Privacy: Formshelf for Notion
Last updated 2026-10-01. This page adds add-on specific detail to the Great Work privacy policy, which covers the licensing and billing service. This add-on handles data differently from our spreadsheet add-ons in one way: once you turn it on, it sends each new response to your form to Notion, a third-party service you connect.
Google data the add-on accesses
- The form you open it in (scope
forms.currentonly): its title, questions and choices, and its responses (answers, submit time, the respondent's email if your form collects it, the edit-response link, and the Drive IDs of uploaded files). It can also add questions to that form, only when you click "Add form questions". It cannot open any other form, and it cannot read the uploaded files themselves or anything else in your Drive. - Your email address (
userinfo.email): to identify your license and to show teammates who turned delivery on. - A form-submit trigger (
script.scriptapp): so new responses are sent while the form is closed. Turning delivery off removes it.
How it is used and where it goes
- When a response is submitted (or you click Send a test page, Send past responses or Send waiting responses), the add-on reads that response inside Google's Apps Script environment and sends it over HTTPS directly to the Notion API (api.notion.com) using the Notion connection of the person who turned delivery on. It creates or updates one page in the database that person chose.
- Form responses never reach Great Work servers. The only data sent to Great Work (addons.greatwork.company) is your Google account email address, the add-on name and a count of delivered responses, to run the trial and your subscription.
- Once a page is in Notion, Notion's own privacy policy and your workspace's settings govern it.
What is stored, and where
- Your Notion connection: either the OAuth tokens Notion issues when you click Connect Notion, or the integration secret you paste. Stored in your own Apps Script user properties inside Google, readable only by the add-on running as you. Never shared with teammates and never sent to Great Work.
- This form's setup, in the form's own add-on storage (Apps Script document properties): the chosen database's ID, name and property names, the question-to-property mapping, fixed values, the time zone, who turned delivery on, an activity log of the last 100 deliveries (time, response ID, the response's title, status, Notion page link), the IDs of responses waiting to be sent, and response ID to Notion page ID pairs for the last 400 responses (so edits update the right page).
- No response content is stored by the add-on beyond the short page titles in the activity log. Responses live in Google Forms and in the Notion pages created from them.
Sharing
We don't sell, rent or share Google user data. Form responses go only to the Notion workspace connected by the person who turned delivery on. Payment details go to Stripe, never to us.
Limited Use
Formshelf for Notion's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is transferred only to Notion, as configured by you, to provide the feature you are using. We don't use Google user data for advertising, no person at Great Work reads your responses, and we don't use them to train AI models.
Your respondents
You are responsible for telling respondents where their answers go (for example, in the form's description) and for having a reason to store them in Notion.
Deleting your data
- Turn off stops delivery and removes the trigger. Disconnect deletes your stored Notion connection. To also revoke it on Notion's side, remove the integration in Notion under Settings, Connections.
- Clear under Activity deletes the log. Removing the add-on from the form, or deleting the form, removes the form's add-on storage.
- Pages created in Notion are yours, in your Notion workspace. Delete them in Notion.
- To delete your license record (email, usage count, subscription ids), email hello@greatwork.company from that account. We delete it within 30 days, apart from billing records the law requires us to keep.