Privacy Policy
Plain-English first, legally accurate throughout. This page describes what actually happens to your data — no more, no less.
The short version
Files are parsed in your browser. For analysis, the full CSV runs in a disposable Vercel Sandbox; your question, column information, a small sample and computed results are processed by the selected AI provider (DeepSeek or Z.AI) to prepare the program and report. We stop the execution workspace after use and do not save it as a reusable snapshot. Provider retention follows their own terms. We store reports only when you choose to create them: reports use unguessable links, are hidden from search engines and can be deleted. We also keep aggregate usage measurements; see our privacy policy for details. We do not sell your data, we do not run advertising, and we collect the minimum needed to run the service.
What happens to an uploaded file
- Parsing — in your browser. When you drop a CSV, Excel, JSON, or TSV file, your browser reads and parses it locally. No upload happens at this stage.
- Analysis — transient processing. When you ask a question, your dataset is sent over an encrypted connection to our analysis engine, which executes Python against the full CSV in a disposable Vercel Sandbox. Your question, column information, a small sample, and the computed results are sent to the selected AI provider (DeepSeek or Z.AI) to prepare the program and report. Each execution environment is stopped after use and is not saved as a reusable data snapshot. The execution has no network access or API keys.
- AI and execution providers. We do not train models on your uploads. The selected AI provider and Vercel process the information described above under their own service and privacy terms. Our temporary-workspace cleanup does not override provider retention policies. Do not submit data you are not permitted to share with these processors.
- Storage — only if you create a report. Nothing is persisted unless you click "Generate report". A report stores the computed blocks (metrics, chart data, tables, text and the code that produced them) and the dataset's name, column names, and row count — not the raw file. Anonymous reports expire automatically after 90 days.
- Usage measurement — shape, not content. So we can tell what to build and what to charge for, we record anonymous, aggregate counts of how the product gets used: which size band a dataset fell into, which category its column names matched from a fixed list we maintain, what kind of question was asked, whether the analysis succeeded, how many questions were asked in a sitting, and which category of site referred the visit (a search engine, an AI assistant, a social network — derived from the referrer hostname, never a full URL), and a coarse country grouping (three purchasing-power tiers, never the individual country of a request). We also count what the engine produced (which block and chart types an answer contained, and which of our AI providers wrote it), whether a follow-up question was a re-phrasing of the previous one (judged in your browser by word overlap — only a yes/no travels), and how long someone had waited if they left mid-analysis. Nothing you type is ever part of these counts. The AI that composes your results also writes a short, generic-word description of the dataset's topic and the question's goal (like "monthly sales by region" or "compare revenue across stores") under a strict format that forbids names, numbers, and your own wording; phrases that pass that filter are kept for 90 days, and anything that fails it is discarded. For reports you choose to save, we compute aggregate statistics across many reports (common column words, chart types) — a word can only appear in those summaries when it occurs in several different people's reports. These are daily totals — not records about you. Your file, your actual column names, and the text of your question are never stored or logged. This can tell us that people analyze marketing data more than survey data; it cannot tell us anything about you.
Report share links
Reports live at unguessable URLs, are excluded from search engines by default, and are visible to anyone who has the link — treat the link like the document itself. The creator's edit key can update or permanently delete a report at any time.
Google user data (Search Console & Analytics connections)
If you connect Google Search Console or Google Analytics, we request read-only access (scopes: webmasters.readonly, analytics.readonly) and use it for exactly one purpose: pulling the performance data you ask for into your workspace so the engine can analyze it and build your report. We store the OAuth tokens server-side, encrypted at rest by our storage provider, keyed to an opaque connection ID in your browser; the pulled data itself is processed in memory and saved only if you generate a report. We never use Google user data for advertising, never sell it, and never let humans read it except with your permission for support. Disconnecting removes the stored tokens; connections expire automatically after 180 days.
AnalyzeData's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers
- OpenAI API — runs the analysis computation (code execution), under API-tier data-usage terms (no training on your data).
- Google Gemini API — fallback analysis engine, under API-tier data protection terms (no training on your data).
- Vercel — hosts the site and provides aggregate, cookie-free web analytics.
- PostHog — product analytics, configured cookieless (nothing stored on your device, no consent banner needed), no session recording, no autocapture; we send only pageviews and the same named product events described above.
- Upstash Redis — stores reports you create and enforces rate limits (10 analyses per day per IP; the IP record expires within 24 hours).
Your rights
You can delete any report you created, and you can contact us to request deletion of anything else associated with you. Since we store no accounts today and almost no personal data, most requests are satisfied immediately. Reach us via the contact page.
Changes
If this policy changes materially, we will update this page and its effective date. Effective: July 2026.