Effective Date: September 2026

Overview

Open Excel is a Chrome extension that lets you open, view, and edit spreadsheet files (.xls, .xlsx, .csv) directly in Chrome and save or export them as .xlsx. The core viewer/editor is local-first: by default, your workbook content is processed in your browser and is not uploaded to our servers unless you choose a feature that requires remote processing or storage.

Optional features may use Open Excel cloud storage, AI tools, Google Sheets export, authentication services, and payment processing. This Privacy Policy explains what data is processed, when it is uploaded, and how you can control it.

Controller

ValmisLab OÜ, Tornimäe 7, 10145 Tallinn, Estonia, is the controller of personal data processed to operate OpenExcel, except where a third-party provider acts as an independent controller under its own terms. Contact: valmislab.studio@gmail.com.

Data Processing: Local-First by Default

By default, Excel files are processed locally in your browser. We do not upload your workbook contents in the background. File content is uploaded only when you explicitly use a feature that requires it, such as:

Local storage on your device

To provide core features, Open Excel stores some data locally in your browser:

You can remove individual recent items or clear the recent list. Clearing local browser data may also remove cached files, settings, and local AI history.

Website and service logs

When you visit our website or call our backend, hosting and security systems may process technical request data such as IP address, user agent, requested URL, timestamp, response status, and security or rate-limit information. The public website does not use advertising cookies or sell browsing data. Third-party resources you request, such as Google Fonts or Paddle checkout, may receive ordinary network request data under their own privacy policies.

Account & Authentication (api.openexcel.org)

Editing allowances, Cloud files, AI tools, purchases, and account entitlements require sign-in. OpenExcel offers:

When you sign in, we process minimal data needed for authentication, security, account management, and entitlements:

We do not upload Excel file contents to our servers as part of sign-in.

Workbook Recognition and Free Editing

To enforce the Free allowance of three distinct edited spreadsheets and avoid counting another saved copy of the same recognized workbook as a new file, we may process and store an account-scoped workbook identifier and cryptographic file fingerprints. A random identifier may also be embedded in custom properties when OpenExcel saves an XLSX file.

These records may include the internal workbook key, SHA-256 fingerprint, source type, status, and first/last-seen timestamps. They are used for access control and allowance accounting, not advertising. A fingerprint is derived from file bytes but is not stored as workbook content. Workbook names, cell values, prompts, and file fingerprints are not included in monetization analytics events.

Cloud Files and Version History (Plus)

If you choose to save or open files in Open Excel Cloud, the workbook file bytes are stored in private cloud object storage and associated metadata is stored in our backend database. Metadata may include file name, owner account, file id, version id, version number, file size, timestamps, and pointers to stored objects.

Cloud files and their versions are used to provide features such as Save to Cloud, Open from Cloud, Copy Local → Cloud, Copy Cloud → Local, and Version History. Each Save to Cloud may create a new file version, up to the configured version limit.

Access to cloud file bytes is controlled by our backend using short-lived signed URLs. Cloud storage credentials are not exposed to the extension.

If your Plus, legacy, or administrative Cloud access is unavailable, or if a storage limit is reached, we may restrict creating new cloud files, saving new versions, restoring versions, or using other write actions. To support data portability, we may continue to allow you to list, view, download, or delete your own existing cloud files and versions, subject to the Service’s current product rules.

AI Tools and AI Actions

Open Excel AI tools can help audit spreadsheet structure, clean selected data, rewrite text, generate formulas, answer custom questions, and propose changes that you can review before applying. AI changes are not applied automatically; for patch-style actions, you must explicitly click Apply.

When you use AI tools, the extension sends the following to our backend:

The backend sends this context to our configured AI provider (currently Google Gemini) to generate the response. We use the AI request and response to provide the requested feature, validate safe patch operations, handle errors, and account for usage limits. AI provider behavior may be governed by that provider’s own terms and privacy practices.

We design AI requests to avoid sending more spreadsheet data than needed. For example, clean, rewrite, and formula actions are based on selected spreadsheet context, while broader audit or custom requests may use larger context only when you choose that scope. Do not send sensitive data to AI tools unless you are comfortable with it being processed for the requested AI feature.

AI actions are deducted only after a successful response. We store action balances and ledger entries needed to distinguish free and purchased actions, apply eligible monthly minimums, prevent duplicate purchase credit, and resolve billing or usage disputes. Purchased actions are used after free actions and do not expire during normal operation.

Google Sheets Export (Optional)

If you click “Edit in Google Sheets”, the extension exports the current workbook and uploads it to your Google Drive, converts it to a Google Sheets file in your account, and opens it on docs.google.com. This upload happens only when you explicitly use this feature.

Payments and Billing

If you purchase Plus Lifetime or an AI action package, payments are processed by Paddle, our Merchant of Record and authorised reseller. Paddle may collect billing information such as your name, email address, country, tax or VAT details, and payment method information to process transactions, calculate taxes, prevent fraud, and provide receipts and buyer support. We do not store your full card number on our servers.

We may store billing-related identifiers received from Paddle, such as customer id, transaction id, product/price id, environment, payment status, purchased package, entitlement, amount/currency, and relevant timestamps. Historical subscription identifiers and statuses may also be retained where applicable. We use these records to fulfil purchases, prevent duplicate grants, activate or revoke entitlements or AI actions, provide support, and handle refunds, chargebacks, accounting, tax, and disputes.

Minimal Monetization Analytics

We record a small set of account events needed to understand and operate Free limits and paid offers, such as a Free workbook claim, paywall display, checkout opening, completed purchase, or reaching the free AI limit. A record may contain the account id, event name, timestamp, production or sandbox environment, source, app version, plan or package code, and purchase amount/currency where relevant.

These events do not contain workbook content, file names, workbook identifiers or fingerprints, cell data, AI prompts, or AI responses. They are not used for targeted advertising and are scheduled for deletion after 12 months.

Purposes and Legal Bases

Service Providers, Sharing, and Transfers

We do not sell personal data or share it with advertising platforms. We disclose data only as needed to operate the feature you request, comply with law, protect rights and security, or complete a corporate transaction subject to appropriate safeguards. Recipients may include hosting and database providers, Cloudflare R2 for Cloud files, Google for authentication, Drive/Sheets export and Gemini AI processing, email delivery providers, Paddle for purchases and buyer support, and professional or public authorities where legally required.

Some providers may process data outside Estonia or the European Economic Area. Where required, transfers are based on an adequacy decision, contractual safeguards, or another lawful transfer mechanism. Third-party services may also process data as independent controllers under their own policies.

Permissions

The extension requests the following Chrome permissions:

The extension also uses host permissions to access:

Google OAuth scopes

Data Retention

Your Privacy Rights

Depending on your location, you may have rights to be informed and to request access, correction, deletion, restriction, objection, or portability of personal data, and to withdraw consent. You may also complain to the Estonian Data Protection Inspectorate or your local supervisory authority. These rights may be limited where we must retain or process records for legal, security, payment, tax, fraud-prevention, or dispute purposes.

Security

We use reasonable technical and organizational measures to protect account data and cloud file access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Remote Code

The extension ships with all required assets and does not execute remote code.

Changes

We may update this Privacy Policy in the future. Updates will be posted here with a revised effective date.

Contact

For questions about this policy, email us at valmislab.studio@gmail.com. You may also use this address to request access, correction, or deletion of account data, subject to identity verification and records we must retain for legal, security, billing, or dispute purposes.