✓Your files never leave your browser
✓No server uploads or cloud storage
✓First-party usage statistics only (no third-party ad analytics)
✓No tracking cookies
✓GDPR-aligned rights, including deletion of your account data on request
✓You control all your data
1. Introduction
Welcome to RowLab ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how RowLab handles your information.
2. Our Local-First Architecture
RowLab operates entirely in your browser. This is the cornerstone of our privacy commitment:
- •Your files never leave your device - All data processing happens locally in your browser
- •No server uploads - We do not upload, transmit, or store your CSV files on our servers
- •No cloud storage - Your data is stored in your browser's IndexedDB (local storage only)
- •Complete data control - You can delete all data by clearing your browser storage
3. Data We Do NOT Collect
RowLab does NOT collect, process, or store:
- ✗Your CSV files or any file contents
- ✗The data within your pipelines or transformations
- ✗Personal information from your files
- ✗User-generated content or project data
- ✗Passwords — sign-in uses Google OAuth, so RowLab never sees or stores a password
We collect first-party product analytics on our own systems to improve RowLab. We do not use third-party advertising or cross-site tracking tools for this. The following aggregated or bucketed data may be stored when you use the app:
- •Feature usage - Which product events occurred (for example, pipeline run, export), with counts stored in coarse buckets—not your file contents or column names
- •Anonymous session label - A random identifier in
sessionStorage for the browser tab, rotated when you close the tab; it is not your name, email, or Google account - •Network metadata - A one-way hash derived from your IP address (we do not store raw IPs in analytics) for abuse prevention
Important: Analytics events are validated server-side; we do not log filenames, project names, or spreadsheet cell values.
5. How Your Data is Stored
Local Storage (Your Browser)
- •IndexedDB - All your projects, pipelines, and settings are stored in your browser's IndexedDB
- •localStorage - Preferences and UI state (e.g., theme, onboarding completion)
- •Browser cache - Application code and assets for offline functionality
This data persists on your device until you:
- •Clear your browser storage
- •Delete specific projects within the app
- •Uninstall the application (if using PWA)
RowLab uses minimal essential cookies:
- •No tracking cookies - We do not use cookies for tracking or advertising
- •Session cookies - If you sign in, used only to keep you signed in
- •Preference cookies - To remember your settings (theme, language)
RowLab may integrate with the following third-party services:
Analytics
- •RowLab (first-party) - Usage events sent to our API and stored in our database
- •No third-party marketing or advertising pixels for product analytics
Authentication & cloud sync
- •Google Sign-In - When you sign in, Google processes authentication per their policies. We store your name, email, and Google account identifier to maintain your account
- •Optional cloud project storage - If enabled, project and pipeline metadata you choose to sync (pipeline structure, not file contents) is stored in our database provider (for example Neon)
- •Optional Google Drive connection - If you connect Drive, we request only the narrow
drive.file scope (access limited to files RowLab creates or you open with it). Your file bytes flow directly between your browser and Google — they never pass through or get stored on our servers. We store only the OAuth tokens needed to maintain the connection, encrypted at rest; you can disconnect at any time from Settings, which revokes the grant at Google and deletes the stored tokens
8. Data Security
We implement industry-standard security measures:
- •HTTPS encryption - All communications are encrypted in transit
- •Content Security Policy (CSP) - Prevents XSS attacks
- •Input validation - All user inputs are sanitized
- •Minimal server data - Your CSV/Excel file contents stay local unless you use optional cloud sync; we still store account, support submissions, and aggregated analytics on servers we control
- •Encrypted OAuth tokens - Google Drive access/refresh tokens are encrypted at rest (AES-256-GCM) in our database, not stored as plain text
- •Dependency monitoring - Regular security updates
9. Your Privacy Rights (GDPR)
If you are in the EU/EEA, you have the following rights:
- •Right to access - You can export all your project data from the app; for cloud-synced account data, email us and we'll provide a copy
- •Right to deletion - Clear browser storage or delete individual projects locally at any time. To delete your account and all cloud-stored data (account record, synced projects/pipelines, Drive connection tokens), email privacy@builtbysharan.com from your account's email address — we'll complete the deletion within 30 days and confirm by email
- •Right to portability - Export projects as JSON files
- •Right to object - You can block requests to our analytics endpoint or stop using the product features that send events
- •Right to withdraw consent - Disconnect Google Drive from Settings at any time, or disable cookies in your browser
Data you never sync to the cloud stays entirely in your browser and under your control. For the account and cloud-sync data described above, we handle deletion/export requests manually today rather than through a self-service dashboard — email us and we'll act on it directly.
10. Children's Privacy
RowLab is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us.
11. International Data Transfers
Your file data stays in the browser unless you use optional cloud sync. Account, support, waitlist, and analytics records may be processed wherever your database and hosting provider operate (for example the United States or EU), according to their terms and our agreements with them.
12. Data Retention
Your local data: Stored indefinitely in your browser until you delete it
Analytics events: Retained for up to 24 months, then may be deleted or aggregated further
Feedback and waitlist: Retained as needed to respond and improve the product unless you ask us to delete applicable records
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- •We will update the "Last Updated" date at the top
- •Material changes will be announced in the app
- •Continued use of RowLab constitutes acceptance of changes
If you have questions about this Privacy Policy or how we handle your data:
- •Email: privacy@builtbysharan.com
- •Use the Feedback button in the app
- •GitHub: Contact via builtbysharan.com
This Privacy Policy is effective as of July 24, 2026. By using RowLab, you agree to this Privacy Policy.