Security
Last updated 12 September 2026
Your files are stored privately, never at a public address, and deleted automatically after 30 days. Every analysis runs in an isolated container with no internet access that is destroyed when the run ends. The AI model that writes the analysis sees your column names and a small preview, not your whole file, and every answer shows which sheet, columns and rows its figures came from.
Where your files are stored
Uploaded spreadsheets, and the cleaned tables derived from them, are stored in private object storage on Cloudflare. There is no public URL to any file: a file is read by the application on behalf of the signed-in workspace that uploaded it, and requests for another workspace's file are refused.
Data travels over HTTPS, and Cloudflare encrypts stored data at rest.
How long files are kept
| What | Kept for |
|---|---|
| Uploaded files and cleaned data | 30 days, then deleted by a scheduled job |
| Generated files (decks, reports, exports) | 30 days, unless you save them to your library |
| Free-trial usage counters | 30 days |
Cleaning a file never changes the original: the cleaned copy is stored as a new file, and the original stays exactly as uploaded until it expires.
How an analysis runs
When you ask a question, an AI model writes Python code to answer it. That code runs inside an isolated container:
- No internet access. The container cannot open a network connection, so code running against your data has nowhere to send it.
- A fresh container per run. Your file is copied in for that analysis, and the container is destroyed when the run ends.
- A hard time limit on every run.
What the AI model sees
To write the analysis, the model receives a description of your data — sheet and column names, column types and a small preview of rows — and your question. The calculation itself happens in the container, on your full file, not inside the model.
When you press Explain on a chart, the figures shown in that chart are sent so they can be described in words. DataMimi does not train models on your data.
Answers you can check
- Every answer carries a source line: the file and sheet, the columns used — checked against what the code actually read — any filters, and how many rows the figures were computed over.
- Cleaning is previewed with real before-and-after examples, and nothing changes until you choose what to apply.
- An analysis that fails is not charged.
Accounts and payments
- Sign-in is handled by Clerk. DataMimi never stores your password, and signing in with Google never shares your Google credentials with us.
- Payments are handled by Paddle, the merchant of record. DataMimi never sees or stores card details.
- Administrator changes to limits and settings are recorded in an audit log.
Who processes data on our behalf
| Provider | What for |
|---|---|
| Cloudflare | Hosting, database, file storage and the analysis containers |
| Clerk | Sign-in and account security |
| OpenRouter | Routing requests to the AI model providers that write and explain analyses |
| Paddle | Payments, as merchant of record |
Reporting a vulnerability
If you find a security problem, email support@datamimi.com with the details. Please give us a reasonable chance to fix it before disclosing it publicly. For how we handle personal data more broadly, see the privacy policy.

