Who this notice covers
Chartlapse is a client-first visual storytelling tool. This notice describes product behavior for the public web app and Creator. It is not legal advice and may be revised before or after a public launch.
Embedded AI research, remote planning and AI repair are paused for this beta. Copying Excel instructions makes no AI request. If you use your own AI, its terms govern what you share with it. Custom icon URLs are loaded by your browser from the image host; the remote-AI details below describe retained, paused capabilities.
Notice version 2026-09-15 (draft-public-v1).
Your Excel files stay local by default
When you choose a .xlsx file in the Creator, Chartlapse reads it in your browser. The raw workbook bytes and table rows are not uploaded to Chartlapse servers for ordinary planning or preview.
File name and a content hash may appear in a Project Document you create so the result can be audited later. That metadata is part of the document you control—not a server-side workbook store.
- D1 · Original Excel bytes — browser memory only unless you keep your own file
- D2 · Parsed rows and mappings — browser memory only during the session
- Cloud saving stores the validated Project Document, never the original workbook bytes
Project Documents are the unit of save and share
A Project Document is the validated JSON description of your visualization (items, times, values, renderer settings, presentation text, and audit notes). It is the default unit for download, reopen, and sharing.
Downloading JSON stores a file on your device. If you explicitly create a share link, Chartlapse stores that validated Project Document—not the original workbook bytes—in its Cloudflare database for up to 30 days. Share links remain separate from account cloud projects.
After signing in, Save to cloud stores the current Project Document against your site-specific account id. It includes the chart’s normalized data and settings so editing can continue on another device. The first save is explicit; edits to that cloud project then autosave with revision conflict protection.
- Share links expire 30 days after creation
- Expired documents and their report rows are deleted on access or by bounded background cleanup
- Cloud projects remain until you delete one or choose Delete all cloud projects; current safety limits are 50 projects per account and 900KB per Project Document
- Manual early-delete for anonymous share links is not available yet
Optional account sign-in
You can use Creator without signing in. Chartlapse may use the Sites-managed ChatGPT sign-in fallback or offer direct Google and passwordless email-code sign-in. Direct methods are brokered by Supabase; Google handles its own credentials, and Chartlapse never receives your Google or email password.
For direct sign-in, Supabase processes the provider identity, email when supplied, profile claims, and the authentication session. Chartlapse receives a stable Supabase user subject plus available email, display name, and linked-provider claims. Email sign-in also sends a short-lived one-time code through the configured mail delivery service.
Chartlapse uses the stable site-specific or Supabase identifier to scope cloud Project Documents to their owner. Email and optional display name are shown for the current session; cloud project rows do not store them. Original workbook bytes are not attached to the account.
Google and email sign-in with the same verified email may be joined by the identity service. You can also confirm Google from Account to add it to the same Chartlapse account.
AI planning and repair requests
If you use the remote planner (DeepSeek via Chartlapse), the browser calls Chartlapse’s server route. That route forwards a minimized payload to DeepSeek: locale, output mode, renderer choice, your prompt text, chat turns, and whether a local Excel file is present.
For uploaded workbooks, DeepSeek is not sent Excel rows, cell values, or your original file name. Chartlapse may receive a generic local file marker and size for safety limits only, then redacts the name. API keys stay on the server. A local reference planner can plan without leaving your machine.
The separate public-data research command sends your request and retrieved public page excerpts and table previews to DeepSeek with your consent. Selected public source URLs may be read directly from verified public publishers, or through Jina Reader and AllOrigins. It does not include uploaded workbook rows. Downloaded source data retain the public source links, selected cells and document hashes.
Chartlapse privately stores your research request, retrieved public source documents, completed steps and results for up to 7 days, subject to a per-request size limit, so an interrupted request can continue. Your browser keeps an opaque guest credential and request IDs for reconnecting; losing that browser session can prevent access to saved research. Expired research is inaccessible and is removed on subsequent research activity. Cancel research and Delete saved research erase the stored request, public documents and results. A deduplication tombstone and cost audit remain until expiry. Completed steps are reused; a sent call without a saved response is not automatically repeated or assumed refunded. Step accounting is retained through the following UTC month and purged on subsequent activity. Provider-side retention follows each provider's own policy.
When AI repair is available, Chartlapse shows a What leaves this browser preview with the exact field groups and counts before any provider request. The bounded repair payload can include your repair goal, table-shape and issue summaries, opaque preparation candidates and operations, and optional column profiles that contain header text, inferred kind, and ratios. If the protected provider route is unavailable, Smart Prep keeps the repair preview local.
AI repair requires source- and session-specific consent to that exact preview. A source, sheet, payload, or disclosure-version change invalidates consent. Original file bytes, raw table rows, cell values, formulas, comments, hidden sheets, file and sheet names or paths, source URLs and source identifiers, source hash, sheet index, mapping, recipe, generation, account/session identifiers, and API keys remain local and are not sent to DeepSeek in the repair payload.
A repair response is an assistive proposal only. Chartlapse validates it against current local preparation choices, shows changes for review, and applies nothing without separate approval.
Browser storage
Opening the local Full player may write the current Project Document into sessionStorage so a new tab can play it. Choosing Sign in to save may also keep one pending Project Document there across the sign-in redirect; Chartlapse asks before uploading it and removes the pending copy after you save or keep it local. This storage is limited to your browser session/tab context. Closing the tab or clearing site data removes it.
After validation, Creator may keep only the latest Project Document in localStorage for up to 24 hours as a temporary recovery draft. Returning to Creator offers Restore or Discard before opening it. The recovery entry excludes original workbook bytes, editable source rows, File/Blob handles, and undo history; clearing site data or choosing Discard removes it.
Signing in may set strictly necessary first-party session and PKCE cookies so the account can remain authenticated and OAuth redirects can be verified. Chartlapse does not set third-party analytics cookies.
Telemetry and logs
Chartlapse may collect cookie-less aggregate traffic (host platform page views / unique visitors) and first-party product funnel counts: sample start, data accepted, validation pass, first play, export complete, share create, plus short export-failure codes.
These events never include Excel rows, cell values, file names, category labels, notes, sources, or full prompts. Dimensions are limited to route, renderer id, still/animated mode, export format, and stable error codes. Operational logs must not store original Excel rows or full sensitive payloads.
Deletion
Workbook bytes and editable source rows clear when you leave or refresh the page, remove a file, or discard a plan. After a chart is validated, Creator may keep only its Project Document in this browser for up to 24 hours so a reload can recover the draft; it never stores the original workbook in that recovery entry. Downloaded JSON and your original Excel files are deleted only by you on your device. Shared Project Documents expire after 30 days; Chartlapse deletes the expired document and associated safety-report rows on access or through bounded cleanup.
A safety report stores one allow-listed reason and a per-link HMAC-protected network fingerprint. It does not collect a free-text message or store the raw network address in the report row. Repeats from the same network count once, and five distinct reports temporarily quarantine the link.
A signed-in owner can delete one cloud project immediately or delete all cloud projects attached to that site-specific account id. Signing out ends the Chartlapse authentication session but does not delete saved projects.
To request deletion of the authentication account record itself, use Support or email contact@chartlapse.com. Delete all cloud projects first if you also want the saved Project Documents removed immediately.
Third-party AI providers may retain minimized prompts under their own policies; Chartlapse limits what is sent so that surface stays small.
Questions
For product questions, privacy requests, or accessibility feedback, use Support or email contact@chartlapse.com.