Skip to content

Your files are your files.

The short version first, because this is the part people actually need to read before uploading anything.

Version 2026-09-14 · Updated 14 September 2026

Private by default.
Nobody at Data Analysis App opens your files as a matter of course. Access is logged, and the only routine reader is the analysis system itself.
Deleted whenever you want.
Delete a project and its source files go with it. Everything is deleted automatically after 30 days regardless, and you can shorten that in your account.
A person only looks if you ask.
Human review happens when you request it, or when a project fails in a way the system cannot resolve alone, and in that second case you are told before anyone opens anything.
Never used for training.
Your data is not used to train models, ours or anyone else's, under any plan. There is no setting for this because there is no other setting.

1. What we collect

The files you upload, and anything you type into a project: questions, instructions, and corrections.

An account record: your email address, and a payment reference held by the payment processor rather than by us. We never see your card number.

Ordinary service logs: request times, error traces, and which pages loaded. These are used to keep the product working and are retained for 30 days.

2. What Google and Apple tell us when you sign in

Signing in with Google shares three things with us: the email address on the account, the name on it, and the profile picture. That is the whole of it. The permissions we ask for are the two called email and profile, and neither one reaches your Gmail, your Drive, your contacts or your calendar: a Google sign-in cannot see any of those, whatever else it may look like it is agreeing to.

Signing in with Apple shares your email address, and your name only on the very first consent, because that is the only moment Apple ever sends it. Apple also lets you hide your real address behind a relay address instead. If you pick that, the relay address is the only one we ever hold, and it works like any other for receipts and password resets.

All of it is used for one purpose: to make your account and to recognise it next time. The address is where receipts and resets go; the name and picture appear in the account menu and nowhere a stranger can see. None of it is sold, handed to advertisers or data brokers, or used to build a profile of you, and none of it is used to train, tune or evaluate any model, ours or anybody else's.

Data received from Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Deleting your account deletes what a provider told us at the same time as everything else, on the schedule set out below.

3. What we do with your files

Files are read to build your project: cleaned, analysed, and turned into the outputs you asked for. That processing happens on our infrastructure and on the infrastructure of the model providers we use for the reasoning steps.

Model providers process this content to return a response and do not retain it for training under our agreements with them. The deterministic parts of the analysis, the calculations behind every figure, run on our own systems and never leave them.

We do not sell data, and we do not share it with advertisers or data brokers. There is no third category we are quietly not mentioning here.

4. Who else processes your data

Infrastructure and accounts: Vercel, Railway and Supabase. Vercel serves the website, Railway runs the analysis API and stores project files, and Supabase provides authentication, the application database and fallback object storage.

Analysis reasoning: Anthropic. It receives the project context needed for language-based investigation and explanation. Numerical answers are computed and checked by our own two independent calculation engines rather than accepted from a language model.

Payments and email: Stripe runs checkout, subscriptions and the billing portal; Resend delivers account confirmation and password-reset messages.

Measurement and reliability: Umami, Vercel Web Analytics, Vercel Speed Insights, Google Analytics and PostHog (product analytics and public-page session replay); Sentry and PostHog receives scrubbed error diagnostics with query strings and known personal fields removed. PostHog also receives anonymous server-side billing lifecycle facts such as the plan, amount, currency and Stripe transaction reference so a failed or completed payment can be acted on; it receives no billing email, name, card data, uploaded file or project content.

Password screening: Have I Been Pwned receives only the first five characters of a password hash through its k-anonymity API. It receives neither the password nor the account email.

Google and Apple act as identity providers if you choose their sign-in buttons. The information they share and how we use it is described in the section above.

Processing takes place in the United States. If we add a processor that can touch the files you upload, we will update this section and notify you before it starts.

Stripe handles card details directly. We never receive or store a card number.

5. Retention and deletion

Source files and derived data are deleted 30 days after upload by default. You can set a shorter window, down to deletion immediately on project completion, in Account → Files and privacy.

Deleting a project removes its files, its outputs and its analysis. Copies can persist in encrypted backups for up to 30 days after deletion, after which they are purged.

A project started without an account is deleted after 7 days if nobody claims it.

Closing your account deletes everything associated with it, except records we are required to keep for tax and accounting purposes, which are limited to the fact and amount of a payment, not its contents.

6. Sensitive data

Spreadsheets often contain more than their owner remembers. Data Analysis App flags columns that look like personal identifiers, including names, emails, addresses, national identifiers and card numbers. It offers to mask them before analysis, which works because the analysis rarely needs the identifier itself.

This detection is a help, not a guarantee. If a file contains something that must not be uploaded to a third-party service at all, it should not be uploaded here.

7. Human review

Human Verified is an add-on you choose. A reviewer sees the project and the source data, checks the calculations, definitions and findings, and records what they checked. Their access is scoped to that project and ends when the review does.

