Privacy Policy
Effective date: July 26, 2026 · Last updated: July 26, 2026
1. Introduction
Columnly ("Columnly", "we", "us", "our") is an AI analyst offered as two products with different data postures. This policy describes how each one handles your information.
- A · Google Sheets add-on
An add-on that reads the sheet you are actively working in and processes requests synchronously — nothing about your spreadsheet is stored at rest. - B · Columnly Web App
A standalone application where you upload files or connect a CRM. To keep your analyses live and refreshable, the web app persists your data in a per-organization database hosted in the European Union.
Where a section applies to only one product, it is labelled. By using either product you agree to the practices described here.
2. Information We Collect
A · Google Sheets add-on
When you use the add-on, the following is sent to our backend to process your request, and is not retained after the request completes:
| Data type | Purpose |
|---|---|
| User prompt | Understand your request (e.g. "clean this data", "build a dashboard"). |
| Google email address | Identify the requesting user for rate limiting and plan enforcement. |
| Spreadsheet & sheet identifiers | Identify the active spreadsheet and tab for context. |
| Schema & sample rows | Column names and a sample of rows to give the analysis context. |
| Full sheet data | For operations that require the whole dataset (restructuring, computing dashboard/brief figures). |
B · Columnly Web App
To provide the web app, we collect and store:
| Data type | Purpose |
|---|---|
| Account & organization data | Your email, name, role, workspace membership, seats, and credit/usage counts. |
| Uploaded files (CSV/XLSX) | Ingested into your workspace so you can query them; stored as columnar Parquet. |
| Connected CRM data (HubSpot / Pipedrive) | Read read-only via OAuth and ingested so your dashboards stay live and refresh daily. Columnly cannot write back to your CRM. |
| Prompts, analyses & generated artifacts | Your questions, pinned figures, and the dashboards/briefs you build, so they persist and can be re-run. |
2.1 Information we do NOT collect
- Sheets We read only the spreadsheet you are actively working in — not other files in your Google Drive — and we do not access Gmail, Contacts, Calendar, or any other Google service.
- Web App CRM connections are read-only; we request only the minimum scopes needed to read the objects you choose to analyze, and never gain write access to your CRM.
- We do not collect browsing history or device identifiers, and we do not use tracking cookies for advertising.
Payment information. When you subscribe to a paid plan, payments are processed by Razorpay. Columnly does not store your full card details; Razorpay processes card data under its own terms.
3. How We Use Your Information
We use the information above solely to provide, operate, secure, and bill the service — generating formulas, cleaning data, building verified dashboards and briefs, keeping analyses fresh, enforcing usage limits, and supporting you.
We do not use your data for:
- Training or fine-tuning machine-learning models — your data is never used to train any model, ours or a subprocessor's.
- Advertising, profiling, or behavioral analysis.
- Selling, renting, or sharing with third parties for their own purposes.
4. Data Retention
A · Google Sheets add-on
- Request data (prompts, schema, sample rows, sheet contents) is processed synchronously and is not stored at rest beyond the duration of the request.
- Account & usage data (your email, plan tier, credit counts) is stored to operate the service and retained while your account is active. We do not store the contents of your spreadsheets.
- Hosted dashboards and briefs generated from the add-on are stored as HTML artifacts on Google Cloud and automatically deleted after 30 days.
- Server logs may contain request metadata (timestamps, response codes, email) and are retained per our hosting provider's default log-retention policy.
B · Columnly Web App
- To keep your analyses live and refreshable, the web app persists your data — uploaded files and ingested CRM records (stored as Parquet), your analyses, pins, and generated artifacts — in a per-organization database.
- This data is retained while your organization is active and is versioned; refresh snapshots are kept with a 15-day retention window and swapped atomically.
- Disconnecting a CRM lets you reconnect, retain a frozen snapshot, or remove the ingested data. Deleting your organization deletes its stored data. You can also request deletion at any time (see Section 8).
5. Data Sharing & Subprocessors
We do not sell, rent, or trade your information. We share data only with the subprocessors below, each acting on our instructions to deliver the service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Anthropic (Claude models) | The AI reasoning behind analyses. Prompts, schema, and the data needed for a given operation are sent to produce the requested result. Not used to train models. | — |
| Google Cloud | Compute and storage for request processing, hosted artifacts, and ingested data. | Belgium (EU) |
| Turso | Per-organization application database (accounts, analyses, ingested records). | Ireland (EU) |
| Razorpay | Subscription payment processing. Columnly does not store full card details. | — |
| Resend | Transactional email (team invites, account notifications). | — |
| Cloudflare | Website hosting, content delivery, and network security. | — |
6. Data Security
- Encryption in transit: all communication uses HTTPS/TLS.
- Read-only CRM access: connectors are enforced read-only at the provider edge — Columnly cannot modify your CRM.
- Tenant isolation: each organization's web-app data lives in its own per-organization database.
- Minimal scopes: we request only the OAuth scopes necessary for the operations you choose.
- Access control & rate limiting: requests are authenticated and rate-limited to prevent abuse.
- Columnly is GDPR-compliant.
7. Google API Services User Data Policy
Columnly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the add-on, do not transfer it except to the subprocessors necessary to run the service (Section 5), do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.
8. International Data & Your Rights
Web-app data is hosted in the European Union (Google Cloud in Belgium; Turso in Ireland). We process personal data in accordance with the EU General Data Protection Regulation (GDPR).
You have the right to access, correct, export, and delete your personal data, and to object to or restrict certain processing. Specifically:
- Access & portability: request a copy of your data, or export your analyses and outputs.
- Deletion: for the Sheets add-on, uninstalling stops all further collection; for the web app, deleting your organization (or contacting us) removes stored data.
- Objection / restriction: contact us to exercise these rights.
To exercise any right, contact us at the address below.
9. Children's Privacy
Columnly is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time and will revise the "Last updated" date above. Material changes will be communicated where appropriate. Continued use after changes constitutes acceptance.
11. Contact
- Email: [email protected]
- Website: columnly.ai