Privacy Policy

    Effective Date: September 11, 2026

    Controller: EBITDAI ("we," "us," "our")

    This Privacy Policy explains how EBITDAI ("we," "us," "our") collects, uses, and protects your personal data when you use the EBITDAI Excel Add-in, the EBITDAI add-on for Google Sheets, and related services, including our website and AI-powered features.

    1. Information We Collect

    • Account Information: Name, email, organization details.
    • AI Interaction Data: Prompts you submit to our AI features, AI-generated responses, conversation history, and associated metadata (timestamps, model used, token counts). This data is collected to provide the Service, improve model quality, and enhance user experience. On the free plan, this includes the full conversation (prompts, responses, the workbook content sent to the model, and the AI's actions in your workbook), which EBITDAI staff may read, and which are the only conversations EBITDAI keeps: free-plan requests are the only ones written to our conversation log. On the paid plans (Lite and Pro), EBITDAI does not store prompts or workbook content; only usage metadata (timestamps, model, token counts) is kept for billing.
    • Usage Data: Device info, diagnostics, logs, page views, feature usage patterns, and interaction data.
    • Billing Data: Payment details (processed securely by third-party providers).
    • Email Data: If you connect your email account (e.g., Gmail), we collect email metadata such as sender, recipient, subject lines, and message snippets to power CRM and contact management features.

    2. How We Use Your Data

    We process data on these lawful bases under GDPR:

    • Contract: To provide and maintain our services, including processing your AI prompts and delivering responses.
    • Legitimate Interest: To improve AI model quality and accuracy, enhance features, ensure security, prevent abuse, and analyze usage patterns for product improvement. Prompt, response and workbook content is used for this only on the free plan, whose conversations are the only ones we log; on the paid plans (Lite and Pro) we have usage metadata alone.
    • Consent: Where required for communications, data sharing, or optional analytics.

    AI Data Usage: On the free plan we may use your prompts, AI responses, and interaction logs to:

    • Improve the quality and accuracy of our AI features
    • Train and fine-tune models (either directly or through our AI subprocessors)
    • Analyze usage patterns to enhance the Service
    • Debug issues and ensure service reliability

    On the paid plans (Lite and Pro) EBITDAI does not store prompt, response or workbook content, so none of it is available to us for those purposes. We keep only usage metadata (timestamps, model, token counts), which we use for billing, analytics and reliability. The one exception is the model you pick: requests sent with Meta Muse Spark 1.3 on Meta’s Contributor tier go to Meta, which trains on that content itself, on any plan. Meta’s standard Muse Spark 1.3 tier, selectable on Pro, is not used by Meta for training under its published pricing terms.

    Meta Muse Spark 1.3: This model is offered in two Meta tiers, and the tier decides what Meta may do with your content. On Meta’s Contributor tier (shown in the pane as “trains on your data”), every prompt, reply and workbook value you send with it goes to Meta Platforms, Inc., and Meta uses that content to train its models; that tier is the only model on the Free plan, the only model on the paid Lite plan, and an option on Pro. Meta’s standard tier (shown as “not used for training”) is selectable on Pro only, and under Meta’s published pricing terms Meta does not use the content submitted with it to train its models. Neither is the default model on any plan.

    Data Minimization: We strive to collect only the data necessary for the above purposes. Where metadata alone (e.g., timestamps, token counts, model identifiers) suffices for analytics, we prefer that over retaining full interaction content.

    3. Sharing With Subprocessors

    To generate responses, your prompts and workbook context are transmitted to an AI provider. How they get there depends on your plan:

