Privacy Policy
Plain-English first, legally accurate throughout. This page describes what actually happens to your data — no more, no less.
The short version
Files are parsed in your browser; for analysis, your dataset is processed transiently by our AI engine in an isolated code-execution sandbox and is never used to train models. Your data is not stored unless you create a report — reports live at an unguessable link, are hidden from search engines, and can be deleted at any time. We keep anonymous aggregate usage counts (dataset size band, column category, question type) to guide what we build — never your files, column names, or question text. We do not sell your data, we do not run advertising, and we collect the minimum needed to run the service.
What happens to an uploaded file
- Parsing — in your browser. When you drop a CSV, Excel, JSON, or TSV file, your browser reads and parses it locally. No upload happens at this stage.
- Analysis — transient processing. When you ask a question, your dataset is sent over an encrypted connection to our analysis engine, which executes Python against it in an isolated code-execution sandbox via our AI provider's API (OpenAI, with Google Gemini as fallback). Processing is transient: the data exists there only for the duration of the request.
- No training, ever. We use API-tier access with both providers — governed by OpenAI's API data-usage policy and Google's API Terms and Data Processing Addendum — under which your data is not used to train AI models.
- Storage — only if you create a report. Nothing is persisted unless you click "Generate report". A report stores the computed blocks (metrics, chart data, tables, text and the code that produced them) and the dataset's name, column names, and row count — not the raw file. Anonymous reports expire automatically after 90 days.
- Usage measurement — shape, not content. So we can tell what to build and what to charge for, we record anonymous, aggregate counts of how the product gets used: which size band a dataset fell into, which category its column names matched from a fixed list we maintain, what kind of question was asked, whether the analysis succeeded, and how many questions were asked in a sitting. These are daily totals — not records about you. Your file, your actual column names, and the text of your question are never stored or logged. This can tell us that people analyze marketing data more than survey data; it cannot tell us anything about you.
Report share links
Reports live at unguessable URLs, are excluded from search engines by default, and are visible to anyone who has the link — treat the link like the document itself. The creator's edit key can update or permanently delete a report at any time.
Google user data (Search Console & Analytics connections)
If you connect Google Search Console or Google Analytics, we request read-only access (scopes: webmasters.readonly, analytics.readonly) and use it for exactly one purpose: pulling the performance data you ask for into your workspace so the engine can analyze it and build your report. We store the OAuth tokens server-side, encrypted at rest by our storage provider, keyed to an opaque connection ID in your browser; the pulled data itself is processed in memory and saved only if you generate a report. We never use Google user data for advertising, never sell it, and never let humans read it except with your permission for support. Disconnecting removes the stored tokens; connections expire automatically after 180 days.
AnalyzeData's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers
- OpenAI API — runs the analysis computation (code execution), under API-tier data-usage terms (no training on your data).
- Google Gemini API — fallback analysis engine, under API-tier data protection terms (no training on your data).
- Vercel — hosts the site and provides aggregate, cookie-free web analytics.
- Upstash Redis — stores reports you create and enforces rate limits (10 analyses per day per IP; the IP record expires within 24 hours).
Your rights
You can delete any report you created, and you can contact us to request deletion of anything else associated with you. Since we store no accounts today and almost no personal data, most requests are satisfied immediately. Reach us via the contact page.
Changes
If this policy changes materially, we will update this page and its effective date. Effective: July 2026.