Privacy Policy
Effective 1 November 2025
This Privacy Policy explains how sheet2sql (the “Service”) processes information in connection with the sheet2sql.com website and the early-access preview of our AI-powered spreadsheet-to-SQL tool.
By using the Service, you agree to this Policy. This document is designed to be clear and pragmatic for a limited, pre-release test while covering essential legal obligations, including for EU/UK users.
Who We Are
- Controller: Álvaro José Jiménez Palenzuela
- Site: https://sheet2sql.com
- Contact: contact@sheet2sql.com
Scope
This Policy applies to: (a) spreadsheet files you submit to the Service, (b) prompts/outputs exchanged with our AI models, and (c) limited personal information you choose to provide (e.g., your email for the waitlist).
What We Process
- Spreadsheet contents: Processed in Vercel serverless functions to operate the Service; not stored in our databases.
- AI prompts/outputs: Sent to and received from our AI provider (OpenAI) to generate SQL and assist with extraction.
- Technical metadata: Minimal request/response metadata strictly necessary to operate, secure, and debug the Service.
- Logs: We use LangSmith for operational logging. Logs do not contain private or PII data and do not include user file contents.
- Waitlist email: If you join the waitlist, we store your email in Supabase to contact you about access and product updates.
We do not collect payment information for this preview and do not use third‑party advertising or cross‑site tracking.
How We Use Information
- Provide, operate, and improve the Service (including generating SQL from spreadsheets).
- Maintain security, prevent abuse, and debug issues.
- Communicate about waitlist status, product updates, and early-access onboarding (if you opted into the waitlist).
We do not sell personal information.
Legal Bases (EU/UK GDPR)
- Performance of a contract or steps prior to entering into a contract (providing the Service during the preview).
- Legitimate interests (security, debugging, service reliability, and quality).
- Consent (waitlist communications and any optional marketing). You may withdraw consent at any time by contacting us.
Retention
- Spreadsheet contents: Processed in Vercel serverless functions and not retained. We do not write spreadsheet contents to our databases.
- Logs: Operational logs via LangSmith and Supabase exclude private or PII data and are retained only as needed for service operation and diagnostics.
- Waitlist email: Retained until you ask us to delete it or until the waitlist program ends. We will delete upon request.
Third Parties (Subprocessors)
- Vercel: Serverless hosting and execution environment used to process requests.
- OpenAI: AI model provider for translating spreadsheet logic to SQL. According to OpenAI’s API policies, API inputs/outputs are not used to train OpenAI’s models. OpenAI may temporarily retain data for abuse monitoring.
- LangSmith: Operational logging. We do not send private or PII data to logs.
- Supabase: Storage of waitlist emails and email operations, as well as operational logging.
These providers may process data in jurisdictions outside your own. Where applicable, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international data transfers.
International Transfers
We may transfer information to providers located in countries other than your own. We use recognized transfer mechanisms where required by law.
Cookies and Local Storage
We do not use advertising or analytics cookies. Any browser storage, if used, is solely for essential, product‑functional purposes and is not transmitted to our servers.
Security
We use encryption in transit, serverless isolation, ephemeral processing, least‑privilege access, and managed secrets. No method of transmission or storage is absolutely secure, but we strive to minimize exposure and retain no spreadsheet contents by design. Please avoid uploading highly sensitive or special‑category data.
Your Rights
Depending on your location (including EU/UK), you may have rights to request access, rectification, deletion, restriction, portability, or objection. To exercise these rights, contact contact@sheet2sql.com. We will respond within 30 days where legally required. You may also have the right to lodge a complaint with your local supervisory authority.
Children
The Service is not intended for individuals under 16. Do not submit personal data of children.
No Sale or Sharing (CCPA/CPRA)
We do not sell or share personal information as defined by California law.
Changes
We may update this Policy. We will post the updated version with a new effective date. Your continued use after changes signifies acceptance.
Contact
Questions or requests: contact@sheet2sql.com
This policy is provided for transparency and is not legal advice.