Last updated: June 24, 2026
GKit is a suite of Google Workspace tools built and operated by Eshank Tyagi (MrEshank), a solo developer. This policy explains what data we collect, why, and how we handle it. It is written in plain English because you deserve to actually understand it.
When you sign in with Google, we receive your Google profile information - your name, email address, and profile picture - via OAuth. We also receive an OAuth access token that allows GKit to call the Google Sheets API on your behalf. We do not receive or store your Google password.
Your OAuth token is used exclusively to proxy Google Sheets API requests that you initiate through SheetsAPI. When you make a request to your SheetsAPI endpoint, GKit forwards that request to Google using your token and returns the response. We do not read, analyze, or retain the contents of your Sheets.
Your OAuth access token is encrypted and stored in Cloudflare KV so GKit can serve API requests without requiring you to re-authenticate each time. Your profile information (name, email) is stored to identify your account in the dashboard. We set one session cookie - __Secure-gkit.session-token - to keep you signed in. It is httpOnly, Secure, and scoped to .gkit.mreshank.com.
Cloudflare's infrastructure logs standard access data (IP address, timestamp, URL path) as part of normal CDN operation. We do not run any additional analytics or tracking beyond these server logs.
We do not serve advertising. We do not sell, rent, or share your data with third parties for marketing purposes. We do not use third-party analytics scripts (no Google Analytics, no Mixpanel, no tracking pixels). We do not read your Sheets data for any purpose other than fulfilling your own API requests.
Google- Authentication and Sheets API access are provided by Google. Your use of Google's services is governed by Google's Privacy Policy.
Cloudflare- GKit runs on Cloudflare Workers and uses Cloudflare KV for token storage. Cloudflare's infrastructure may process your data as part of serving requests. See Cloudflare's Privacy Policy.
Your OAuth token is stored in Cloudflare KV for as long as your GKit account is active. When you disconnect your Google account or delete your GKit account, your token and profile data are deleted. You can disconnect at any time from the GKit dashboard.
You can delete all data GKit holds about you by disconnecting your Google account in the dashboard or by emailing us. Disconnecting removes your token from Cloudflare KV and deletes your profile data. Server-level Cloudflare logs are outside our control and are retained per Cloudflare's standard retention schedule.
Questions about this policy? Email contact@mreshank.com.