AI Fuzzy Match Privacy Policy
This Privacy Policy explains how the AI Fuzzy Match add-in for Microsoft Excel and the online matching service behind it (together "the Add-in"), published by Bosau Digital LLC and made by Sven Bosau, operating Python & VBA at pythonandvba.com ("we", "us", or "our"), handle your data. It applies specifically to the Add-in. Our general website Privacy Policy continues to apply to your use of our website.
1. In Short
- To match your rows, the Add-in sends text to an AI model. Only the values of the columns you select are sent, together with the optional extra rule you write, and only for the rows that need an AI answer. Exact matches and repeated rows are handled inside Excel and are never sent.
- We do not store your cell data. Our matching service passes the text to the AI provider, returns the answer to Excel, and keeps no copy.
- Your data is not used to train AI models, by us or by our AI providers.
- The AI model is run by TypeSafe AI, Inc. through Cloudflare. Both are listed in Section 4, including what each of them keeps.
- Results are written back into your workbook, in new columns or on a new results sheet, as you choose in the Add-in's settings. The rest of your workbook is not sent.
- The Add-in contains no advertising, no cookies, and no third-party analytics or tracking.
2. Who We Are
The Add-in is published and operated by Bosau Digital LLC, the company behind Python & VBA (pythonandvba.com), founded by Sven Bosau. For any privacy-related questions, please contact us at contact@pythonandvba.com.
3. What Data the Add-in Processes
The Columns You Select
When you run a match, you choose which columns to compare in your first list (usually just the name or description), and which columns of your reference list the AI picks from (usually just the name). For each row that needs an AI answer, the Add-in sends the following to our matching service over an encrypted connection:
- The values of the selected columns of that row, joined into one line of text without the column headers, shortened to a fixed maximum length;
- The candidate entries from your reference list (either the whole list when it is small, or a short list of the closest entries picked inside Excel), shortened the same way;
- The extra rule, if you wrote one: an optional instruction of up to 200 characters (for example "Branches of the same company count as one") that our service adds to the matching question.
The Add-in does not send column headers, other columns, other sheets, formulas, formatting, file names, or the workbook itself. Exact matches, repeated rows, and rows that already have a result are resolved inside Excel and are not sent at all.
Our matching service forwards this text to the AI model, receives the answer (the chosen entry and a confidence score), and returns it to the Add-in. We do not store your cell data: the text exists on our side only in memory while your request is being answered. The same applies to your extra rule: we do not log or store its text. Our service logs contain request identifiers, row counts, status codes and timings, never cell text.
Credits and License Data
To keep track of your credits, the Add-in sends the following to our matching service with every request:
- An anonymous installation identifier, a random value generated on your device. It contains no name, email, or hardware information. It holds your free credits;
- Your license keys (credit packs), if you have added any;
- The Add-in version and the type of Excel you use (Windows, Mac, or the web).
For each license key and each installation, our service keeps a credit record: credits granted, credits used, the pack name, the status of the key, and when it was last checked. It also keeps, for 24 hours, the identifiers and credit counts of recent requests, so a request that is sent twice is never charged twice. These records contain no cell data.
To confirm that a license key is valid and how many credits it carries, our matching service (not the Add-in itself) sends the key, a fixed device identifier that is the same for every user, and the service version to our license server (api.pythonandvba.com). That server holds the license record created when you bought the pack.
In our logs, a license key only ever appears in a shortened form (its first four and last two characters).
Free Credits and Your IP Address
Each installation gets 100 free credits once. To stop the free credits from being claimed over and over, our service uses your IP address, shortened to its network part and stored only as a one-way hash, to count how many free grants were given to that network in the last 30 days. We keep that hash and the dates of those grants for 30 days. We do not store your full IP address.
Usage Metrics
We record numbers about each request (how many rows, credits charged, token counts, response time, status, whether free or paid credits were used, and the length of the extra rule, if any) to keep the service running and to spot faults. These metrics contain no cell text, no rule text and no license keys.
Data Stored Locally on Your Device
The following are saved in your local Office add-in storage on your device: your installation identifier, your license keys, the last known credit balance, and your settings (the confidence threshold, where results are written and the column letter for that, whether rows to review are highlighted, the theme, and whether you have completed a first run, which hides the welcome card).
Inside the workbook, in its document settings, the Add-in saves:
- A random workbook identifier;
- The extra rule you wrote for that workbook, if any, so it is there the next time you open the file;
- A list of the result blocks it wrote: for each block, the sheet name, the header row and the headers of the result columns, where the block was placed (next to the list, from a chosen column, or on a new sheet), which list and column it was made for, the headers of any reference-list columns copied next to it, and the extra rule it was made with. The Add-in uses this list to find, update and clear exactly those results later.
These workbook settings travel with the file, so anyone you share the workbook with can see them. You can remove stored keys in the Add-in at any time, empty the extra rule field, or remove the Add-in.
Purchases
Credit packs are bought on pythonandvba.com. The checkout is run by Pabbly, and payments are processed by Stripe or PayPal. Your license key is sent to you by email through Postmark. We receive your name, email address, and order details from the checkout. We never see your full card details. This is covered in more detail by our general website Privacy Policy.
