Skip to content

Your files are your files.

The short version first, because this is the part people actually need to read before uploading anything.

Version 2026-08-10 · Effective 10 August 2026

Private by default.
Nobody at Data Analysis App opens your files as a matter of course. Access is logged, and the only routine reader is the analysis system itself.
Deleted whenever you want.
Delete a project and its source files go with it. Everything is deleted automatically after 30 days regardless, and you can shorten that in your account.
A person only looks if you ask.
Human review happens when you request it, or when a project fails in a way the system cannot resolve alone — and in that second case you are told before anyone opens anything.
Never used for training.
Your data is not used to train models, ours or anyone else's, under any plan. There is no setting for this because there is no other setting.

1. What we collect

The files you upload, and anything you type into a project — questions, instructions, and corrections.

An account record: your email address, and a payment reference held by the payment processor rather than by us. We never see your card number.

Ordinary service logs: request times, error traces, and which pages loaded. These are used to keep the product working and are retained for 30 days.

2. What we do with your files

Files are read to build your project: cleaned, merged, analysed, and turned into the outputs you asked for. That processing happens on our infrastructure and on the infrastructure of the model providers we use for the reasoning steps.

Model providers process this content to return a response and do not retain it for training under our agreements with them. The deterministic parts of the analysis — the calculations behind every figure — run on our own systems and never leave them.

We do not sell data, and we do not share it with advertisers or data brokers. There is no third category we are quietly not mentioning here.

3. Who else processes your data

Running the service means relying on a small number of other companies. They fall into four categories: Stripe for payments, a transactional email provider, for sign-in codes and receipts, Google Analytics and Vercel Web Analytics, and Sentry.

Suppliers are named once they are actually in use. The others are described by what they do, because the list is still being settled and naming a company we have not contracted with would be worse than describing the role. The current list, with names, is available on request through the contact form, and it will be published in full here before launch.

Processing takes place in the United States. If we add a processor that can touch the files you upload, we will update this section and notify you before it starts.

Stripe handles card details directly. We never receive or store a card number.

4. Retention and deletion

Source files and derived data are deleted 30 days after upload by default. You can set a shorter window, down to deletion immediately on project completion, in Account → Files and privacy.

Deleting a project removes its files, its outputs and its analysis. Copies can persist in encrypted backups for up to 30 days after deletion, after which they are purged.

A project started without an account is deleted after 7 days if nobody claims it.

Closing your account deletes everything associated with it, except records we are required to keep for tax and accounting purposes — which are limited to the fact and amount of a payment, not its contents.

5. Sensitive data

Spreadsheets often contain more than their owner remembers. Data Analysis App flags columns that look like personal identifiers — names, emails, addresses, national identifiers, card numbers — and offers to mask them before analysis, which works because the analysis rarely needs the identifier itself.

This detection is a help, not a guarantee. If a file contains something that must not be uploaded to a third-party service at all, it should not be uploaded here.

6. Human review

Human Verified is an add-on you choose. A reviewer sees the project and the source data, checks the calculations, definitions and findings, and records what they checked. Their access is scoped to that project and ends when the review does.

Separately, a small number of projects fail in ways the system cannot resolve, such as a file it cannot parse or a relationship it cannot infer. We ask before a person looks at those, and you can decline human access.

7. How we secure it

Files are encrypted in transit and at rest. Access is enforced in the database itself through row-level security rather than only in application code, so a bug in our code cannot expose another customer's project — the database refuses the query regardless of what the application asks for.

Analysis runs in isolated environments with no network access and no credentials. Code generated during an analysis cannot reach the internet, cannot read another project, and has no access to our infrastructure.

Content inside your files is treated as data, never as instructions. A cell containing text that reads like a command is analysed as text.

The sections below describe what language models see and what they do not.

8. Where your data is processed

Processing takes place in the United States. If you are in the UK, the EEA or Switzerland, that may involve a transfer outside your region.

Where it does, the transfer relies on the appropriate safeguard for that route — an adequacy decision where one exists, and Standard Contractual Clauses with the relevant supplementary measures where one does not. We hold those agreements with every processor named above.

You can ask us which mechanism applies to a specific processor and we will tell you.

10. Automated decisions

The analysis is automated, but it does not make decisions about you. It produces findings about the data you upload, and no output of this service determines your access to anything, your price, or any other consequence for you personally.

There is no profiling of you as a user, and no automated decision-making with legal or similarly significant effect within the meaning of Article 22.

11. Who is responsible for your data

For your account, your payments and the operation of the service, we are the data controller.

For the contents of the files you upload, you are the controller and we act as a processor on your instructions — which matters if your file contains other people's personal data. In that case you are responsible for having a lawful basis to upload it, and we are responsible for processing it only as described here.

If you need a data processing agreement for that arrangement, ask through the contact form.

12. Cookies

We use essential cookies to sign you in and to process payments. Those cannot be switched off without breaking the service.

Anything beyond that is optional, off until you agree, and changeable at any time. The cookie page lists every cookie by name, purpose and lifetime.

13. Your rights

You can export everything in a project — the cleaned data, the report, the charts, the methodology — at any time, in formats that do not require this product to open.

You can request a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular processing activity, or object to processing we base on legitimate interests. Use the contact form and we will act within 30 days.

You can withdraw consent for marketing email at any time, from your account or from any message we send. Withdrawing it does not affect anything we did while it was in force.

Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or the CCPA. We apply the same handling to everyone rather than tiering it by jurisdiction, and we do not charge for exercising a right or treat you differently for having done so.

We will not ask you for more identification than we need to be sure the request is yours. If we cannot verify it, we will tell you why rather than ignoring it.

14. Age

Data Analysis App is for people aged 18 and over. We do not knowingly process data from anyone younger, and supporting them properly would be a design and compliance project rather than a checkbox.

15. Complaints

If you think we have handled your data wrongly, tell us first through the contact form — we would rather fix it than have you escalate.

You also have the right to complain to a supervisory authority without contacting us at all. In the UK that is the Information Commissioner's Office; in the EEA it is the authority for the country you live or work in; in California it is the California Privacy Protection Agency.

16. Data breaches

If a breach affects your personal data and is likely to result in a risk to you, we will notify you without undue delay and tell you what happened, what data was involved, and what we are doing about it.

Where the law requires it, we will also notify the relevant supervisory authority within 72 hours of becoming aware.

17. Changes to this policy

If this policy changes in a way that affects how your files are handled, we will notify you before the change takes effect rather than updating the page and moving the date.

The version and effective date at the top of this page always identify the current policy. Earlier versions are available on request.

18. Contact

Privacy questions, data requests and security reports all go through the contact form, which routes them to the right person and lets you attach a project reference. We publish no email addresses: an address on a public page is scraped within days, and a privacy contact route buried in spam is a compliance problem.

Buildalytic Inc.