Privacy Policy

SheetAudit Privacy Policy

Last updated: 19 November 2025

SheetAudit (“we”, “us”, “our”) is owned and operated by Yod Solutions Pty Ltd (ABN 672 231 515). We provide a spreadsheet auditing platform that allows users to analyze Excel and CSV files locally in their browser. We are committed to protecting your privacy and being transparent about how your data is collected, stored, and used.

1. Overview

SheetAudit (“we”, “us”, “our”) is owned and operated by Yod Solutions Pty Ltd (ABN 672 231 515). We provide a spreadsheet auditing platform that allows users to analyze Excel and CSV files locally in their browser. We are committed to protecting your privacy and being transparent about how your data is collected, stored, and used.

2. What Data We Collect

2.1 Personal Information You Provide

When you create an account, we collect:

  • Email address
  • Hashed password (we never store plain-text passwords)
  • User name
  • Company or organisation name (optional)
  • Stripe Customer ID (when you subscribe to a paid plan)

2.2 Usage Information

We store limited usage metadata, including:

  • Audit usage count (how many audits you have run)
  • AI summary / LLM usage count
  • Subscription tier and limits

2.3 Payment Information

Payments are processed by Stripe. We do not store or process payment card details on our servers. We store only:

  • Stripe customer ID
  • Subscription status
  • Renewal dates

Stripe’s own privacy policy applies to your payment information.

3. Spreadsheet Data and Privacy

3.1 Local-First Processing

  • Workbooks are parsed and audited entirely in your browser.
  • Spreadsheet contents are never uploaded to our servers.
  • Structural analysis (formula patterns, ranges, errors, duplicates, etc.) happens locally using in-browser compute (Web Workers and WebAssembly).
  • Sheets remain stored in memory only on your device during a session.

3.2 AI Summaries

  • Only structured metadata from audit findings (e.g., “Column F: inconsistent formula pattern”, severity, sheet names, row ranges) is sent to our AI worker.
  • No cell values or file contents are ever transmitted for AI summaries.
  • We do not store the structured metadata sent to the AI model after the request is completed, other than aggregated usage counts.

4. Cookies, Analytics, and Tracking

We use analytics and advertising tools to understand product usage and measure marketing performance. These include:

  • Cloudflare Web Analytics
  • Google Analytics (GA4)
  • Google Ads Conversion Tracking
  • Meta Ads (Facebook) Conversion Tracking

These tools may use cookies or similar technologies to collect information such as:

  • Device and browser details
  • Pages visited and navigation events
  • Approximate location (e.g. city or region)
  • Referring website
  • Time spent on pages
  • Conversion events related to our marketing campaigns

No spreadsheet content, file data, or raw audit results are ever included in analytics or advertising tracking.

Where possible, we use privacy-enhancing methods such as Cloudflare Zaraz server-side tracking to minimise or avoid the use of client-side advertising cookies. This reduces the amount of personal data shared with advertising platforms.

You may opt out of personalised advertising using the tools provided by:

5. How We Store Data

We use the Cloudflare platform for hosting and data storage:

  • Cloudflare D1 – stores account data, usage counts, and subscription metadata.
  • Cloudflare KV – stores session data and access tokens.
  • Cloudflare Workers – handle API endpoints, authentication, and authorization logic.

We retain:

  • Account data until the user requests deletion, or until it is no longer needed for the purposes described in this policy.
  • Subscription and billing metadata for as long as required for legal, accounting, or reporting obligations.

6. Sharing of Data

We do not sell or rent your personal data. We share data only with:

  • Stripe, for subscription billing and payment processing.
  • AI provider(s) (e.g. OpenAI, Google) when generating AI summaries, and only in the form of structured metadata, not raw spreadsheet contents.
  • Cloudflare, as our infrastructure and hosting provider.

These third parties process data on our behalf in accordance with their own privacy policies and applicable law.

7. Data Security

We use a range of technical and organisational measures to protect your data, including:

  • HTTPS encryption for all network traffic
  • Secure password hashing for account credentials
  • Signed tokens and short-lived authorization for audit operations
  • Least-privilege access to internal systems
  • No spreadsheet content is stored on our servers as part of normal operation

Despite these protections, no method of transmission or storage is completely secure. You use the Service at your own risk.

8. Data Retention and Deletion

You may request deletion of your account and personal data at any time by emailing support@sheetaudit.com.

Upon deletion:

  • Your account and associated personal data will be permanently removed or anonymized, except where we are required to retain certain data for legal or accounting reasons.
  • Any active Stripe subscription will be cancelled.
  • Usage metrics associated with your account will be deleted or anonymized.
  • Once deleted, your account cannot be restored.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction or updating of your personal information.
  • Request deletion of your personal information, subject to legal obligations.
  • Object to certain processing or withdraw consent (for example, by deleting your account or disabling analytics via browser settings).

To exercise any of these rights, contact us at support@sheetaudit.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. If changes are material, we may provide additional notice (e.g. in-app or by email). Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact: