Privacy Policy
Last updated 2 October 2026
We keep your spreadsheets for 30 days so you can reopen past analyses, then delete them. They are analysed in an isolated sandbox with no internet access that is destroyed after each run. We study our own mistakes — including the files that caused them — so the product gets better at files like yours, and you can switch that off in Settings at any time. We never use your data to train any model, and we never sell it.
Who we are
DataMimi is an analysis tool for spreadsheets. This policy covers the DataMimi web application and the processing that happens when you upload a file to it. Contact us at privacy@datamimi.com about anything here.
What we collect
Files you upload
The spreadsheet itself, and the cleaned table we derive from it. We store the cleaned version rather than your original because it is what later questions are answered against, and re-deriving it each time could produce a different result than the one you already reviewed.
Your questions and our answers
The questions you ask, the analysis code generated to answer them, the results, and the credits each cost. This is what lets you reopen a past analysis and what makes your usage visible to you.
Account information
Your email address and display name, from whichever sign-in method you choose. We do not store passwords — authentication is handled by Clerk, and if you sign in with Google we never see your Google credentials.
Usage and billing records
Which analyses ran, what they cost us, and your subscription status. If you have not signed in, we keep a salted hash of your IP address to count free trial usage. The address itself is never stored, and the hash cannot be reversed into one.
If you use DataMimi without signing in, we also keep what you asked and did — the questions you typed, the names and sizes of the files you brought, and which free tool you used — so we can see what people expect from the product and where it falls short. We keep the values inside your file out of this record, and we tie it only to the same unreadable hash. If you ask us to email you a link back to your file, we keep that address with the record and send that one email; we do not add it to a mailing list.
On our public pages we set two first-party cookies for up to 90 days. dm_first holds the path of the first page you visited — for example /analyse/quickbooks-report. dm_src holds where that visit came from: the referring website's domain only (such as google.com, never the full address or what you searched for) and any campaign tags in the link (utm_source, utm_medium, utm_campaign). If you create an account, both are saved with it so we can tell which pages and channels lead to sign-ups. They contain nothing about you, and no third party reads them.
How long we keep it
| What | Kept for |
|---|---|
| Uploaded spreadsheets and cleaned data | 30 days, then deleted automatically |
| Questions, answers and saved reports | Until you delete them or close your account |
| Account details | Until you close your account |
| Billing records | 7 years, as tax law requires |
| Free-trial usage counters | 30 days |
| Questions and file names from visitors who have not signed in | 180 days |
Closing your account deletes your files, analyses and saved reports immediately. Billing records are the exception — we are required to keep those.
How your file is analysed
When you ask a question, an AI model writes Python code to answer it. That code runs in an isolated sandbox — a separate virtual machine with:
- no internet access, so nothing in it can send your data anywhere;
- a hard time limit on every run;
- destruction after the analysis, along with everything inside it.
The model that writes the code sees a description of your columns — their names, types and a small preview — not your full dataset. The computation itself happens in the sandbox, on our infrastructure.
What we never do
- Train models on your data. Not ours, not anyone else's. Our model providers are contractually bound not to train on data sent through their APIs.
- Sell your data. Not to advertisers, not to data brokers, not to anyone, at any price.
- Share your data outside the providers who run our infrastructure. Those are listed by name further down, each one under contract to process data only on our instructions. Nobody else receives it.
How we use your data to improve DataMimi
DataMimi improves by studying its own mistakes. When an analysis comes out wrong, we look at what happened: the question you asked, the code our system generated, the structure of your file, and — where it is necessary to understand the fault — the contents of the file itself.
This is the whole reason the product gets better. A construction estimate was once answered with “this file has no cost data” when it plainly had cost data on every row; a chart was once labelled with a total where the answer should have been. Both were found because somebody complained. Most people do not complain — they leave, and the fault stays.
What we learn is written as internal guidance for handling files like yours: a note that section headings in Vietnamese estimates span the whole row, that a particular export leaves its totals uncalculated. Your file is never the guidance. The lesson is, and the lesson contains no figure, no name and no row from your data.
What this does not mean
- We do not train AI models on your data. Not our own, not anyone else’s. Our model providers are contractually bound not to train on anything sent through their APIs.
- We do not show your data to anyone outside DataMimi beyond the infrastructure providers listed below, who process it on our instructions alone.
- No human browses your files for interest. A file is opened when a fault points at it, and for that fault.
Turning it off
It is on by default, and it is one switch: Settings → Your data → Help improve DataMimi. Turn it off and we stop, for everything in that workspace, immediately. Nothing else about your account changes — no feature is withheld, no price moves, and we will not ask you again.
When you mark an answer unhelpful, the reason you pick and anything you write go to the person fixing it, along with a link to that analysis. That happens whichever way the switch is set, because you chose to tell us.
Who processes data on our behalf
| Provider | What for |
|---|---|
| Cloudflare | Hosting, database, file storage and the analysis sandbox |
| Clerk | Sign-in and account security |
| OpenRouter | Routing requests to AI model providers |
| Paddle | Payments — they are the merchant of record and hold your payment details |
We never see your card details. Paddle handles payment entirely and we receive only whether a subscription is active.
Where data is held
Primarily in the United States and the European Union, depending on the provider. If you need data held in a specific region, contact us before subscribing — we would rather tell you we cannot than have you find out afterwards.
Your rights
You can, at any time:
- see everything we hold about you, from Settings;
- delete any file, analysis or saved report;
- delete your account and all of its data;
- ask us for a copy of your data in a portable format;
- object to processing, or ask us to restrict it.
Email privacy@datamimi.com and we will respond within 30 days. If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.
Security
- Everything travels over HTTPS and is encrypted at rest.
- Uploaded files are stored privately — there is no public URL to any of them.
- Analysis runs in an isolated sandbox with no network access.
- Access to production systems requires a verified administrator account signed in with Google, and administrator changes are recorded in an audit log.
No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you what happened and what we are doing about it, without waiting until we have a complete picture.
Children
DataMimi is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
If we change this policy in a way that affects how we handle your data, we will tell you by email before it takes effect — not by quietly updating the date at the top.

