Privacy Policy
Last updated 11 August 2026.
This policy explains what we collect, why, and who else sees it. The short version: we process your documents in order to build spreadsheets for you, that processing involves sending content to AI providers, and we do not sell your data.
1. What we collect
- Account data — your name, email address, organisation name, and a securely hashed password. We never store your password in readable form.
- Content you provide — documents you upload, the instructions you type, and the workbooks the service produces. Text extracted from your documents is stored so the service can search and reason over it, along with numeric embeddings derived from that text.
- Usage and billing records — which actions you ran, when, how many credits they cost, and the model-provider cost behind them. This is what your balance and receipts are computed from.
- Technical logs — IP address, request metadata, and error traces, used to operate the service, debug failures, and apply rate limits.
- Product analytics — if enabled, which screens were opened and which actions were taken, recorded against your account id. What it deliberately does not include: your IP address (discarded on every event), your name or email, anything you typed, any document name or content, and any model output. We record the route pattern rather than the address you were on, so a document or session identifier is never sent. There is no session recording and no automatic click capture, and we never combine this with third-party data or use it for advertising.
We do not collect payment card details. If and when card payments are enabled, they are handled entirely by our payment processor; card numbers never reach our servers.
2. Why we process it
To provide the service (generating and editing your workbooks), to meter and bill usage, to secure the service against abuse, to support you when something breaks, and to comply with legal obligations. Where the law requires a lawful basis, ours is performance of our contract with you and our legitimate interest in operating and securing the service.
3. AI subprocessors — where your content goes
To generate a workbook, relevant portions of your instructions and your uploaded content are sent to third-party AI providers. Depending on configuration, those providers are OpenAI and/or Anthropic. They process that content in order to return a result to us, under their own terms.
If your documents contain confidential or personal information you are not permitted to share with a third-party processor, do not upload them.
We also rely on:
- a cloud hosting provider, to run the application;
- a managed database provider, to store your account and content data;
- an object-storage provider, to store uploaded and generated files;
- a product-analytics provider, where analytics is enabled, receiving only the screen and action records described in section 1 — never your documents, instructions or results.
4. Training
We do not use your content to train our own models — we do not train models. We ask our AI providers to process your content only to serve your request, on their non-training API terms.
5. Sharing
We do not sell your personal information and we do not share it for advertising. We disclose data only to the subprocessors above, to professional advisers where necessary, where required by law or valid legal process, and to a successor entity in a merger or acquisition (in which case this policy continues to apply until replaced).
Within the product, documents are scoped to your organisation — anyone you invite into your organisation can see them. They are not visible to other customers.
6. Retention
We keep your account and content data for as long as your account is open. If you delete a document we remove it and its extracted text and embeddings. If you close your account we delete your content within 30 days, except where we must retain records to meet legal, tax, or accounting obligations — billing records are kept for as long as the law requires. Backups age out on their own cycle.
7. Security
Traffic is encrypted in transit. Passwords are hashed with bcrypt. Access is scoped per organisation and enforced server-side. Code that generates your workbooks runs in an isolated subprocess with outbound network access blocked and credentials withheld from its environment.
No service is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data, we will notify you as required by law.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to your data protection authority. You can delete documents in the app at any time. For anything else, email support@supasheet.dev and we will respond within the period the applicable law requires.
9. International transfers
Our providers may process data in countries other than yours, including the United States. Where required, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.
10. Children
The service is for business use and is not directed to children. We do not knowingly collect data from anyone under 16.
11. Changes
We may update this policy; the "last updated" date above will change. If a change is material we will give notice before it takes effect.