Privacy
You upload a PDF and a spreadsheet, and we produce documents from them. This page says what we hold to do that, where it sits, and when it goes.
What we hold
- Your account. An email address, a name if you gave one, and either a password hash or the fact that you sign in with Google or Microsoft. We never see a password used with those providers. Our own cookie is the one that keeps you signed in. We also use Google Analytics, loaded through Google Tag Manager, to understand how the site is used; it sets its own cookies and receives the usual usage signals — pages visited, rough location, device — never the contents of your documents or spreadsheets.
- Your templates and spreadsheets. The files you upload, and for a spreadsheet the column names, inferred types, and the first few rows — which is what the mapping screen shows you.
- The documents we produce. Every PDF a run creates, plus the record of what each was called and which row it came from.
- Delivery records. If a run emails its documents, the address each was sent to and whether it arrived.
- A connected Google Sheet. If you connect one, a token that lets us read your spreadsheets and nothing else.
Where it is stored
Files live in object storage; the database holds only the keys that point at them, never the file contents. Nothing you upload stays on the machine that processed it beyond the job that needed it.
The Google token is the one secret we hold on your behalf that would be worth stealing — it is a standing key to your account — so it is encrypted before it is written down, with a key that is not in the database. A copy of the database on its own does not yield it.
How long we keep it
Documents a run produces are deleted 24 hours after it finishes, on every plan. Your run history stays — you can still see what was produced and what it was called — but the files themselves are removed, and the page says so rather than offering a download that fails.
Your templates and spreadsheets are different: they are the reusable half of the product, so they stay until you delete them.
Previews are deleted within a day, since they exist to be looked at once. Delivery records go when the documents they describe do. Delete your account and everything attached to your workspace goes with it.
Who else sees it
Only the services needed to run the product: the host our containers and database run on, the object storage the files sit in, Google Tag Manager and Analytics for site usage, the provider that sends email on your behalf, and Stripe if you pay us. Stripe handles card details directly — we never receive a card number.
We do not sell anything about you, and we do not use your documents or spreadsheets to train anything.
Google Sheets
Connecting a sheet asks Google for one permission — read-only access to your spreadsheets. We ask for no access to the rest of your Drive, and we could not delete or edit a spreadsheet if we wanted to. We read a connected sheet when a run needs it, not on a schedule.
Revoke the connection whenever you like from your Google account’s third-party access page, and tell us to delete the stored token from the address below.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Sheet data is used to populate your documents and for nothing else — not advertising, not training, and never transferred to anyone except as needed to produce the documents you asked for.
What you can ask for
A copy of what we hold about you, a correction, or deletion. Write to [email protected] from the address on your account, or use the contact form inside the product, and we will answer.