AI Categorizer Privacy Policy
This Privacy Policy explains how the AI Categorizer add-in for Microsoft Excel and the online categorizing service behind it (together "the Add-in"), published by Bosau Digital LLC and made by Sven Bosau, operating Python & VBA at pythonandvba.com ("we", "us", or "our"), handle your data. It applies specifically to the Add-in. Our general website Privacy Policy continues to apply to your use of our website.
1. In Short
- To sort your rows into categories, the Add-in sends text to an AI model. Only the values of the columns you tick are sent, together with your category names, their optional descriptions and the optional question you write, and only for the rows that need an AI answer. Blank rows, repeated rows and rows that already have a result are handled inside Excel and are never sent.
- We do not store your cell data, your categories or your question. Our categorizing service passes the text to the AI provider, returns the answer to Excel, and keeps no copy.
- Your data is not used to train AI models, by us or by our AI providers.
- The AI model is run by TypeSafe AI, Inc. through Cloudflare. Both are listed in Section 4, including what each of them keeps.
- Results are written back into your workbook, in new columns or on a new results sheet, as you choose in the Add-in. Columns you copy back from your category list (for example an account number) are filled in inside Excel. The rest of your workbook is not sent.
- The Add-in contains no advertising, no cookies, and no third-party analytics or tracking.
2. Who We Are
The Add-in is published and operated by Bosau Digital LLC, the company behind Python & VBA (pythonandvba.com), founded by Sven Bosau. For any privacy-related questions, please contact us at contact@pythonandvba.com.
3. What Data the Add-in Processes
The Columns You Tick, Your Categories and Your Question
When you run the Add-in, you choose the rows to sort and tick the columns that describe each row (usually just the description or comment). You also give it your categories, either from a range in your workbook or typed into the Add-in, and optionally a question. For each row that needs an AI answer, the Add-in sends the following to our categorizing service (ai-api.pythonandvba.com, hosted on Cloudflare Workers) over an encrypted connection:
- The values of the ticked columns of that row, joined into one line of text without the column headers, shortened to a fixed maximum length;
- Your category names. When the categories come from a range, each name is made from the columns you ticked as the category name (for example an account number and an account name);
- The optional descriptions of your categories, up to 200 characters each;
- The optional question, an instruction of up to 300 characters (for example "Which P&L account should this bank transaction be booked to?") that our service adds to the categorizing question.
The Add-in does not send column headers, columns you did not tick (so no amounts or dates unless you tick those columns), the columns you chose to copy back from your category list, other sheets, formulas, formatting, file names, or the workbook itself. Blank rows, rows that repeat an earlier row in the same run, and rows that already have a result are resolved inside Excel and are not sent at all.
Our categorizing service forwards this text to the AI model, receives the answer (one of your categories, or Other, and a confidence score), and returns it to the Add-in. We do not store your cell data: the text exists on our side only in memory while your request is being answered. The same applies to your category names, descriptions and question: we do not log or store their text. Our service logs contain request identifiers, row counts, status codes and timings, never cell text or category text.
Credits and License Data
To keep track of your credits, the Add-in sends the following to our categorizing service with every request:
- An anonymous installation identifier, a random value generated on your device. It contains no name, email, or hardware information. It holds your free credits;
- Your license keys (credit packs), if you have added any;
- The Add-in version and the type of Excel you use (Windows, Mac, or the web).
For each license key and each installation, our service keeps a credit record: credits granted, credits used, the pack name, the status of the key, and when it was last checked. It also keeps, for 24 hours, the identifiers and credit counts of recent requests, so a request that is sent twice is never charged twice. These records contain no cell data and no category text.
To confirm that a license key is valid and how many credits it carries, our categorizing service (not the Add-in itself) sends the key, a fixed device identifier that is the same for every user, and the service version to our license server (api.pythonandvba.com). That server holds the license record created when you bought the pack.
In our logs, a license key only ever appears in a shortened form (its first four and last two characters).
Free Credits and Your IP Address
Each installation gets 500 free credits once. To stop the free credits from being claimed over and over, our service uses your IP address, shortened to its network part and stored only as a one-way hash, to count how many free grants were given to that network in the last 30 days. We keep that hash and the dates of those grants for 30 days. We do not store your full IP address.
Usage Metrics
We record numbers about each request (how many rows, credits charged, token counts, response time, status, whether free or paid credits were used, how many categories were sent, and the total length of the category names and descriptions) to keep the service running and to spot faults. These metrics contain no cell text, no category names or descriptions, no question text and no license keys.
Data Stored Locally on Your Device
The following are saved in your local Office add-in storage on your device: your installation identifier, your license keys, the last known credit balance, and your settings (the confidence threshold, where results are written and the column letter for that, whether rows to review are highlighted, whether Other is allowed, the theme, whether you have completed a first run, which hides the welcome card, and a test service address that is only used during development and is empty in normal use). For each workbook you use the Add-in with, it also saves your last setup there: the address of the rows, the ticked columns, where the categories came from (a range address and its ticked columns, or the list you typed) and the question, so the Add-in can restore them the next time you open that workbook.
Inside the workbook, in its document settings, the Add-in saves:
- A random workbook identifier;
- The last category list you typed into the Add-in for that workbook (names and descriptions), if you typed one, so it is there the next time you open the file;
- A list of the result blocks it wrote: for each block, the sheet name, the header row and the headers of the result columns (including any columns copied from your category list), where the block was placed (next to the rows, from a chosen column, or on a new sheet), and which rows it was made for. The Add-in uses this list to find, update and clear exactly those results later.
