Privacy Policy
Version 1.1, published August 1, 2026 · Website and waitlist sections apply now; account sections apply at public launch
This is the permanent link to the current version. Read the current version
Pre-launch notice: Sheetward is currently in the Early Access waitlist phase. The parts of this Policy about the sheetward.com website and the Early Access waitlist apply now; the parts about accounts, workspaces, Customer Content, AI features, and billing apply from public launch, when production accounts and paid subscriptions become available, until then no production account exists and no payment details are collected. This Privacy Policy explains how SemaBytes Corp., 5900 Balcones Drive STE 100, Austin, TX 78731, USA, doing business as Sheetward ("Sheetward", "we"), handles personal data across the Sheetward marketing website, the Early Access waitlist, and the Sheetward platform, the hosted service that turns an App Specification authored in a spreadsheet into a working web application. It replaces the earlier waitlist-only privacy notice published at this address. Contact: privacy@sheetward.com.
Scope, and the two roles we play
This Policy covers all three parts of Sheetward: the marketing website at sheetward.com, including the help, template, comparison, and knowledge pages published there; the Early Access waitlist, including the sign-up form and the emails we send to the people on it; and the Sheetward application: workspaces, generated applications, and the accounts of the people who use them. The website and the waitlist are live today. The application sections describe how the platform handles personal data once production accounts open at public launch.
Sheetward plays two different roles, and which one applies decides who is answerable to you. For account, workspace, waitlist, billing, and platform-operations data, Sheetward decides how the data is used, exactly as this Policy describes, so bring those questions to us.
For Customer Content, Sheetward acts on the customer’s behalf and only on the customer’s instructions. Customer Content is everything a workspace puts into the Service: workbooks and App Specifications, records entered into generated applications, files and attachments, prompts, exports, and backups. The workspace decides what goes in, who may see it, and when it is deleted; we process it only to provide, secure, and support the Service, and we do not mine it for our own purposes. If a generated application holds personal data about you and you are not that workspace’s admin, the workspace running the application is responsible for it, contact that workspace first, and we will support its admins in answering you.
What we collect
Waitlist data, collected today. When you join the Early Access waitlist we collect your email address (required) and, only if you choose to give them, your name, company, country, and a short message about what you would build. With your submission we store a consent record: the date and time, the version of the consent wording you agreed to, and the page the form was submitted from, so we can show what you agreed to and when. The request also carries your IP address and an approximate country derived from the network; both are stored with the submission and used only to prevent spam, fraud, and misuse.
Account data (from public launch). When you create an account: your name, email address, and a password (stored only as a secure hash), your language and regional preferences, and your plan and workspace membership. We record your acceptance of the Terms of Service: the date, time, and version of the text you accepted: and, separately, an optional marketing-email opt-in with its own date and version. If you turn on two-factor authentication we store the data needed to verify it.
Google data. If you sign in with Google, we receive your basic Google profile: name, email address, and account identifier, solely to create and authenticate your account; we never receive your Google password. Separately, the Service offers an optional Google Sheets import and export. It uses per-file access only: you pick the specific file in Google’s own picker, Sheetward sees only that file or a file it creates for you, and no long-lived Google credentials are stored, the browser obtains a short-lived access token for each action. We ask for this access at the moment you use the feature, never at sign-in.
Workspace and user data. Workspace names and settings, invitations (the invitee’s email address and who invited them), member roles, session records used to enforce the single-active-session and idle-timeout protections, and audit logs of significant actions (who changed what, and when), which workspace admins can review.
Customer Content. The workbooks, App Specifications, records, line items, lookup data, files and attachments, AI prompts, exports, and backups your workspace submits. We handle it as the previous section describes.
Technical data. When you use the website or the Service, we and our infrastructure providers process your IP address, an approximate network-derived location, browser and device information, timestamps, and security and error logs: to deliver the site and the Service, keep sessions working, prevent abuse, and diagnose problems. The marketing website uses cookieless, aggregate web analytics; the application itself carries no advertising or analytics trackers.
