Spreadsheet Studio

Privacy

What we collect, and what we do with it

Last updated September 3, 2026

This is written to be read, not to cover us. It describes what Spreadsheet Studio (“we”) collects when you use spreadsheetstudio.co, where it lives, who can see it, and how to have it removed. If anything here is unclear, email sturdylaw@gmail.com.

What we collect

  • Account details. Your name, your company name if you give it, your email address, and a password. The password is stored only as a hash by our authentication provider; we never see it.
  • Your requests. What you write on your request board, the files you attach, the messages in each request thread, and the files we deliver back.
  • Plan and billing status. Which plan you are on and whether it is active or paused. If you pay by card, the card details go to the payment processor (Stripe), not to us. We never store a card number.
  • Session cookies. The cookies that keep you logged in.
  • A first-visit source cookie. Set once, on the first page you see, it records where the visit came from — the referring site and any campaign tag in the address — and the page you landed on, for thirty days. It holds no identifier, and it exists so that when you ask us something we can tell which page brought you.
  • Page views. We keep our own count: the page, the referring site's name, and whether the device was a phone, tablet or desktop. No IP address is stored.
  • What you send through a form. If you ask for the free teardown or ask a question, we keep what you typed so we can reply.

What we do not collect

There is no third-party analytics script, advertising pixel, tracking cookie or chat widget on this site, and nothing here reports your visit to anyone else. We do not buy data about you, and we do not sell, rent or share your data with anyone for marketing.

Where it is stored

Accounts, requests, messages and files are stored with Supabase, in a database hosted in the United States (AWS, us-east-2). The website runs on Vercel. Both providers encrypt data at rest and in transit. Files you attach to a request are held in private storage and served only through short-lived signed links to you and to us.

Who can see it

You can see your own requests and files. The operator of Spreadsheet Studio can see every request, because building your workbook is the service. Row-level security rules in the database enforce that one client can never see another client’s requests, names or files. An automated build pipeline reads a request's brief and attachments to build the workbook; what it is, what it may do and where it runs are described on the data-handling page. No one else has access.

How we use it

To build what you asked for, to run your board, and to email you about your account and your requests. We do not use your files or your numbers for anything else, and we do not use them to train any model.

How long we keep it

For as long as your account exists. Delivered workbooks are yours to download at any time. When you ask us to delete your account, we delete the account, its requests, its messages and every file attached to them.

Your rights

Ask for a copy of what we hold about you, ask for it to be corrected, or ask for it to be deleted, by emailing sturdylaw@gmail.com from the address on your account. We will do it and confirm by reply.

Changes

If this page changes in a way that matters, the date at the top moves and anyone with an active account gets an email. The current version is always the one at spreadsheetstudio.co/privacy.