is held by established providers who maintain their own security programmes. No service can promise perfect security, and anyone who does is worth doubting.

13Where information is processed

The information described in section 3 is stored and processed in the United States. Blotter does not operate outside the United States, and we do not transfer your information elsewhere.

Your mail and calendar are a separate matter, and a simpler one: they stay where they already are, inside your own Google account, and are read there. Google’s own terms and its own storage locations govern them, not ours.

14Age

Blotter is built for university students and graduates recruiting for finance roles. You must be 18 or older to hold a Blotter account, and we do not knowingly collect information from anyone under 18.

15Changes to this policy

Blotter is still being built, so this policy will change as it is: providers, storage locations and specific practices may all be revised. We will update this page when they are, and the date at the top will always show when the current version took effect. If a change materially affects how we handle your information, we will tell account holders by email before it takes effect.

16Contact

Questions about this policy or your data can be sent to blotterib@gmail.com.

17Common questions

Why does Google ask for such broad Gmail access?

Because Google uses the same wording for every app that asks, and does not offer a permission that means only the people in this spreadsheet. There is a narrower Gmail permission that would hand over headers only, and Blotter cannot use it: it forbids searching, and searching for your contacts is the whole mechanism. What Blotter does with it is narrow: it reads who wrote, who it went to, when, and the subject line, for conversations with your contacts. It cannot read the text.

Does Blotter read my personal email?

No. It only looks at conversations with the people in your Contacts tab, and it reads the outside of those, not the text. Everything else in your inbox is never touched.

Does Blotter store my emails?

It cannot. Blotter’s server is sent who wrote, who it went to, when, and the subject line. The text of an email is never sent, so there is nothing to store.

Can Blotter send emails or change my calendar?

No, and not as a matter of policy. The permissions it asks Google for are read-only, so sending an email or touching a calendar event is not something it is able to do.

Does Blotter sell my data?

No.

Why does Google warn me that this app is not verified?

Only a personal Gmail account sees it. A university account goes straight to the permissions, because Google trusts universities automatically. On a personal account, the email address in the brackets is yours: the copy of Blotter you just made lives in your Google account, and Google treats everything in your account as yours. The screen is asking whether you want to let Blotter read your own account. It does not change what Blotter is allowed to do. That is fixed by the permissions on the next screen. Three of them are read-only, one is the spreadsheet you just copied, and the last two are not about your data at all: one lets Blotter reach its own server, and one lets it run while you are away.

What if I want to stop using it?

Remove its access in your Google account’s security settings and it stops immediately. The spreadsheet is yours to keep or delete. There is no account to close and nothing held anywhere else.