Files

10 KiB

Privacy Policy for Muwat Sheets Automation

Last Updated: September 30, 2026
Application Name: Muwat Sheets Automation
Application Homepage: https://git.muwat.org/murat/n8n-sheets-sync
Operator & Contact: Murat (murat@muwat.org)


1. Introduction and Scope

Muwat Sheets Automation is a private, personal automation application hosted on a self-hosted instance of n8n under the primary domain muwat.org. The application is developed, operated, and utilized solely by the individual operator for personal finance management and personal recordkeeping.

This Privacy Policy explains how Google user account data and related statement records are collected, handled, stored, protected, and retained when using the integration with Google APIs.


2. Google OAuth 2.0 Scopes and Operational Purpose

The application connects to Google APIs using credentials configured in n8n's standard GoogleSheetsOAuth2Api integration. The requested OAuth 2.0 scopes grant technical capabilities at the account/credential level, while the automation workflow currently operates on a single private spreadsheet designated by the operator:

Google OAuth 2.0 Scope Technical Capability Granted Actual Use in this Workflow
https://www.googleapis.com/auth/spreadsheets See, edit, create, and delete all your Google Sheets spreadsheets. Reads and appends normalized transactions, statement summaries, and reconciliation flags only in the single designated private spreadsheet via the Google Sheets API.
https://www.googleapis.com/auth/drive.file See, edit, create, and delete only the specific Google Drive files you use with this app. Requested by default credential configuration; the workflow operates solely on the single designated private spreadsheet file.
https://www.googleapis.com/auth/drive.metadata View and manage metadata of files in your Google Drive (distinct from read-only metadata access). Requested by default credential configuration. The workflow makes no direct Drive metadata API calls; sheet tab names and properties are retrieved via the Google Sheets API.

Operational Boundaries

  • While OAuth scopes technically permit broader account-level spreadsheet and Drive access under the credential, the workflow logic is bounded exclusively to the single private spreadsheet configured by the operator.
  • The workflow does not browse, inspect, or modify unrelated documents, files, or folders in Google Drive.

3. Data Ingestion, Local Processing, and Transmissions

3.1 Local Ingestion and Deterministic Parsing

  1. Ingress: Bank statement documents (PDF format) are transmitted to the user's self-hosted n8n service (flow.muwat.org) via an authenticated webhook channel. n8n runs as a system service (custom npm / systemd on muwat.org, not in a container).
  2. Local Text Extraction: Document text is parsed locally within the self-hosted environment using the deterministic open-source library pdf-parse.
  3. No Third-Party AI / OCR Extraction: Document binaries and extracted text are processed entirely on self-hosted infrastructure. No PDF files, raw statements, or extracted lines are transferred to third-party cloud OCR, machine learning, or artificial intelligence services.

3.2 Transmissions and Third Parties

Data handled by this automation is transmitted solely across the following endpoints:

  1. Google APIs (Google Sheets & Google Drive):
    • Transmitted data includes normalized transaction dates, transaction descriptions, normalized amounts, currency identifiers, statement period headers, and masked card identifiers (source card type and the last four digits).
    • Transmissions occur over encrypted HTTPS connections directly to Google's official API endpoints.
  2. Telegram Bot API (Third-Party Service):
    • Summary operational alerts are dispatched directly to the operator's private Telegram account via an automated Telegram bot across Telegram's third-party infrastructure.
    • The alert payload is limited to operational metadata: originating bank name, statement period, total count of parsed transactions, and reconciliation outcome status (ready or review required, potentially including review/error category). Raw card numbers, credentials, and full financial statement files or raw PDFs are never transmitted to Telegram.
  3. No Commercial Sale or Marketing Transfers:
    • User data is never sold, rented, leased, traded, or transferred to marketing networks, data brokers, advertising agencies, or third parties for promotional purposes. Disclosed data transfers are strictly operational and limited to Google APIs (for spreadsheet synchronization) and Telegram Bot API (for owner-only operational notifications) as described above.