Separately, a small number of projects fail in ways the system cannot resolve, such as a file it cannot parse or a relationship it cannot infer. A failure grants nobody access: the diagnosis you are shown is produced by the code, not by a person reading your file. If sorting it out needs human eyes, it goes through the grant above: you tick the box when you write to us, it covers that one project, and it expires.

8. How we secure it

Files are encrypted in transit and at rest. In the database, access is enforced by the database itself through row-level security rather than only in application code, so a bug in our code cannot hand one account another account's rows. Uploaded files sit outside the database, where the same rule is enforced by our API: it checks the requesting account before it reads anything, and refuses any path outside that project's own directory.

No code written by a model is ever executed: every figure is produced by our own reviewed code, and each project is read and written under its own identifier, so one analysis cannot reach another customer's files. See the security page for how that is arranged.

Content inside your files is treated as data, never as instructions. A cell containing text that reads like a command is analysed as text.

The sections below describe what language models see and what they do not.

9. Where your data is processed

Processing takes place in the United States. If you are in the UK, the EEA or Switzerland, that may involve a transfer outside your region.

Where it does, the transfer relies on the appropriate safeguard for that route: an adequacy decision where one exists, and Standard Contractual Clauses with the relevant supplementary measures where one does not. We hold those agreements with every processor named above.

You can ask us which mechanism applies to a specific processor and we will tell you.

11. Automated decisions

The analysis is automated, but it does not make decisions about you. It produces findings about the data you upload, and no output of this service determines your access to anything, your price, or any other consequence for you personally.

There is no profiling of you as a user, and no automated decision-making with legal or similarly significant effect within the meaning of Article 22.

12. Who is responsible for your data

For your account, your payments and the operation of the service, we are the data controller.

For the contents of the files you upload, you are the controller and we act as a processor on your instructions, which matters if your file contains other people's personal data. In that case you are responsible for having a lawful basis to upload it, and we are responsible for processing it only as described here.

If you need a data processing agreement for that arrangement, ask through the contact form.

13. Cookies

We use essential cookies to sign you in and to process payments. Those cannot be switched off without breaking the service.

Analytics runs automatically for all visitors, without a cookie banner. Umami and Vercel Web Analytics are cookieless; Vercel Speed Insights measures page performance. Google Analytics uses cookies, and PostHog uses cookies and browser storage. Previously saved cookie-banner choices no longer control analytics. PostHog receives reviewed product events with a redacted page category and, after sign-in, the account's opaque UUID to connect activity across sessions. Events do not include email, name, filename, cell value, finding or report text. Session replay is limited to public marketing and authentication pages, with inputs masked. Uploads, projects, results, dashboards, reports, account pages and shared projects are excluded from replay. You can block cookies and tracking requests through browser settings or a browser extension. Server-side reliability monitoring and anonymous billing lifecycle notices operate separately. Advertising cookies remain off, and marketing email preferences are separate. The cookie page describes each service.

14. Your rights

You can export everything in a project, the cleaned data, the report, the charts, the methodology, at any time, in formats that do not require this product to open.

You can request a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular processing activity, or object to processing we base on legitimate interests. Use the contact form and we will act within 30 days.

You can withdraw consent for marketing email at any time, from your account or from any message we send. Withdrawing it does not affect anything we did while it was in force.

Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or the CCPA. We apply the same handling to everyone rather than tiering it by jurisdiction, and we do not charge for exercising a right or treat you differently for having done so.

We will not ask you for more identification than we need to be sure the request is yours. If we cannot verify it, we will tell you why rather than ignoring it.

15. Age

Data Analysis App is for people aged 18 and over. We do not knowingly process data from anyone younger, and supporting them properly would be a design and compliance project rather than a checkbox.

16. Complaints

If you think we have handled your data wrongly, tell us first through the contact form: we would rather fix it than have you escalate.

You also have the right to complain to a supervisory authority without contacting us at all. In the UK that is the Information Commissioner's Office; in the EEA it is the authority for the country you live or work in; in California it is the California Privacy Protection Agency.

17. Data breaches

If a breach affects your personal data and is likely to result in a risk to you, we will notify you without undue delay and tell you what happened, what data was involved, and what we are doing about it.

Where the law requires it, we will also notify the relevant supervisory authority within 72 hours of becoming aware.

18. Changes to this policy

If this policy changes in a way that affects how your files are handled, we will notify you before the change takes effect rather than updating the page and moving the date.

The version and effective date at the top of this page always identify the current policy. Earlier versions are available on request.

19. Contact

Privacy questions, data requests and security reports all go through the contact form, which routes them to the right person and lets you attach a project reference. We publish no email addresses: an address on a public page is scraped within days, and a privacy contact route buried in spam is a compliance problem.

Buildalytic Inc.