Effective Date: September 2026
Overview
Open Excel is a Chrome extension that lets you open, view, and edit spreadsheet files
(.xls, .xlsx, .csv) directly in Chrome and save or export them as .xlsx. The core viewer/editor is local-first: by default,
your workbook content is processed in your browser and is not uploaded to our servers unless you choose a feature
that requires remote processing or storage.
Optional features may use Open Excel cloud storage, AI tools, Google Sheets export, authentication services, and payment processing. This Privacy Policy explains what data is processed, when it is uploaded, and how you can control it.
Controller
ValmisLab OÜ, Tornimäe 7, 10145 Tallinn, Estonia, is the controller of personal data processed to operate OpenExcel, except where a third-party provider acts as an independent controller under its own terms. Contact: valmislab.studio@gmail.com.
Data Processing: Local-First by Default
By default, Excel files are processed locally in your browser. We do not upload your workbook contents in the background. File content is uploaded only when you explicitly use a feature that requires it, such as:
- Cloud files / Save to Cloud (Plus or other eligible access): uploads the workbook to your OpenExcel cloud storage so you can access it from your account.
- AI tools: sends the spreadsheet context you choose, together with your prompt, to our backend and AI provider so a response can be generated.
- Google Sheets export (optional): uploads the workbook to your own Google Drive and opens it in Google Sheets.
Local storage on your device
To provide core features, Open Excel stores some data locally in your browser:
- Excel file bytes are stored in the browser’s IndexedDB to support Recent files and local saving.
- Recent files list (metadata such as file name and internal file id) and settings are stored in
chrome.storage.local. - Session state may be stored in
chrome.storage.localto keep you signed in. - AI chat history is stored locally in your browser for convenience. It is not stored in your Open Excel cloud files.
You can remove individual recent items or clear the recent list. Clearing local browser data may also remove cached files, settings, and local AI history.
Website and service logs
When you visit our website or call our backend, hosting and security systems may process technical request data such as IP address, user agent, requested URL, timestamp, response status, and security or rate-limit information. The public website does not use advertising cookies or sell browsing data. Third-party resources you request, such as Google Fonts or Paddle checkout, may receive ordinary network request data under their own privacy policies.
Account & Authentication (api.openexcel.org)
Editing allowances, Cloud files, AI tools, purchases, and account entitlements require sign-in. OpenExcel offers:
- Google sign-in via Chrome Identity / OAuth
- Email OTP, a one-time code sent to your email address
When you sign in, we process minimal data needed for authentication, security, account management, and entitlements:
- Email address and account identifier
- Auth provider (Google or Email)
- Optional marketing consent, only if you choose it
- Privacy policy version and UI language
- Session and entitlement data, such as plan, enabled features, and usage limits
- AI wallet and usage data, such as free and purchased action balances, successful consumption entries, and monthly refill period
- Basic security signals, such as IP address and user agent, for abuse prevention and rate limiting
We do not upload Excel file contents to our servers as part of sign-in.
Workbook Recognition and Free Editing
To enforce the Free allowance of three distinct edited spreadsheets and avoid counting another saved copy of the same recognized workbook as a new file, we may process and store an account-scoped workbook identifier and cryptographic file fingerprints. A random identifier may also be embedded in custom properties when OpenExcel saves an XLSX file.
These records may include the internal workbook key, SHA-256 fingerprint, source type, status, and first/last-seen timestamps. They are used for access control and allowance accounting, not advertising. A fingerprint is derived from file bytes but is not stored as workbook content. Workbook names, cell values, prompts, and file fingerprints are not included in monetization analytics events.
Cloud Files and Version History (Plus)
If you choose to save or open files in Open Excel Cloud, the workbook file bytes are stored in private cloud object storage and associated metadata is stored in our backend database. Metadata may include file name, owner account, file id, version id, version number, file size, timestamps, and pointers to stored objects.
Cloud files and their versions are used to provide features such as Save to Cloud, Open from Cloud, Copy Local → Cloud, Copy Cloud → Local, and Version History. Each Save to Cloud may create a new file version, up to the configured version limit.
Access to cloud file bytes is controlled by our backend using short-lived signed URLs. Cloud storage credentials are not exposed to the extension.
If your Plus, legacy, or administrative Cloud access is unavailable, or if a storage limit is reached, we may restrict creating new cloud files, saving new versions, restoring versions, or using other write actions. To support data portability, we may continue to allow you to list, view, download, or delete your own existing cloud files and versions, subject to the Service’s current product rules.
AI Tools and AI Actions
Open Excel AI tools can help audit spreadsheet structure, clean selected data, rewrite text, generate formulas, answer custom questions, and propose changes that you can review before applying. AI changes are not applied automatically; for patch-style actions, you must explicitly click Apply.
When you use AI tools, the extension sends the following to our backend:
- the action you selected, such as audit, clean, rewrite, formula, or custom;
- your optional user prompt or note;
- the spreadsheet context you choose, such as selected cells, the current sheet, or the workbook context;
- basic metadata needed to process the request, such as locale, range, sheet name, and usage accounting data.
The backend sends this context to our configured AI provider (currently Google Gemini) to generate the response. We use the AI request and response to provide the requested feature, validate safe patch operations, handle errors, and account for usage limits. AI provider behavior may be governed by that provider’s own terms and privacy practices.
We design AI requests to avoid sending more spreadsheet data than needed. For example, clean, rewrite, and formula actions are based on selected spreadsheet context, while broader audit or custom requests may use larger context only when you choose that scope. Do not send sensitive data to AI tools unless you are comfortable with it being processed for the requested AI feature.