Billing data, from public launch. Nothing is collected today: no payment details are taken and nobody is charged. When paid subscriptions open, purchases are processed by Paddle acting as Merchant of Record. Paddle runs the checkout, collects and processes your payment-card and billing details directly under its own privacy policy, issues your invoice or receipt, and calculates, collects, and remits applicable sales tax or VAT. Sheetward never receives or stores full payment-card numbers. From Paddle we keep only what we need to administer a subscription: the Paddle customer, subscription, and transaction identifiers, the plan and billing interval you chose, and your subscription and payment status.
Why we use it
We use personal data to: provide the Service (run your workspace, generate and host your applications, store and return your data); keep the website and accounts secure (authenticate sign-ins, enforce session protections, send security alerts, and prevent spam, fraud, and abuse; send the messages the Service requires: account, security, service-change, and, once billing exists, billing messages, which are not marketing; tell you about Early Access and launch if you joined the waitlist, and send product news and offers only if you separately opted in; provide support when you ask for it; operate and improve the platform using aggregate, de-identified usage measures; and meet our legal obligations and enforce our Terms.
Where our use of your data rests on your consent (the waitlist emails and the marketing opt-in), you can withdraw that consent at any time with effect for the future, using the unsubscribe link in any message we send or by writing to privacy@sheetward.com. Declining or withdrawing marketing consent never affects the Service. We do not use your data for purposes unrelated to Sheetward, and the section on what we never do sets out the lines we do not cross.
Cookies
The Sheetward marketing website sets no advertising or analytics cookies and runs no behavioral-tracking scripts; its analytics are cookieless and aggregate. The application uses strictly necessary cookies only, a first-party session cookie that keeps you signed in, essential to the Service and never used for advertising or cross-site tracking. Cloudflare, which delivers and protects our sites, may set strictly necessary security cookies when an enabled security feature requires one. We use no advertising cookies anywhere.
AI processing
Sheetward’s AI-assisted features (drafting an App Specification from your description, and the support assistant) are optional and run only when you invoke them. When you use one, your prompt and the context the feature needs are sent to the AI model host we have selected for that feature, which processes them in the United States and returns a response. Support-assistant requests pass through automated redaction before they leave our servers. We use only the model hosts named under “Service providers” below, and we update that list when a host changes. Today both AI features run on Anthropic Claude models through Amazon Bedrock.
Neither we nor our AI providers use your prompts or your Customer Content to train AI models shared with other customers or with anyone else. AI output can be inaccurate or incomplete: a drafted App Specification is a proposal you review and approve before an application is generated from it.
Service providers
We run the Service with a small, named set of providers. Each acts for us under a written data processing agreement and on our instructions, and may not use your data for its own purposes. These six are the complete list:
Cloudflare, Inc.: the network edge: DNS, TLS, content delivery, security and abuse protection, hosting of the marketing website, storage of waitlist submissions, and object storage for file delivery. Processing takes place in the United States, on a global edge network.
Supabase, Inc., databases and file storage for the platform and for Customer Content, including backups. Processing takes place in the United States.
Amazon Web Services, Inc.: application hosting and compute, and AI model hosting through Amazon Bedrock, which runs the Anthropic Claude models behind the AI features described above. Processing takes place in the United States.
Microsoft Corporation, AI model hosting through Microsoft Foundry, which runs OpenAI models for the AI features described above when we have selected it as the host for a feature. Processing takes place in the United States and globally.
Resend, Inc.: transactional email delivery: waitlist notifications, invitations, verification, security alerts, and service notices. Processing takes place in the United States.
Paddle: payment processing, and tax calculation and remittance, as Merchant of Record for paid subscriptions from public launch. Paddle collects your payment details directly and handles them under its own privacy policy. Processing takes place in the United States and globally.
We will update this list when a provider changes, and the section on changes to this Policy describes how we announce it.
