Privacy Policy
Last updated 20 August 2026
We keep your spreadsheets for 30 days so you can reopen past analyses, then delete them. They are analysed in an isolated sandbox with no internet access that is destroyed after each run. We never use your data to train any model, and we never sell it.
Who we are
DataMimi is an analysis tool for spreadsheets. This policy covers the DataMimi web application and the processing that happens when you upload a file to it. Contact us at [email protected] about anything here.
What we collect
Files you upload
The spreadsheet itself, and the cleaned table we derive from it. We store the cleaned version rather than your original because it is what later questions are answered against, and re-deriving it each time could produce a different result than the one you already reviewed.
Your questions and our answers
The questions you ask, the analysis code generated to answer them, the results, and the credits each cost. This is what lets you reopen a past analysis and what makes your usage visible to you.
Account information
Your email address and display name, from whichever sign-in method you choose. We do not store passwords — authentication is handled by Clerk, and if you sign in with Google we never see your Google credentials.
Usage and billing records
Which analyses ran, what they cost us, and your subscription status. If you have not signed in, we keep a salted hash of your IP address to count free trial usage. The address itself is never stored, and the hash cannot be reversed into one.
How long we keep it
| What | Kept for |
|---|---|
| Uploaded spreadsheets and cleaned data | 30 days, then deleted automatically |
| Questions, answers and saved reports | Until you delete them or close your account |
| Account details | Until you close your account |
| Billing records | 7 years, as tax law requires |
| Free-trial usage counters | Reset daily |
Closing your account deletes your files, analyses and saved reports immediately. Billing records are the exception — we are required to keep those.
How your file is analysed
When you ask a question, an AI model writes Python code to answer it. That code runs in an isolated sandbox — a separate virtual machine with:
- no internet access, so nothing in it can send your data anywhere;
- a hard time limit on every run;
- destruction after the analysis, along with everything inside it.
The model that writes the code sees a description of your columns — their names, types and a small preview — not your full dataset. The computation itself happens in the sandbox, on our infrastructure.
What we never do
- Train models on your data. Not ours, not anyone else's. Our model providers are contractually bound not to train on data sent through their APIs.
- Sell your data, or share it with advertisers.
- Read your files except where you ask us to help with a specific problem and give us permission.
Who processes data on our behalf
| Provider | What for |
|---|---|
| Vercel | Hosting, file storage and the analysis sandbox |
| Neon | Database — accounts, analyses, billing records |
| Clerk | Sign-in and account security |
| OpenRouter | Routing requests to AI model providers |
| Paddle | Payments — they are the merchant of record and hold your payment details |
We never see your card details. Paddle handles payment entirely and we receive only whether a subscription is active.
Where data is held
Primarily in the United States and the European Union, depending on the provider. If you need data held in a specific region, contact us before subscribing — we would rather tell you we cannot than have you find out afterwards.
Your rights
You can, at any time:
- see everything we hold about you, from Settings;
- delete any file, analysis or saved report;
- delete your account and all of its data;
- ask us for a copy of your data in a portable format;
- object to processing, or ask us to restrict it.
Email [email protected] and we will respond within 30 days. If you are in the EU or UK and are unhappy with our response, you may complain to your local data protection authority.
Security
- Everything travels over HTTPS and is encrypted at rest.
- Uploaded files are stored privately — there is no public URL to any of them.
- Analysis runs in an isolated sandbox with no network access.
- Access to production systems requires a verified administrator account with multi-factor authentication, and every privileged action is logged.
No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you what happened and what we are doing about it, without waiting until we have a complete picture.
Children
DataMimi is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
If we change this policy in a way that affects how we handle your data, we will tell you by email before it takes effect — not by quietly updating the date at the top.