Data Handled by Microsoft Excel
The Add-in runs inside Microsoft Excel on Windows, Mac and the web. Microsoft's handling of your Office documents and account data is governed by Microsoft's own privacy terms. See the Microsoft Privacy Statement.
4. Third-Party Services (Subprocessors)
The Add-in relies on the following service providers. Each receives only what it needs for its task:
- Cloudflare, Inc. (United States): hosts our matching service and routes requests to the AI model through its AI Gateway. We have turned off content logging in the gateway, so Cloudflare does not keep the text of your rows, your extra rule, or the answers. Cloudflare does keep request metadata for each AI call (time, model, status, duration, token counts, and cost). Cloudflare states that it does not use Workers AI customer content to train AI models. See the Cloudflare Privacy Policy.
- TypeSafe AI, Inc. (United States): provides the AI model (Jev) that reads the text of your selected columns and your extra rule and chooses the answer. TypeSafe states that it does not train its models on your inputs. TypeSafe keeps data for as long as reasonably necessary under its own privacy policy, so we cannot promise that it deletes your text immediately after answering. If that is not acceptable for a particular list, do not send it through the Add-in.
- Our license server (api.pythonandvba.com, operated by us): checks license keys as described in Section 3.
- Pabbly, Stripe and PayPal: checkout and payment processing when you buy a credit pack.
- Postmark: sends the email that delivers your license key.
- Microsoft Excel / Microsoft 365: the host application in which the Add-in runs.
No other third parties receive data through the Add-in. We do not sell your personal data.
5. What the Add-in Does Not Do
- It does not send columns you did not select, column headers, other sheets, or the workbook file.
- It does not store your cell data on our servers, and it does not use your data to train AI models.
- It does not include advertising, cookies, or third-party analytics or tracking.
- It does not change anything in your workbook outside the result columns or results sheet it adds and the workbook settings described in Section 3.
- It does not send automatic error reports. If you contact support, you can choose to copy a short diagnostic report (add-in version, Excel version, recent error messages; never your cells or keys) and include it yourself.
6. How We Use Data
- To answer your match requests and return the results to Excel.
- To grant free credits, check license keys, and count the credits you use.
- To prevent abuse of the free credits and of the service.
- To keep the service running, measure its speed and accuracy, and find faults.
- To deliver your license key and handle purchases and support requests.
7. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process the data described above under the following legal bases:
- Contract performance: Answering your requests, managing your credits, and verifying your license keys so we can provide the service you use or bought.
- Legitimate interests: Preventing abuse of the free credits and of the service, and keeping the service secure and reliable.
You decide which data you put into the columns you select. If those columns contain personal data about other people (for example customer names), you are responsible for having a lawful basis to process it, and we process it on your behalf only to answer your request.
8. International Data Transfers
Bosau Digital LLC and the providers listed in Section 4 are located in the United States or process data there. If you use the Add-in from outside the United States, the text of your selected columns and the other data described above are transferred to the United States. Where the GDPR applies, these transfers rely on the safeguards our providers offer, such as the EU Standard Contractual Clauses.
9. Data Retention
- Cell contents and the extra rule: Not stored by us. They are held in memory only while a request is answered. The AI provider, TypeSafe AI, keeps data for as long as reasonably necessary under its own privacy policy (see Section 4).
- AI Gateway metadata (time, model, status, duration, token counts, cost): Kept by Cloudflare under its log retention settings, without any content.
- Credit records and license records: Kept for as long as the credits can be used and as necessary to support your license and comply with legal obligations. Credits never expire, so these records are kept for the life of the service.
- Request identifiers and counts (to prevent double charging): 24 hours.
- Hashed network identifiers for free credits: 30 days.
- Locally stored keys and settings: Remain on your device until you remove them or the Add-in.
- Workbook settings (the workbook identifier, the extra rule and the list of result blocks): Stay in the workbook file. The extra rule is removed when you empty the rule field, and the entry for a result block when you clear those results in the Add-in.
10. Your Rights
If you are located in the EEA or UK, you have the following rights under GDPR in respect of the personal data we hold (essentially, your license and credit records and your purchase details):
- Access: Request a copy of the data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request that we limit how we use your data
- Portability: Request your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise any of these rights, please contact us at contact@pythonandvba.com. We will respond within 30 days. Because we do not store your cell data, there is no cell data of yours for us to return or delete.
11. Data Security
We take reasonable technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. All traffic between the Add-in, our matching service, the AI provider, and our license server is encrypted (HTTPS). License keys are never written to our logs in full.
12. Children's Privacy
The Add-in is not directed at children under the age of 16. We do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time, for example if we change AI providers. The "Last updated" date at the top of this page will reflect any changes. Continued use of the Add-in after changes are posted constitutes acceptance of the updated policy.
14. Contact
For any privacy-related questions or to exercise your rights, please contact:
1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA
Python & VBA · Sven Bosau
Email: contact@pythonandvba.com
Website: pythonandvba.com