International transfers
Sheetward operates from the United States, and the providers above process data in the United States. If you use the website, join the waitlist, or use the Service from another country, your data is transferred to and processed in the United States. Wherever it is processed, it is protected by the safeguards described in this Policy and by the data processing agreements we hold with each provider.
How long we keep it
Waitlist entries, until the earliest of: you unsubscribe or ask us to delete your entry; 24 months after your last interaction with Sheetward; or 90 days after public launch, unless by then you have created an account or separately consented to continued communications.
Account data: for as long as your account exists, then deleted or de-identified within a short period after account deletion, except records we are required to keep, such as the record that you accepted the Terms or, once billing exists, invoice records.
Customer Content, under your workspace’s control: it stays until your workspace edits or deletes it. Deleted records and apps go first to the workspace recycle bin, from which admins can restore or purge them.
Backups, manual exports live wherever you save them, outside our systems. Hosted automatic backups, on the plans that include them, are kept for the retention window the workspace admin chooses within the plan’s limits and then deleted on schedule; deleted live data ages out of hosted backups as those backups expire.
Workspace closure: closing a workspace starts a grace window (currently 30 days) during which the workspace stays usable for a final export and the closure can be cancelled. When the window ends, the workspace’s Customer Content (databases, files, uploaded workbooks) and its hosted backups are permanently deleted from the Service.
Logs: security, abuse-prevention, and technical logs are kept only as long as their purpose requires and are then deleted or aggregated. Workspace audit logs, which admins can review, remain available for the life of the workspace and are deleted with it.
Your rights and requests
You can ask us to: give you access to the personal data we hold about you; correct it; delete it; give you a portable copy; stop or limit a particular use, including objecting to it; and withdraw a consent you gave, with effect for the future. Exercising any of these is free, and using them never disadvantages you.
Write to privacy@sheetward.com and we will answer promptly; we may need to check that a request about an account really comes from its holder. Much of this is also self-serve: you can edit your profile, export your data, and delete content in the product, workspace admins can export or close an entire workspace, and every marketing or waitlist email carries an unsubscribe link.
If your request concerns data held inside a customer’s generated application, we will refer it to that workspace’s admin, as the first section explains, and support them in answering you. If our answer does not satisfy you, you may take the matter to the data-protection authority for your country.
What we never do
We do not sell personal data. We do not share personal data for targeted or cross-context behavioral advertising. We do not use your prompts or your Customer Content to train AI models shared with other customers or third parties. We do not run advertising or analytics trackers inside the application, and we place no advertising or analytics cookies on the website. We do not use waitlist details for unrelated newsletters or partner marketing.
Children
Sheetward is intended for business use by adults and is not directed to anyone under 18. The Early Access waitlist is likewise for adults aged 18 or older. We do not knowingly collect personal data from children; if you believe a child has joined the waitlist or created an account, write to privacy@sheetward.com and we will delete it.
Security and incidents
We maintain reasonable administrative, technical, and organizational safeguards: encryption of data in transit and at rest, additional field-level encryption for sensitive fields such as identification and card numbers, password hashing and breached-password screening, role-based access controls, audit logging, session protections (a single active session, optional two-factor authentication, and idle timeout), rate limiting and bot protection, network protections at the edge, and backups. Our personnel’s access to Customer Content is restricted to what operating and supporting the Service requires.
No online service can guarantee absolute security. If we learn of an incident affecting your personal data, we will investigate, take corrective action, and notify affected customers and the relevant authorities without undue delay where notification is required or otherwise warranted.
Changes to this Policy
We may update this Policy from time to time. When we do, we will change the version and date shown at the top and publish the revised Policy here. For material changes we will give advance notice, by email to waitlist subscribers or workspace admins, and by a notice in the product, before the change takes effect.
Contact
SemaBytes Corp., doing business as Sheetward, 5900 Balcones Drive STE 100, Austin, TX 78731, USA. Privacy questions and requests: privacy@sheetward.com.
This Policy may be published in several languages for convenience. If the versions differ, the English version controls, except where the law of your country of residence requires otherwise.