    • Included usage (paid plans): requests are routed through EBITDAI’s relay infrastructure to whichever included model you pick, using EBITDAI’s own provider credential. On Lite the only included model is Meta Muse Spark 1.3 on Meta’s Contributor tier. On Pro the included models are Kimi k3, DeepSeek V4.1 Flash, DeepSeek V4 Pro, Gemini 3.8 Flash and Meta Muse Spark 1.3 in both Meta tiers. The relay forwards your prompt and the model’s response without logging or storing their content; only token counts and model identifiers are recorded, for billing your included usage. Each model is served by its own provider under that provider’s terms (linked below): DeepSeek V4.1 Flash and DeepSeek V4 Pro by Hangzhou DeepSeek in the People’s Republic of China, Kimi k3 by Moonshot AI in Singapore, and Gemini 3.8 Flash by Google in the United States. Requests you send with either Meta Muse Spark 1.3 tier are routed instead to Meta Platforms, Inc. in the United States. On Meta’s Contributor tier, which is the only model on Free and Lite and an option on Pro, Meta trains on the prompts, responses and workbook content submitted; on Meta’s standard tier, selectable on Pro, Meta’s published pricing terms say it does not. On the Free and Lite plans every request runs on the Contributor tier.
    • Your own API key (Pro): requests go to the AI provider you choose to connect, using your own API credential and under that provider’s terms. Pro connects your own key for every provider: Kimi Code, Moonshot (pay-as-you-go Kimi), DeepSeek and Gemini. Own-key DeepSeek and own-key Moonshot calls go directly from your device to the provider, so the key and the workbook never touch EBITDAI servers. Own-key Kimi Code and own-key Gemini cannot be called from a browser, so those requests pass through EBITDAI’s stateless relay, which forwards the request and stores nothing: no bodies, no keys. Because you connect with your own key, you establish a direct relationship with that provider.

    The AI providers we work with:

    • Moonshot AI PTE. LTD. (Kimi), incorporated in Singapore. Privacy Policy
    • Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (DeepSeek), incorporated in the People’s Republic of China. Privacy Policy · Terms
    • Meta Platforms, Inc. (Meta Muse Spark 1.3), incorporated in the United States. The model is served in two tiers. On Meta’s Contributor tier, which is the only model on the Free and Lite plans and an option on Pro, Meta uses the prompts, responses and workbook content submitted with it to train its models. On Meta’s standard tier, selectable on Pro, Meta’s published pricing terms state that submitted content is not used to train its models.
    • Google LLC (Gemini 3.8 Flash), incorporated in the United States, serving included Gemini usage on Pro and any Gemini key you connect. API Terms
    • Cross-border transfer & training: Which provider receives a request follows the model you pick, not your plan alone. DeepSeek V4.1 Flash and DeepSeek V4 Pro are served by Hangzhou DeepSeek Artificial Intelligence Co., Ltd., incorporated in the People’s Republic of China and processing there; Kimi k3 by Moonshot AI PTE. LTD., incorporated in Singapore; Gemini 3.8 Flash by Google LLC and Meta Muse Spark 1.3 by Meta Platforms, Inc., both incorporated in the United States. Lite includes Meta Muse Spark 1.3 on Meta’s Contributor tier only; Pro adds Kimi k3, Gemini 3.8 Flash, the two DeepSeek models and Meta Muse Spark 1.3 on Meta’s standard tier. Providers may use submitted content to improve their models under their own terms. Meta is the named case, and it turns on the tier: the Contributor tier lets Meta train on the prompts and completions submitted with it, while Meta’s published pricing terms say the standard tier is not used for training. If none of that is acceptable for your data, connect your own API key on Pro: your own key for any of the four providers. EBITDAI does not control any provider’s processing.
    • We also use the following third-party services that may process your data:
      • Clerk: Authentication and user management
      • Stripe: Payment processing
      • Supabase: Database hosting and storage
      • Google Analytics: Website usage analytics

    4. Google Sheets Add-on and Google User Data

    The EBITDAI add-on for Google Sheets runs in a sidebar inside the spreadsheet where it is installed. This section explains how that add-on handles Google user data, and it applies alongside the rest of this policy.

    What we access: With your permission, the add-on reads and writes only the spreadsheet it is installed in, meaning the active Google Sheets file you open it in. It does not access other files in your Google Drive, and it does not access Gmail, your contacts or any other Google service. The OAuth scope behind that access is the current spreadsheet only (https://www.googleapis.com/auth/spreadsheets.currentonly), the narrowest scope that lets an editor add-on edit the spreadsheet it is installed in. A second scope, https://www.googleapis.com/auth/script.container.ui, is what lets the add-on render its sidebar; no user data is read through it.

