Privacy & Trust Center

Privacy Policy

Last Updated: 26 July 2026

Zero Data Training

Your spreadsheet cells and prompts are transient and never used to train public AI models.

Secure Protocols

All active data in transit is protected using enterprise-grade TLS 1.3 encryption.

Full Data Ownership

You retain 100% ownership of your input datasets, custom scripts, and saved analysis results.

1. Introduction

Welcome to SheetFactorys. This Privacy Policy describes how GSquare Labs, a registered sole proprietorship in Gujarat, India, with its registered office address at 1650, 1st Floor, Girdhar Gopal Bldg, Shastrinagar Main Rd, Jadiya Wadi, Surat - 395002, Gujarat, India (operating under the brand name "SheetFactorys", "we", "us", or "our"), collects, processes, secures, and governs your personal information when you visit our website, register an account, and use our AI-powered spreadsheet plugins for Google Sheets and Microsoft Excel. We respect your privacy and are committed to protecting your personal data.

2. Data We Collect & How We Use It

To provide our automation features, we process different categories of information depending on your interaction with our Service:

  • Account Identity Credentials: We collect your name, email address, and profile picture during registration to manage auth sessions via Google Firebase Auth.
  • Subscription & Payment Data: All transactions are securely processed by our Merchant of Record, Paddle. SheetFactorys does not store or process credit card numbers directly. We receive transaction references, billing country, and subscription status flags.
  • Spreadsheet Processing Context: When you generate formulas, translate syntax, clean datasets, or create dashboards, the target spreadsheet structure (headers, cell data selection, metadata) is securely processed.

3. Zero-Data-Training Policy

We strictly enforce a Zero Data Training rule. All inputs and cell calculations routed through our LLM services (including Google Gemini API) are transient. They are used solely to compute the formula, build the dashboard, or translate code in real-time, and are not logged or stored persistently on public AI models. Pinned formulas, variables, and saved reports are stored within your private account space in our database and are never made public without your action.

4. Third-Party Processors & AI Data Handling

We collaborate with select, highly secure third-party processors to operate our services. To ensure high availability, system redundancy, and continuous service uptime, our core application utilizes a multi-model fallback architecture. Depending on model availability, system limits, or performance optimization, user prompts and spreadsheet data selections may be routed securely through any of the following enterprise AI infrastructure providers:

  • Google Gemini API (Google LLC): Primary backend processing of natural language queries and formula computations.
  • OpenAI API / ChatGPT (OpenAI, LLC): Secondary fallback processor for text generation, formula handling, and data automation.
  • Anthropic Claude API (Anthropic PBC): Secondary fallback processor for advanced analysis and code translation context.

Data Protection Standards across AI Providers:

All inputs, prompts, and cell calculations routed through our LLM services are entirely transient. Data sent to Google Gemini, OpenAI, and Anthropic via our application is processed strictly under their respective enterprise privacy terms. This means your inputs are used solely to compute your request in real-time and are never logged, stored persistently, or utilized by any third party to train public AI or machine learning models.

Other core service processors we utilize include:

  • Firebase (Google): Authentication, user session management.
  • Supabase (PostgreSQL): Storage of saved dashboards, variables, and user configuration.
  • Paddle.com: Order processing, subscription billing, customer invoicing, and reseller services.

5. GDPR & CCPA Compliance (Data Rights)

If you reside in the European Economic Area (EEA) or California, you are entitled to specific data subject protection rights. You may request access to, correction of, transfer of, or permanent erasure of your personal data stored within our system. Users can trigger complete profile deletions at any time directly through the Settings panel.

Data Isolation & Instant Deletion: Our core application architecture utilizes secure, enterprise-grade United States infrastructure. We strictly enforce data minimization: all user-deleted client configurations, private variables, and custom datasets are purged instantly from our active application systems upon user command, with backup cycles completely overwritten within standard retention windows.

6. GOOGLE USER DATA SHARING, TRANSFER, AND DISCLOSURE

We are committed to maintaining the absolute confidentiality of the integration data you provide via Google Workspace APIs and Google Sheets.

No Commercial Sharing or Sale: We strictly do not sell, trade, rent, lease, or disclose your Google user data to any outside parties, including advertising networks, data brokers, or marketing companies.

Authorized Transfers & Disclosures: We do not share, transfer, or disclose Google Workspace user data to any unauthorized third parties. Google user data is only shared with our core hosting infrastructure (Google Firebase for authentication, Supabase for PostgreSQL database storage) and AI sub-processors (such as Google Gemini API, OpenAI API, and Anthropic Claude API) strictly for the purpose of providing, executing, and supporting the application's core automated spreadsheet features requested by the user.

Prohibition on AI Training: Under no circumstances is user data obtained via Google Workspace APIs used to train, retrain, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models.

SheetFactorys' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. DATA PROTECTION & SECURITY MECHANISMS FOR SENSITIVE GOOGLE DATA

We implement robust technical and organizational security mechanisms specifically designed to protect your sensitive Google user data from unauthorized access, alteration, disclosure, or destruction:

  • Data Encryption in Transit: All sensitive Google user data, spreadsheet selections, and API transmissions are encrypted in transit using enterprise-grade Transport Layer Security (TLS 1.3 / HTTPS) cryptographic protocols.
  • Data Encryption at Rest: Sensitive Google data stored within our persistent configuration space is protected at rest using robust AES-256 encryption standards.
  • Database Row-Level Security (RLS): Strict access controls are enforced at the database layer. PostgreSQL Row-Level Security policies completely isolate each user's authenticated Google workspace records.
  • Transient AI Processing: User prompts and spreadsheet data routed to AI model endpoints (Gemini, OpenAI, Anthropic) for execution are processed transiently in-memory and are never stored or logged persistently by the AI infrastructure.

8. MICROSOFT USER DATA POLICY & SECURITY MECHANISMS

We are committed to maintaining the absolute confidentiality of the integration data you provide via Microsoft 365 APIs, Microsoft Identity, and Microsoft Excel.

No Commercial Sharing or Sale: We strictly do not sell, trade, rent, lease, or disclose your Microsoft user data to any outside parties, including advertising networks, data brokers, or marketing companies.

Local Integration Scope: The SheetFactorys Excel add-in operates locally within your active Excel application workspace. We do not request tenant-wide Microsoft Graph administration scopes or access files stored outside the active, open workbook. All reading and writing is performed via local Office JavaScript API calls under your authenticated session.

Data Protection & Access Control: All sensitive Microsoft user data, spreadsheet selections, and API transmissions are encrypted in transit using TLS 1.3 / HTTPS cryptographic protocols and encrypted at rest using AES-256 standards. Microsoft 365 user data is only shared with our core hosting infrastructure and secure AI sub-processors (Google Gemini API, OpenAI API, Anthropic Claude API) solely for the purpose of providing, executing, and supporting the application's core automated spreadsheet features. Under no circumstances is Microsoft user data used to train, retrain, or fine-tune generalized AI or machine learning models.

9. Contact information

For privacy-related inquiries, data access requests, or policy questions, please contact our Data Protection Officer at:

support@sheetfactorys.com

Subject: Data Privacy Inquiry