4. Personally Identifiable Information (PII) and Masking

The application processes personal financial statements and adheres to the following privacy boundaries:

  • Card Numbers & Account Numbers: Primary account numbers (PAN) and complete payment card numbers are never extracted into structured Google Sheets rows or summary records. The canonical Google Sheet stores only operational metadata—specifically the card issuer, card type, and masked card suffixes (last 4 digits). However, incoming source bank statement PDF files (which may contain unmasked account details or full card numbers printed by the bank) remain stored in the originating email mailbox and are retained in n8n execution error payloads when a workflow run fails.
  • Financial Metadata: Transaction timestamps, merchant descriptions, normalized amounts, and statement balances are stored within the private Google Spreadsheet owned by the account operator.
  • Review Records, Email Subjects, and Filenames: Dedicated review tabs in the spreadsheet and error logs can record document filenames, email subjects, or parsing error messages to allow manual layout debugging. These review records are not temporary and persist until explicitly cleared or updated.

5. Storage, Token Security, and Retention

5.1 Credential & OAuth Token Storage

  • Google OAuth 2.0 access and refresh tokens are stored within the self-hosted n8n database hosted on the operator's private server infrastructure.
  • Tokens are encrypted at rest using n8n's internal credential encryption mechanism (encryptionKey).
  • OAuth tokens and client secrets are never committed to public version control, public repositories, or client-side assets.

5.2 Data Retention Policy

  • Spreadsheet Records: Normalized transaction data and statement summaries remain in the user's private Google Spreadsheet until the user manually deletes, modifies, or archives the spreadsheet.
  • Workflow Execution History:
    • Successful workflow executions are configured with saveDataSuccessExecution: none, meaning execution payload data for successful runs is immediately discarded and not stored in n8n execution databases.
    • Failed or erroneous executions retain execution data (saveDataErrorExecution: all) on the self-hosted server to permit manual debugging, troubleshooting of layout changes, and error reconciliation. These retained error execution payloads may contain the raw incoming statement PDF document.
    • The global retention and pruning schedule of the n8n instance is not fixed or verified; execution logs and error payloads are maintained until pruned by host configuration or manual operator maintenance. No specific automated pruning duration or fixed retention window is promised.
  • Originating Mailbox Messages: Source bank statement emails and attached PDF documents remain in the originating IMAP mailbox under the mailbox provider's standard storage and the operator's personal retention habits until the operator manually archives or deletes them. The automation workflow does not automatically delete source emails or PDFs from the mailbox.
  • Telegram Notification Messages: Operational alert messages dispatched to the private Telegram chat remain in the operator's Telegram conversation history until deleted by the operator or removed per Telegram's data handling policies. The automation workflow does not manage or automatically purge Telegram message history.

6. User Rights, Data Deletion, and Access Revocation

As this is a personal, self-hosted automation application:

  1. Revoking Google Access:
    The operator or user can immediately revoke the application's access to their Google account at any time through Google's security settings:
    https://myaccount.google.com/permissions
  2. Deleting Data:
    • All spreadsheet records can be permanently deleted directly by the user inside Google Sheets or Google Drive.
    • Self-hosted database records, execution error logs, and credential entries can be purged directly through the self-hosted n8n instance or the server host.
    • Source bank statement emails and PDF attachments can be deleted directly within the originating email account.
    • Operational alert messages in Telegram can be cleared or deleted directly within the Telegram application.
  3. Contact:
    For questions, concerns, or requests regarding this application's privacy practices, contact the operator at murat@muwat.org.

7. Google API Services User Data Policy Compliance (Limited Use)

Muwat Sheets Automation strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • Limited Use: The application's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • Human Inspection: Google user data accessed via Google APIs is not inspected by third parties. However, as this is a personal self-hosted system, the individual operator may directly inspect workflow logs, error execution payloads, and spreadsheet contents during routine maintenance and troubleshooting.
  • No AI / ML Training: Data obtained via Google APIs is not used to develop, train, or fine-tune generalized artificial intelligence or machine learning models.
  • No Advertising: Data obtained via Google APIs is never used for serving advertisements, personalized marketing, or retargeting purposes.