Effective: August 13, 2026
Version: 1.2
Product: OmniVectors / PyExcelAI Suite
Who we are
OmniVectors, a Cloud Labs LLC company, operates the PyExcelAI suite: a family of financial planning and analysis tools delivered as web applications — currently a set of retirement planners, with additional analysis tools rolling out over time — plus the original PyExcelAI add-in for Excel and Google Sheets (Mac support is on the roadmap). The technology behind the suite, including how it's deployed and how AI is routed, is described at Technology & Platform. We are a small, independent software team.
What we collect — and what we don't
We're built around a minimal-data principle. Here is the full picture, by product area:
- Web apps (retirement planners and other analysis tools as they launch) — if you create an account, we store your email address and the plan/portfolio inputs you choose to save (e.g. age, savings, spending targets). Free-tier use of most apps does not require an account at all, and unsaved sessions are not persisted beyond your browser.
- Ticker symbols and filing queries — entered by you, sent to our API to fetch SEC data, and not stored beyond the duration of the request unless you explicitly save a result.
- Server access logs — standard web-server logs (timestamp, IP address, HTTP method, response code) retained for up to 30 days for debugging and abuse prevention, then automatically deleted.
- Authentication — for email/password accounts we store a securely hashed password (never the password itself); for Google sign-in, OAuth tokens are managed by Google and your browser — we never receive or store your Google credentials.
- Billing — subscription and payment processing is handled by Stripe; we do not store your card details ourselves.
We do not collect: investment account credentials, brokerage login details, government ID numbers, or any data beyond what you directly enter into a planner or what's inherent in an IP address / access log.
Data sources we use
Financial statement data is sourced from the SEC EDGAR public database (sec.gov), freely available to the public. We do not purchase, license, or resell proprietary financial data. Retirement projections are computed entirely from the numbers you enter — we do not pull your real account balances from any external institution.
How your data is used
- To run the calculation or fetch the data you requested.
- To let you return to a saved plan or account.
- To maintain service reliability and diagnose errors using server logs.
- To prevent abuse — rate-limiting and blocking malicious traffic using IP logs.
- To process payments for paid subscriptions, via Stripe.
We do not sell your data, and we do not use it for advertising or profiling.
Third-party services
The suite relies on the following third-party infrastructure:
- Google Cloud / Google Workspace — for Google sign-in and the Google Sheets add-in, governed by Google's Privacy Policy.
- Anthropic, OpenAI, Google Gemini, Groq, and AWS Bedrock — AI features route your request (e.g. plan numbers, financial statement data, or your question) to whichever of these providers is best suited to it, to generate analysis and explanations. We do not include your name or account credentials in these requests. A response may be cached briefly to avoid re-computing the same request twice — see "Data retention" below.
- Stripe — for billing and subscription management, governed by Stripe's Privacy Policy.
- SEC EDGAR — public government API; no personal data is transmitted.
Enterprise and self-hosted deployments
Enterprise customers can deploy the suite, or the PyExcelAI add-in, on their own infrastructure — with SSO, audit logging, and role-based access control. In a self-hosted deployment, your prompts and data are routed to whichever AI model you configure, including your own internally hosted or air-gapped model, and never reach Anthropic, OpenAI, Google, Groq, AWS, or us. Contact us via our Partners program to discuss a self-hosted or enterprise deployment.
Data retention and deletion
Server access logs are retained for up to 30 days. AI response caching — used to speed up repeated requests and reduce cost — is short-lived, typically well under a day, and is deleted automatically once it expires. Saved plans and account data persist until you delete them or close your account. To request deletion of your account and associated data, contact us at the address below — we will act within 7 business days.
Cookies and tracking
We use session cookies necessary to keep you signed in. We do not use advertising cookies or tracking pixels that identify you across other sites.
Children's privacy
The PyExcelAI suite is intended for adults managing their own or their clients' finances. We do not knowingly collect information from anyone under 18.
Changes to this policy
If we make material changes, we will update the effective date above. Continued use of the service after a posted change constitutes acceptance.
Questions about privacy?
Contact us at
[email protected]. We aim to respond within 7 business days.