Skip to content

Security

Local assistance first. Scoped AI quick fixes when you ask.

How myFunction separates local editor assistance from project access, how it protects authorization tokens, and what it can do with your projects.

Updated September 11, 2026

In the editor

Language assistance

Completions, diagnostics, hover information, signature help, navigation, and deterministic quick fixes are produced locally by the extension against editor models. One 10-minute diagnostic session is available without an account; signing in enables five monthly sessions, and Pro includes unlimited diagnostics.

No Apps Script API scope

Scoped AST snippets

myFunction never requests Google Apps Script project access scopes. When you trigger an AI quick fix, only the enclosing code scope and diagnostic details are transmitted to generate the fix.

Review-first

Inline diff previews

AI quick fixes present a side-by-side or inline diff for your review. The code in the editor changes only when you click Apply.

Session data

Account and diagnostic allowance records.

Account identity
Google OAuth uses standard identity scopes (openid, email, profile) to manage diagnostic allowances and verify active subscriptions for Pro features.
Feature-use counts
The extension keeps feature counters locally. While signed in, it sends aggregate unsent counts and the extension version without a project, file, source-code, or user dimension in the analytics record.
Permanent project copy
myFunction does not keep an account-level copy of your Apps Script projects.

Limits

Capabilities the product does not have.

CapabilityBoundary
Runs Apps Script functionsNo. Running stays in the Apps Script editor.
Creates versions or deploymentsNo. Published behavior changes only when you change it.
Uses a shell or terminalNo. It has no command-execution tool.
Browses your filesystemNo. It works only with the open code in the editor.
Directly mutates project filesNo. Quick fixes apply only after you review and choose them.

More detail

Read the permission-by-permission explanation.

The privacy policy remains the legal statement. Report security concerns to [email protected].