Privacy & Trust Center

Privacy Policy

Effective Date: September 7, 2026

Zero Model Training

Spreadsheet cell contents and formulas are never used to train public or foundational AI models.

Ephemeral Execution

Workbook cells pass through isolated memory buffers during computation and are discarded after response generation.

Encrypted Channels

All active transmissions use TLS 1.3 encryption, and saved configurations are secured with AES-256 at rest.

Explicit Deletion

Accounts, saved variables, and dashboard templates can be permanently purged at any time from user settings.

1. Scope & Operational Entity

This Privacy Policy applies to personal data and technical information processed by GSquare Labs, a registered sole proprietorship in Gujarat, India, with its principal office at 1650, 1st Floor, Girdhar Gopal Bldg, Shastrinagar Main Rd, Jadiya Wadi, Surat - 395002, Gujarat, India. GSquare Labs operates the SheetFactorys software brand, comprising the web application at sheetfactorys.com and add-in extensions for Microsoft Excel and Google Sheets.

2. Data Categories Processed

The platform processes four distinct data categories to perform requested spreadsheet actions:

  • Authentication profiles: Name, email address, and authentication identifiers supplied via Google Firebase Auth to establish and verify user sessions.
  • Subscription records: Transaction identifiers, plan status, renewal timestamps, and country codes managed through Merchant of Record Dodo Payments. Credit card numbers are handled directly by payment processors and are never received or stored on SheetFactorys servers.
  • Spreadsheet schema context: User-selected cell coordinates, column headers, and structural formulas submitted through the active sidebar for syntax compilation or data cleaning.
  • Workspace configuration: Custom global variable names, pinned formula snippets, and dashboard layout preferences explicitly saved by users to their private database workspace.

3. Zero-Model-Training Policy

Client spreadsheet data, prompt inputs, and returned calculations are processed through commercial enterprise API endpoints. Inputs and outputs are never utilized by GSquare Labs or its upstream infrastructure partners to train, retrain, or fine-tune public foundation models or machine learning algorithms. All formula and data cleaning queries run under enterprise terms that prohibit data retention for model improvements.

4. Technical Sub-Processors

Service delivery relies on four vetted cloud infrastructure partners:

  • Google LLC: Authentication state via Firebase Auth and language model inference through Google Gemini API enterprise endpoints.
  • OpenAI LLC: Secondary fallback processing for natural language interpretation and formula structure verification.
  • Supabase Inc: Managed PostgreSQL hosting in United States data centers with Row-Level Security isolating workspace configurations.
  • Dodo Payments Inc: Merchant of Record handling billing management, invoicing, tax compliance, and payment settlement.

5. Data Retention & Automatic Purge

Transient spreadsheet processing data is purged from memory immediately upon completion of the HTTP response. Saved user preferences, global variables, and generated dashboard templates persist until deleted by the user. Free tier accounts inactive for longer than 60 consecutive days are flagged for automated deletion to minimize unnecessary data storage. Accounting transaction records are maintained in accordance with statutory financial compliance periods.

6. Statutory Privacy Rights (GDPR & CCPA)

Users in the European Economic Area, the United Kingdom, and California hold statutory rights regarding personal data. These include the right to inspect personal information on file, request rectification of inaccurate records, obtain a portable machine-readable copy of stored configurations, and request complete account deletion. Requests can be executed directly inside the user settings interface or by emailing privacy@sheetfactorys.com.

7. Google Workspace API Data Policy

The Google Sheets add-in requests narrow authorization scopes, primarily spreadsheets.currentonly, to operate strictly on the active sheet open in the user's browser.

  • No commercial disclosure: Google user data is never sold, traded, rented, or transferred to advertising networks or broker registries.
  • Operational transfers only: Transmission of sheet data occurs solely between authenticated client browsers, the backend processing application, and approved API sub-processors to calculate requested outputs.
  • No model training: Information accessed via Google Workspace APIs is never retained to build or tune artificial intelligence models.
  • Google Limited Use compliance: SheetFactorys adheres to the Google API Services User Data Policy, including all Limited Use requirements.

8. Technical Safeguards for Sensitive Information

The backend architecture implements defense-in-depth measures to protect transmitted information:

  • Cryptographic transport: External network communications require TLS 1.3 / HTTPS encryption to prevent interception.
  • Storage security: Database volumes and persistent configuration objects use AES-256 encryption at rest.
  • Tenant isolation: Database queries enforce PostgreSQL Row-Level Security (RLS) rules tied to authenticated account tokens.
  • Buffer sanitation: In-memory cell vectors and calculation payloads are systematically cleared upon request completion.

9. Microsoft 365 & Office.js Integration Policy

The Microsoft Excel add-in uses client-side Office.js APIs to read and insert formulas within the active workbook window.

  • Local execution boundary: The add-in does not request tenant-wide Microsoft Graph administrator privileges or access files outside the active open workbook.
  • Confidentiality standard: Microsoft user data is never shared with third-party advertisers or data brokers.
  • API security: Workbook cell payloads submitted for syntax generation are encrypted during transport and processed transiently in memory.
  • Training restriction: Content extracted through Office.js APIs is strictly excluded from machine learning training routines.

10. Privacy Inquiries & Data Requests

Inquiries regarding data practices, export requests, or erasure demands should be submitted in writing to the privacy office:

privacy@sheetfactorys.com

Reference: Data Subject Access Request