AI actions are deducted only after a successful response. We store action balances and ledger entries needed to distinguish free and purchased actions, apply eligible monthly minimums, prevent duplicate purchase credit, and resolve billing or usage disputes. Purchased actions are used after free actions and do not expire during normal operation.
Google Sheets Export (Optional)
If you click “Edit in Google Sheets”, the extension exports the current workbook and uploads it to
your Google Drive, converts it to a Google Sheets file in your account, and opens it on
docs.google.com. This upload happens only when you explicitly use this feature.
Payments and Billing
If you purchase Plus Lifetime or an AI action package, payments are processed by Paddle, our Merchant of Record and authorised reseller. Paddle may collect billing information such as your name, email address, country, tax or VAT details, and payment method information to process transactions, calculate taxes, prevent fraud, and provide receipts and buyer support. We do not store your full card number on our servers.
We may store billing-related identifiers received from Paddle, such as customer id, transaction id, product/price id, environment, payment status, purchased package, entitlement, amount/currency, and relevant timestamps. Historical subscription identifiers and statuses may also be retained where applicable. We use these records to fulfil purchases, prevent duplicate grants, activate or revoke entitlements or AI actions, provide support, and handle refunds, chargebacks, accounting, tax, and disputes.
Minimal Monetization Analytics
We record a small set of account events needed to understand and operate Free limits and paid offers, such as a Free workbook claim, paywall display, checkout opening, completed purchase, or reaching the free AI limit. A record may contain the account id, event name, timestamp, production or sandbox environment, source, app version, plan or package code, and purchase amount/currency where relevant.
These events do not contain workbook content, file names, workbook identifiers or fingerprints, cell data, AI prompts, or AI responses. They are not used for targeted advertising and are scheduled for deletion after 12 months.
Purposes and Legal Bases
- Contract and requested service: authentication, editing access, Cloud, AI, purchase fulfilment, support, and account administration.
- Legitimate interests: security, abuse and fraud prevention, reliable operation, debugging, enforcing limits, and compact product analytics, balanced against user rights.
- Legal obligations: payment, tax, accounting, consumer-rights, fraud, and dispute records where applicable.
- Consent: optional marketing communications and any other processing for which consent is specifically requested. Consent can be withdrawn prospectively.
Service Providers, Sharing, and Transfers
We do not sell personal data or share it with advertising platforms. We disclose data only as needed to operate the feature you request, comply with law, protect rights and security, or complete a corporate transaction subject to appropriate safeguards. Recipients may include hosting and database providers, Cloudflare R2 for Cloud files, Google for authentication, Drive/Sheets export and Gemini AI processing, email delivery providers, Paddle for purchases and buyer support, and professional or public authorities where legally required.
Some providers may process data outside Estonia or the European Economic Area. Where required, transfers are based on an adequacy decision, contractual safeguards, or another lawful transfer mechanism. Third-party services may also process data as independent controllers under their own policies.
Permissions
The extension requests the following Chrome permissions:
- storage — store local settings, session state, recent file metadata, local AI history, and cached workbook bytes.
- identity — authenticate with Google when you sign in with Google and/or export to Google Sheets.
The extension also uses host permissions to access:
- https://accounts.google.com/* — Google OAuth sign-in flow
- https://www.googleapis.com/* — Google APIs for user info and Google Drive upload when requested
- https://docs.google.com/* — open exported spreadsheets in Google Sheets
- https://api.openexcel.org/* — Open Excel backend for authentication, entitlements, Cloud, AI, usage, and billing-related account status
- Open Excel cloud storage host — upload and download your cloud files through signed URLs when you use Cloud features
Google OAuth scopes
- userinfo.email — used for Google sign-in to retrieve your email address.
- drive.file — requested only when you click “Edit in Google Sheets”. This scope is limited to files you create or select with the app and does not provide access to your entire Google Drive.
Data Retention
- Local cached files / recent list / AI history: stored locally in your browser; you can remove items or clear browser data.
- OTP codes: expire after a short time and are used only to complete sign-in.
- Sessions: expire after a limited period; you can log out to clear local session data.
- Cloud files and versions: retained while your account uses Cloud features, until you delete them, or as otherwise required to provide the Service.
- Workbook recognition records: retained while needed to enforce the account’s editing allowance and recognize previously edited workbooks.
- Monetization analytics events: retained for 12 months.
- Account, entitlement, AI ledger, billing, and security records: retained as needed for account operation, fraud prevention, legal compliance, billing, tax, and dispute handling.
- AI requests: processed to provide the requested AI feature and usage accounting. Local AI history is not used as Cloud file storage.
Your Privacy Rights
Depending on your location, you may have rights to be informed and to request access, correction, deletion, restriction, objection, or portability of personal data, and to withdraw consent. You may also complain to the Estonian Data Protection Inspectorate or your local supervisory authority. These rights may be limited where we must retain or process records for legal, security, payment, tax, fraud-prevention, or dispute purposes.
Security
We use reasonable technical and organizational measures to protect account data and cloud file access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Remote Code
The extension ships with all required assets and does not execute remote code.
Changes
We may update this Privacy Policy in the future. Updates will be posted here with a revised effective date.
Contact
For questions about this policy, email us at valmislab.studio@gmail.com. You may also use this address to request access, correction, or deletion of account data, subject to identity verification and records we must retain for legal, security, billing, or dispute purposes.