    How it is used: When you run a request, the cell contents and ranges that request needs, along with your instructions, are sent to the AI provider you select so it can generate the output you asked for, and the result is written back to the same spreadsheet. Content leaves Google only when you run a request, and only to the provider serving the model you picked. Those providers are the ones named in Section 3: Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (DeepSeek V4.1 Flash and DeepSeek V4 Pro), Moonshot AI PTE. LTD. (Kimi k3, including a Kimi Code subscription you connect), Google LLC (Gemini 3.8 Flash) and Meta Platforms, Inc. (Meta Muse Spark 1.3, in both tiers), plus any provider whose own API key you connect on a plan that supports own keys. Each of them processes the content under its own terms and its own privacy policy, linked in Section 3.

    What we store: Storage for the Sheets add-on is the same as for the Excel Add-in, described in Sections 1 and 5. On the paid plans (Lite and Pro), EBITDAI does not store your prompts, responses or spreadsheet content; only usage metadata (timestamps, model, token counts) is kept, for billing, and the relay that carries your request forwards it without logging its content. On the free plan, full conversation logs, which include the prompts, the responses, the spreadsheet content sent to the model and the AI’s actions in your spreadsheet, are retained for up to 90 days and then deleted, as described in Section 5. Account data, billing records and aggregated analytics are retained as described in Sections 1 and 5.

    Sharing: Google user data is not sold, is not used for advertising, and is not transferred to third parties other than the AI providers named above and the service providers already listed in this policy (Clerk, Stripe, Supabase and Google Analytics). It is not used to train models except where this policy already says the content you send is used that way: Meta Muse Spark 1.3 on Meta’s Contributor tier, where Meta trains on the prompts, responses and spreadsheet content submitted with that model. Meta’s standard tier is not used for training under Meta’s published pricing terms.

    EBITDAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

    Revoking access: You can revoke the add-on’s access to your Google Account at any time at myaccount.google.com/permissions, or by uninstalling the add-on from Google Sheets.

    5. Data Retention

    • AI Interaction Logs: Your API key is stored to make requests to your provider and is never shared. On the free plan, EBITDAI retains full conversation logs (prompts, responses, workbook content sent to the model, and the AI's actions) for up to 90 days for product improvement, support, debugging, and abuse prevention, after which they are automatically deleted unless required for an active support case or legal obligation. Lite and Pro requests are never written to that log; on the paid plans (Lite and Pro), EBITDAI retains only usage metadata (timestamps, model, token counts); prompts and workbook content are not stored. Note that the content of your prompts is also processed by your chosen provider under that provider’s own retention policy, which EBITDAI does not control.
    • Account Data: Retained while your account is active and for a reasonable period thereafter to comply with legal obligations.
    • Usage & Analytics Data: Aggregated, anonymized usage data may be retained indefinitely for analytics and product improvement. This data cannot be used to identify individual users.
    • Billing Records: Retained as required by applicable tax and financial regulations.

    You may request earlier deletion of your data by contacting us (see Section 10). Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law.

    6. Your Rights (GDPR & Global)

    You can request to:

    • Access, correct, or delete your data
    • Restrict or object to processing
    • Receive a copy of your data (portability)
    • Withdraw consent at any time
    • Opt out of AI training on your data (we will cease using your interaction data for model improvement upon request, though this may limit service quality)

    Contact ebitdaicontact@gmail.com to exercise rights. We will respond within 30 days.

    7. Security

    We use industry-standard security measures to protect your data, including:

    • Encryption at Rest: All personal data and AI interaction logs stored in our databases are encrypted at rest using AES-256 or equivalent encryption standards.
    • Encryption in Transit: All data transmitted between your device and our servers is protected with TLS 1.2 or higher.
    • Access Controls: Strict role-based access controls limit who can access user data internally.
    • Monitoring: Continuous security monitoring, logging, and regular security reviews are performed.

    8. International Transfers

    Data may be stored or processed outside your country. We implement safeguards (such as Standard Contractual Clauses) to protect EU/EEA users' data.

    9. Children

    Our services are not directed to children under 13, and we do not knowingly collect their data.

    10. Contact Us

    EBITDAI
    Email: ebitdaicontact@gmail.com