Privacy Policy
Last updated: August 8, 2026
Greater Than the Sum ("we", "our", "us") operates the network mapping platform at viz-sumapp.net (the "Platform"). This policy explains what data we collect, how we use it, and your rights regarding that data.
Who we are
Greater Than the Sum is operated by Tim Hanson and Christine Capra. Our contact email is accounts@greaterthanthesum.com.
What the Platform does
The Platform renders interactive network maps from relationship data. Account administrators provide data (via Google Sheets or JSON), configure the map, and publish it for their viewers. Viewers interact with the map in a web browser.
Data we collect
1. Authentication (Google Sign-In)
Administrators sign in using Google. We receive and store:
- Name and email address (from your Google profile)
- Google user ID (for session management)
We do not access your Google password. Authentication is handled by Google's OAuth 2.0 service and Firebase Authentication.
2. Google Sheets data (read-only access)
When an administrator links a Google Sheet as a data source, they choose that one file with the Google Picker. We request the drive.file scope, which grants access only to files chosen that way. This allows us to:
- Read the contents of that specific spreadsheet to extract node and edge data for the network map
- Re-read the spreadsheet when the administrator requests a data refresh
3. Sharing the chosen Sheet with our service account
Under the same drive.file scope, we share the spreadsheet the administrator chose with our platform service account as a Viewer. This allows the Platform to refresh the map data without requiring the administrator to remain signed in.
- The share is applied once, to the specific spreadsheet the administrator selected
- The service account receives read-only (Viewer) access only
- We do not browse, list, or access any other files in your Google Drive
4. Platform usage data
We store configuration data (map settings, filters, styles, views) and account information (account name, member roster, roles) in Google Cloud Firestore. This data is used solely to operate the Platform.
5. Map viewer data
Viewers who access a published network map do not need to sign in. We do not collect personal information from viewers. Standard web server logs (IP address, browser type, timestamp) may be recorded by Firebase Hosting infrastructure.
How we use your data
- Render network maps — the core function of the Platform
- Authenticate administrators — to manage accounts and projects
- Maintain data freshness — re-read linked spreadsheets for map updates
- Operate the service — store configuration, manage accounts, send service emails
What we do not do
- We do not sell, rent, or share your personal data or spreadsheet contents with third parties
- We do not use your data for advertising or profiling
- We do not train AI or machine-learning models on your data
- We do not access Google data beyond the specific scopes described above
Data storage and security
Data is stored in Google Cloud infrastructure (Firebase Authentication, Cloud Firestore, Firebase Hosting) in the United States. Access to production systems is restricted to the platform operators. Authentication tokens are short-lived and transmitted over HTTPS only.
Data retention and deletion
Account data is retained while the account is active. Administrators may request account deletion by contacting accounts@greaterthanthesum.com. Upon deletion, we remove account data from Firestore and revoke any stored OAuth tokens. Cached spreadsheet data is deleted when the data source is unlinked or the project is removed.
Third-party services
- Google Cloud / Firebase — authentication, data storage, hosting
- Google Sheets API — reading spreadsheet data
- Google Drive API — the file chooser, and sharing the chosen spreadsheet with the platform service account
These services are governed by Google's Privacy Policy.
Your rights
You may:
- Request a copy of the data we hold about your account
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Revoke the Platform's access to your Google data at any time via Google Account permissions
Changes to this policy
We may update this policy from time to time. Material changes will be communicated to active account administrators by email. The "last updated" date at the top reflects the most recent revision.
Contact
For privacy questions or data requests, contact:
Tim Hanson
accounts@greaterthanthesum.com