Privacy Policy
This Privacy Policy explains how Code Crafters ("Sheet
Intelligence", "we", "us") collects, uses, shares, and protects information when you use
the Sheet Intelligence add-on for Google Sheets™, the browser add-in for
Microsoft Excel™, and the website at sheetintelligence.app (together, the "Service"). Sheet Intelligence
is an AI assistant that helps you read, analyze, and edit the spreadsheet you have open,
with your approval for every change.
Contact: info@sheetintelligence.app · Code Crafters, No. 44, Galle Road, Colombo 03, Sri Lanka.
Preview availability: Both integrations are in private preview. Existing users can sign in to the website to manage their account, subscription, and data. Signing in to this website does not install either integration or grant workbook access. Public marketplace installation is not available yet.
1. Google user data we access
Sheet Intelligence works inside the workbook you open it in, and it reads every tab of that workbook — not just the tab you happen to be looking at. That is how the assistant profiles your data before it answers.
To do this, we request the Google Sheets scope spreadsheets. Please read this
plainly: it is a broad scope. On the Google consent screen it appears as
access to your Google Sheets spreadsheets — not just the open one. We request it
because our backend reads your workbook through the Google Sheets API, and
the narrower "current document only" scope does not authorize that API at all.
So the permission Google grants us is wider than what we actually do with it. Here is what we actually do, and what we commit to:
- We access only the spreadsheet you have open the add-on in (and any file you explicitly pick). We do not browse, list, search, or open your other spreadsheets.
- We do not access your Gmail, your Calendar, or your Drive at large.
- Within the workbook you open, we do read every tab — see the table below for exactly which parts.
This is a commitment about our conduct, not a technical limit imposed by the scope. You can review or revoke this access at any time at myaccount.google.com/permissions.
| Data | Google scope | Why |
|---|---|---|
| The content of the spreadsheet you open the add-on in — across all of its tabs: cell values, formulas, formatting, cell notes, charts, named ranges, and tab names | spreadsheets |
So the assistant can profile the whole workbook, analyze it, and (with your approval) edit it. This scope also permits access to your other spreadsheets; we do not use it that way — see the commitment above. |
| Files you explicitly open or share with the add-on | drive.file |
To render/export a range of the spreadsheet you are working in as a PDF, so the assistant can visually check its own work. Grants access only to files you pick — never your whole Drive |
| Your primary Google Account email address | userinfo.email, openid |
To sign you in and identify your account/subscription |
| Add-on UI + outbound requests to our service | script.container.ui, script.external_request |
To run the sidebar and send your request to our backend |
1a. Microsoft Excel™ user data we access
The browser add-in uses the host application's document permission
(ReadWriteDocument) to read workbook context and apply approved cell-value edits.
This permission is broader than the range selected for an individual request. The current
preview sends the selected range's cell values and formulas, range address, worksheet and
workbook context, and your prompt to our backend and AI provider. Selected ranges are limited
to 200 rows and 2,000 cells. Proposed value edits require your approval before the add-in
writes them to the workbook.
Sign-in uses the openid, profile, and email identity
scopes. We use the identity information returned by Microsoft™ to create your service
session and identify your account and subscription. This sign-in does not request permission
to browse your files through Microsoft Graph™. Workbook access occurs through the add-in
inside the document you open. You can remove the add-in from the host application to stop
using it, and request account-data deletion using the controls or contact details below.
The data-use, AI-provider sharing, account storage, security, and deletion practices below also apply to this integration. Descriptions of reading all workbook tabs, rendered range images, and the Google™ permission scopes specifically describe the Google Sheets™ integration.
2. How we use your data
We use your data only to provide and improve the AI assistant features that are visible and prominent in the add-on — reading and analyzing the workbook you have open (within the context provided by the integration) and proposing edits to it, and maintaining your session, memory of preferences you ask us to remember, and your subscription. We do not use your data for advertising, and we do not sell or share it with data brokers.
3. How we share your data (sub-processors) — including the AI provider
To provide the Service we transfer your data to approved service providers ("sub-processors") under the applicable contracts and the processing described here. Our current sub-processor list is maintained at https://sheetintelligence.app/subprocessors.html.
- Anthropic, PBC (the "Claude" API). To generate the assistant's responses, content from the workbook you have open and your chat messages are sent to Anthropic's Claude API. That content can include cell values, formulas, and cell notes from any tab of that workbook — including tabs you are not looking at — and, when the assistant visually checks its own work, a rendered image of a range. This transfer is made under a zero-data-retention arrangement: Anthropic does not retain this data after processing your request and does not use it to train or improve any AI/ML model.
- Amazon Web Services (AWS). Our backend uses AWS in us-east-1 (United States) for hosting, databases, private storage, and semantic-search embeddings through Amazon Bedrock. It processes and stores Service data for the periods described in §4.
- Vercel. Hosts the website, customer dashboard and browser Excel task pane, with global delivery infrastructure. It can process account and website request metadata; workbook context is sent by the integration to our AWS API for AI processing.
- Lemon Squeezy for billing (name, email, subscription/payment metadata — not your spreadsheet content).
- Zoho Mail hosts our business correspondence. If you email us, it processes your address, message and any attachments. Please avoid including workbook content or sensitive information that is unnecessary for your enquiry.
- Cloudflare provides restricted access and security infrastructure for our Founder panel, including operator identity and request/security metadata.
Which AI providers your integration can use
We choose approved models internally; you do not need to select a model. Anthropic is the default and remains the currently enabled route at the date of this notice. The architecture can additionally support the following routes after contractual, security and quality review. A provider listed as supported or pending is not thereby authorized to receive your content.
