XLlama Privacy Policy
TL;DR: AI runs on your computer
- AI stays local. Your prompts and attached cells go to Ollama on your computer. XLlama has no cloud AI fallback.
- We do not receive your AI conversations through the add-in. There is no telemetry or automatic error upload.
- Chats and unfinished drafts are saved on your PC and are not separately encrypted. Uninstalling keeps them; delete chats in the app when you no longer need them.
- Licenses, optional updates, downloads and links can use the internet. License and update checks do not include your chats or worksheet data. Content you choose to send to support is shared with us.
This is a quick summary. The full policy below explains what is stored, what is sent, and your rights.
This policy explains how the XLlama Windows add-in for Microsoft Excel, published by Bosau Digital LLC and made by Sven Bosau at Python & VBA ("we", "us" or "our"), handles data. It covers the Windows installer edition, not the separate classic VBA XLlama product. Our website Privacy Policy also applies when you visit our websites, follow links, purchase a license or contact us.
1. Local AI processing
XLlama sends AI requests to Ollama on your computer, normally at http://127.0.0.1:11434. Its address setting accepts only local loopback addresses. Remote servers and cloud models are blocked, and there is no cloud AI fallback.
A chat request contains your question, system instructions and recent conversation context. If you enable Selected cells, it also contains the selected range’s address, values and formulas in the attachment you approve. Worksheet functions use your prompt and referenced cells. XLlama also examines workbook formulas locally to enforce Free limits or perform worksheet tools you request. Those local checks do not send the rest of the workbook to us.
We do not receive prompts, model answers or worksheet contents as part of AI processing. You control any later sharing, such as saving a workbook to cloud storage or sending a conversation to support. Ollama is third-party software you install and manage separately.
2. Data stored on your computer
- Chats, unfinished drafts, settings and formula answers: saved under
%LOCALAPPDATA%\XLlamaDesktop\Data. Chats can include attached worksheet data and model reasoning. These files are not separately encrypted by XLlama. - License records: protected using Windows data protection for your Windows account.
- Free usage records: protected local records plus a recovery record in your Windows user registry. They help preserve daily usage across reinstalls and resist accidental or casual deletion.
- Application files and runtime data: installed in your Windows user profile; WebView2 can keep its own runtime files.
New chat starts another conversation; it does not delete earlier chats. You can delete individual chats and their drafts, clear an unfinished question, and clear the formula cache in XLlama. Drafts are saved as you type; the last active draft is restored when you reopen Excel. Updating and uninstalling preserve saved chats, settings, license and usage records. Ollama and its models are also kept. Copies exported or saved into workbooks remain wherever you saved them.
3. License validation
Free users without a saved license key make no license requests. If you enter a key, XLlama contacts api.pythonandvba.com over HTTPS and sends:
- Your license key;
- The add-in version;
- A pseudonymous device identifier derived by hashing the Windows computer name and Windows account name. The raw names are not sent. This is a stable identifier used for licensing, not a random anonymous identifier;
- Ordinary connection information, such as the source IP address, available to the receiving server and its infrastructure.
Validation is normally due every 24 hours. A last successful check is stored locally. During an outage, Pro can remain available for up to seven days from the last fresh successful check. A confirmed inactive or refunded status ends Pro access. Licensing data is used to administer licenses, prevent abuse, troubleshoot activation and meet applicable obligations. License API requests go directly to the API; they do not pass through the product’s redirect links.
4. Updates, downloads and links
Automatic version checks are off by default. If you enable them, or choose Check for updates now, XLlama requests published version information from our API. This request does not include your license key, prompts or worksheet contents. The server and hosting infrastructure still receive ordinary network information such as your IP address. Update settings do not disable paid-license validation.
Product buttons use redirect links on pythonandvba.com. Following them can record click information under our website Privacy Policy before forwarding you to documentation, support, checkout, account management or a download provider. Clicking Manage account includes the product name and your saved license key in the URL to prefill account sign-in. The portal removes these parameters from its address bar after reading them; website and infrastructure logs may still receive them. Other product links do not include your key. No product link includes chat or worksheet data.
The installer is distributed through GitHub. Prerequisite downloads go to Microsoft; Ollama and model downloads use Ollama and its download infrastructure. These providers handle download and connection information under their own policies. Windows, Excel, WebView2 and Ollama may make their own network requests independently of XLlama.
5. Diagnostics and support
XLlama has no telemetry, advertising or automatic error uploads. Diagnostics checks installation paths, the local API, its version and local-model availability. An optional response test sends only a short fixed test prompt and does not use worksheet data or chat history.
A copied diagnostic report contains the XLlama version, Excel process bitness, local endpoint and check results. It excludes keys, prompts, worksheet contents, model names and raw server errors. Copying puts it on your clipboard; it is not sent to us automatically. If you contact support, we process the information you choose to provide, which may include screenshots or other content. Review it before sending.
6. Purposes and legal bases
Where GDPR or UK data-protection law applies, we rely on contract performance to provide and manage a purchased license, and legitimate interests to secure and operate the service, prevent licensing abuse and answer support requests. Website purchases, cookies and marketing are addressed in the website Privacy Policy. AI content processed only on your computer is not received by us through the add-in.
7. Sharing and retention
We do not sell your personal data. Our hosting, security, licensing, payment and support providers may process relevant service information on our behalf or under their own policies. Requests to GitHub, Microsoft or Ollama are handled by those providers. Bosau Digital LLC is based in the United States; service information may be processed there or in other locations used by our providers, with applicable protections for international transfers. See the website Privacy Policy for wider service details.
License and support records are retained as needed to deliver the service, resolve issues, prevent misuse and meet legal obligations. Locally saved content stays on your computer until you remove it; uninstalling alone does not erase it. We do not keep a server copy of your AI conversations unless you choose to send content to us, for example in a support request.
8. Security and your rights
We use reasonable technical and organisational measures to protect service data. License and update API traffic uses HTTPS. Local Ollama traffic uses HTTP loopback on your computer. Windows protection is used for license and quota records; other local files depend on your device and account security.
Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing of personal data we hold, and to receive portable data. These rights have legal conditions and exceptions. Contact contact@pythonandvba.com to make a request; we respond within the period required by applicable law. You may also complain to your data-protection authority.
9. Children and changes
XLlama is not directed at children under 16. We do not knowingly collect their personal data. We may update this policy as the product changes; the date above identifies the current version.
10. Contact
1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA
Python & VBA · Sven Bosau
Email: contact@pythonandvba.com