These workbook settings travel with the file, so anyone you share the workbook with can see them, including a typed category list. You can remove stored keys in the Add-in at any time, change or empty the typed category list, or remove the Add-in.
Purchases
Credit packs are bought on pythonandvba.com. The checkout is run by Pabbly, and payments are processed by Stripe or PayPal. Your license key is sent to you by email through Postmark. We receive your name, email address, and order details from the checkout. We never see your full card details. This is covered in more detail by our general website Privacy Policy.
Data Handled by Microsoft Excel
The Add-in runs inside Microsoft Excel on Windows, Mac and the web. Microsoft's handling of your Office documents and account data is governed by Microsoft's own privacy terms. See the Microsoft Privacy Statement.
4. Third-Party Services (Subprocessors)
The Add-in relies on the following service providers. Each receives only what it needs for its task:
- Cloudflare, Inc. (United States): hosts our categorizing service (ai-api.pythonandvba.com) and routes requests to the AI model through its AI Gateway. We have turned off content logging in the gateway, so Cloudflare does not keep the text of your rows, your categories, your question, or the answers. Cloudflare does keep request metadata for each AI call (time, model, status, duration, token counts, and cost). Cloudflare states that it does not use Workers AI customer content to train AI models. See the Cloudflare Privacy Policy.
- TypeSafe AI, Inc. (United States): provides the AI model (Jev) that reads the text of your ticked columns, your category names and descriptions, and your question, and chooses the answer. TypeSafe states that it does not train its models on your inputs. TypeSafe keeps data for as long as reasonably necessary under its own privacy policy, so we cannot promise that it deletes your text immediately after answering. If that is not acceptable for a particular list, do not send it through the Add-in.
- Our license server (api.pythonandvba.com, operated by us): checks license keys as described in Section 3.
- Pabbly, Stripe and PayPal: checkout and payment processing when you buy a credit pack.
- Postmark: sends the email that delivers your license key.
- Microsoft Excel / Microsoft 365: the host application in which the Add-in runs.
No other third parties receive data through the Add-in. We do not sell your personal data.
5. What the Add-in Does Not Do
- It does not send columns you did not tick, column headers, the columns you copy back from your category list, other sheets, or the workbook file.
- It does not store your cell data, your categories or your question on our servers, and it does not use your data to train AI models.
- It does not include advertising, cookies, or third-party analytics or tracking.
- It does not change anything in your workbook outside the result columns or results sheet it adds and the workbook settings described in Section 3.
- It does not send automatic error reports. If you contact support, you can choose to copy a short diagnostic report (add-in version, Excel version, recent error messages; never your cells, categories or keys) and include it yourself.
6. How We Use Data
- To answer your categorizing requests and return the results to Excel.
- To grant free credits, check license keys, and count the credits you use.
- To prevent abuse of the free credits and of the service.
- To keep the service running, measure its speed and accuracy, and find faults.
- To deliver your license key and handle purchases and support requests.
7. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process the data described above under the following legal bases:
- Contract performance: Answering your requests, managing your credits, and verifying your license keys so we can provide the service you use or bought.
- Legitimate interests: Preventing abuse of the free credits and of the service, and keeping the service secure and reliable.
You decide which data you put into the columns you tick, your categories and your question. If they contain personal data about other people (for example customer names in a comment), you are responsible for having a lawful basis to process it, and we process it on your behalf only to answer your request.
8. International Data Transfers
Bosau Digital LLC and the providers listed in Section 4 are located in the United States or process data there. If you use the Add-in from outside the United States, the text of your ticked columns, your categories, your question and the other data described above are transferred to the United States. Where the GDPR applies, these transfers rely on the safeguards our providers offer, such as the EU Standard Contractual Clauses.
9. Data Retention
- Cell contents, category names, descriptions and the question: Not stored by us. They are held in memory only while a request is answered. The AI provider, TypeSafe AI, keeps data for as long as reasonably necessary under its own privacy policy (see Section 4).
- AI Gateway metadata (time, model, status, duration, token counts, cost): Kept by Cloudflare under its log retention settings, without any content.
- Credit records and license records: Kept for as long as the credits can be used and as necessary to support your license and comply with legal obligations. Credits never expire, so these records are kept for the life of the service.
- Request identifiers and counts (to prevent double charging): 24 hours.
- Hashed network identifiers for free credits: 30 days.
- Locally stored keys, settings and setups: Remain on your device until you remove them or the Add-in.
- Workbook settings (the workbook identifier, the typed category list and the list of result blocks): Stay in the workbook file. The typed category list changes when you change it in the Add-in, and the entry for a result block is removed when you clear those results in the Add-in.
10. Your Rights
If you are located in the EEA or UK, you have the following rights under GDPR in respect of the personal data we hold (essentially, your license and credit records and your purchase details):
- Access: Request a copy of the data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request that we limit how we use your data
- Portability: Request your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, please contact us at contact@pythonandvba.com. We will respond within 30 days. Because we do not store your cell data or your categories, there is no cell data of yours for us to return or delete.
11. Data Security
We take reasonable technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. All traffic between the Add-in, our categorizing service, the AI provider, and our license server is encrypted (HTTPS). License keys are never written to our logs in full.
12. Children's Privacy
The Add-in is not directed at children under the age of 16. We do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time, for example if we change AI providers. The "Last updated" date at the top of this page will reflect any changes. Continued use of the Add-in after changes are posted constitutes acceptance of the updated policy.
14. Contact
For any privacy-related questions or to exercise your rights, please contact:
1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA
Python & VBA · Sven Bosau
Email: contact@pythonandvba.com
Website: pythonandvba.com
