How Data Analysis App protects your data.
You are handing over a file you did not want to share with anyone. Here is exactly what happens to it, in the order it happens.
1. Access
Every project belongs to exactly one account. In the database that is enforced by the database itself, through row-level security rather than only in application code, so a bug in our code cannot hand one account another account's rows: the query is refused regardless of what the application asks for.
Uploaded files sit outside the database, on storage that is never publicly addressable. Reaching one means asking our API, which checks the requesting account against the project before it reads anything and refuses any path outside that project's own directory. That is our code enforcing the rule rather than the database, and we would rather say so than imply a guarantee we do not have.
2. Storage
Files are encrypted in transit and at rest. Source files, the cleaned data derived from them, and generated outputs are stored separately, so a share link to a report never grants access to the spreadsheet behind it.
We keep the file you uploaded unchanged. Cleaning and repair produce a new copy; the original is never overwritten.
3. Processing
No code written by a model is ever executed. Every figure is produced by our own reviewed code, the same code for every customer, so there is no model-authored program to contain in the first place.
Content inside your files is treated as data, never as instructions. A model may help decide which questions are worth asking; it never decides an answer. Every figure is computed in code and recomputed independently before it is shown, so text sitting in a spreadsheet cell cannot change a number, and anything the two computations disagree about is dropped rather than displayed.
Each project is read and written under its own identifier, so one analysis cannot reach another customer's files.
4. What language models see
Models see the structure of your data, not the contents of it: column names, types, statistical profiles, and masked samples. Identifying a column as email addresses does not require sending the addresses.
Where a value must be shown to a model, sensitive fields are masked first.
5. Human access
People at Data Analysis App do not browse customer projects. There are exactly two circumstances in which a person sees your data: you purchase Human Verification, or you explicitly grant access when contacting support about a specific project.
That support checkbox is unchecked by default and scoped to the one project. Every grant is recorded and expires.
6. Retention
Source files are kept for 30 days by default, and you can shorten that or delete them at any point from your account. A project you never claimed with an account is removed after 7 days.
Deleting a project removes it from your account immediately and purges the underlying objects within 30 days.
7. Deletion
Deleting your account removes your projects, uploaded files, generated outputs, saved recipes and profile. It runs as a job rather than a flag: objects are removed from storage, then the records, then the account itself.
Some transaction records are retained where we are legally required to keep them. The privacy policy states which, and why.
8. Who else touches it
Running Data Analysis App means using other companies. These are the ones that can touch your data, and the privacy policy describes what each does.
- Payments
- Stripe
- Resend
- Analytics
- Umami, Vercel Web Analytics, Vercel Speed Insights, Google Analytics and PostHog (product analytics and public-page session replay)
- Error monitoring
- Sentry and PostHog
Processing takes place in the United States.
9. Reporting an issue
Found a vulnerability? Tell us through the contact form, choosing Security. We acknowledge within two business days.
We will not pursue legal action against anyone who reports a genuine issue in good faith and gives us reasonable time to fix it before disclosing it.