- Google Sheets: Anthropic, OpenAI and paid Google Gemini APIs only. Google Workspace content and data derived from it are never routed to Kimi or DeepSeek, and are not provided for general-model training or improvement. Unpaid Gemini data-use terms are not used for this route.
- Microsoft Excel: the same providers, plus Kimi/Moonshot and DeepSeek when approved. Their processing and support locations may be outside the United States; our US AWS backend does not mean every recipient processes data in the US.
Retention differs from training. OpenAI's business API does not train on content by default, but may retain content for abuse monitoring unless an applicable account-specific exception applies. Paid Gemini terms exclude product/model-improvement use of prompts and responses but permit limited safety-related logging. We do not describe these routes as zero retention without supporting terms. Kimi's published API security FAQ states no training while its API agreement reserves broader rights; its account-specific conditions must be resolved in writing. DeepSeek's API-specific conditions must also be established. See the register for status and official sources.
Optional Microsoft training permission: if a reviewed Microsoft route permits provider model training or improvement, we explain that purpose, recipient and relevant data before use and ask for a separate, unchecked opt-in. Declining leaves approved non-training routes available; accepting general Terms or acknowledging this Policy is not that opt-in. Where authorized and enabled, submitted inputs, outputs and derived content may be used by that provider for training or improvement. Your permission does not waive another person's rights or replace an organization's lawful instructions, vendor contract or transfer safeguards. Such routes remain disabled until those requirements are met.
You can review or withdraw AI-processing or optional training permission in your account or add-on, or contact info@sheetintelligence.app. Withdrawal prevents subsequent eligible transfers; it cannot undo completed processing or necessarily remove information already incorporated into a trained model. We record the verified account, accepted document versions, timestamp and permission choices. We notify business customers before new subprocessors begin processing and provide the objection process described in the DPA.
We share data with third parties only: (a) to provide/improve the user-facing features above with your consent; (b) for security and anti-abuse; (c) to comply with law; or (d) in a merger or acquisition, after your explicit prior consent.
4. Retention and deletion
- Agreement and permission evidence: your account export includes your accepted versions, dates, notice snapshots and permission changes. Operational permission history is removed during fulfilled account erasure. A separate, minimal audit record of versions and choices may be retained for applicable legal obligations or the establishment, exercise or defence of claims, under our audit retention policy. It does not retain a second full notice snapshot or workbook content for this purpose.
- Spreadsheet content sent to AI providers: the existing Anthropic route uses the applicable zero-data-retention arrangement. Other approved routes have the retention conditions disclosed above and in the provider register; zero retention is not a blanket promise. Any training-capable Microsoft route requires the separate safeguards and optional permission described above.
- On our backend: we retain your conversation/session state (which can include portions of your spreadsheet the assistant read), your saved memory facts, an audit log of actions, undo checkpoints (a before-and-after copy of the cells each approved edit changed, so you can revert it), and, when you use workbook search, a search index built from your cell text. We keep these to operate the Service and to let you undo and resume your work. We keep this data for the life of your account and delete it within 30 days of account closure or a deletion request.
- Access / export: you can download a copy of your data (your chats, transcripts, and saved preferences) at any time from Account → Export my data in the add-on, or by emailing info@sheetintelligence.app.
- Deletion: you can request deletion from Account → Delete my data in the add-on, or by emailing info@sheetintelligence.app. We complete deletion — including backend copies — within one calendar month of your request (usually far sooner), and on account closure. Records we are required by law to keep (e.g. billing/tax records) are retained for the statutory period and then deleted. You can also revoke the add-on's access at myaccount.google.com/permissions.
5. Security
We use encrypted transport (HTTPS/TLS) and encryption at rest for our AWS data stores. Access is restricted and audited. These controls do not constitute a guarantee that every proposed provider has identical security or certification. Every spreadsheet change is proposed to you and applied only after you approve it.
6. Your rights
Depending on where you live (EU/UK GDPR, California CCPA/CPRA, and others) you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent. To exercise them, contact info@sheetintelligence.app; we respond within the time the law requires (one month under GDPR). For business customers, we act as a processor and will assist you (the controller) with your users' requests under our Data Processing Agreement.
7. Our launch notification list
If you give us your email address on our website to be told when the add-on becomes available, we store only that email address, the date you gave it, and which page it came from. We do not store your name, your IP address, or any tracking identifier alongside it.
Our lawful basis is your consent, given when you submit the form. We use it for one purpose only: to email you once, when the add-on is available. It is not a newsletter, and we do not use it for any other marketing or sell it. Vercel processes the list on our behalf in private storage in the United States. The list is not publicly accessible. You can withdraw your consent and have the address deleted at any time by emailing info@sheetintelligence.app — no reason required. We delete the address once the launch email has been sent, or on request, whichever comes first.
8. International data transfers
We are based in Sri Lanka and use sub-processors in the United States and other regions. Where your data is transferred out of the EEA/UK, we rely on an approved transfer mechanism — the EU-US Data Privacy Framework (where the importer is certified) and/or the 2021 EU Standard Contractual Clauses and the UK IDTA/Addendum, supported by a transfer risk assessment and supplementary measures where required. Each proposed recipient and onward transfer is reviewed before activation; a US hosting location or training opt-in does not itself provide a transfer mechanism. No certification is claimed for a recipient merely because it appears in our provider register.
9. Children
The Service is for business use and is not directed to children under 16.
10. Changes
We will post changes here and update the "Last updated" date; material changes will be notified by email.
11. Google Limited Use disclosure
Sheet Intelligence's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Consistent with that policy, we affirm we do not use your Google Workspace data to create, train, or improve any generalized or foundational artificial-intelligence or machine-learning model — your data is used only to power the assistant features you invoke, for you.