In short. Arrayora writes Excel formulas from what you type. Most requests are solved on your computer and nothing is sent anywhere. You can use every free feature without an account. Only when a request needs AI (Pro or a top-up) does Arrayora send, from the active sheet only: your typed request, the sheet name, the range address, the number of rows and columns, and the column headings. With Privacy Shield on (the default) no cell values are sent; if the first row does not clearly look like headings, neutral names such as "Column B" are sent instead. With Privacy Shield off, the first row of the range is sent as it is, and it may contain data. No other cell values are ever sent. To buy or use Pro you sign in with your Microsoft account. Payments are handled by Razorpay; we never see your card or UPI details. We do not sell your data, show ads, or train AI models on it.
1. Who we are
Arrayora is a Microsoft Excel add-in operated by Mithlesh Udainiya, trading as Arrayora by Udainiya Technologies ("we", "us"). Our postal address is in section 11. For personal data processed through Arrayora we are the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the "controller" under the EU and UK General Data Protection Regulation (GDPR).
Contact: support@udainiya.com. Grievance Officer: see section 11.
2. What stays on your computer
Arrayora reads the cells you select, or the used area of the active sheet, inside Excel on your computer so it can plan a formula and show you a preview. Nothing is written to your sheet until you press Insert. Free features (local formulas, the data cleaner, explanations) never send your data to our server.
The add-in keeps these items in the browser storage of your Excel installation. They never leave your computer unless listed in section 3:
| Stored item | Purpose |
|---|---|
| Language, theme, night mode, contrast, mascot choice | Remember your preferences |
| Privacy Shield on/off | Remember your privacy choice |
| History of your last requests (request text, target cell, formula) | Show the History list; you can clear it with "Reset this seat" |
| A random local ID | Used only on this computer; it is not sent to our server |
| If you signed in: a signed account token | Lets this device use your Pro account; removed when you sign out or reset |
| Your acceptance of these terms (version and time) | Record your consent |
Attached files (for example a PDF you import) are read only on your computer and are never uploaded.
3. What leaves your computer, to whom, and why
| Recipient | What is sent | Why |
|---|---|---|
| AI model provider: Google (Gemini API, paid tier), through our server | Only on Pro or a top-up, and only when a request cannot be solved on your computer. From the active sheet only: the text you typed, the sheet name, the range address, the number of rows and columns, and the column headings. Privacy Shield on (default): headings are sent only when the first row clearly is a heading row (an Excel Table header, or text labels above numbers) and does not look like personal data (for example an email address or a long number); otherwise neutral names such as "Column B" are sent. No cell values are sent. Privacy Shield off: the first row of the range is sent exactly as it is. If your range has no heading row, that first row is data. No other cell values, no other sheets and no files are ever sent. Google does not receive your account ID, email or token. |
Understanding your request so a correct formula can be built |
| Our server (runs on Cloudflare Workers and Cloudflare storage) | Nothing while you use free features without signing in. If you sign in for Pro: a scrambled account ID made from your Microsoft account ID, the email address of your Microsoft account, the current sign-in session (one device at a time), the number of sign-ins today, your plan and its end date, AI credits used and the AI cost of your requests this period, top-up balance, a per-minute request counter, your consent record, and payment records (payment ID, amount, status, item). The AI request itself passes through and is not stored. Cloudflare necessarily processes your IP address to deliver the request and protect against attacks; we do not store your IP address in our records. | Your account, Pro and credits, one-device rule, usage limits, preventing abuse, unlocking what you paid for |
| Microsoft | Excel and the Office add-in platform run under Microsoft's own privacy statement. When you choose "Sign in with Microsoft", you sign in on Microsoft's page; Microsoft gives us a signed sign-in token with your account ID, name and email. We keep only the scrambled account ID and the email. For the microphone button, see "Voice typing" below. | Sign-in for Pro; running the add-in; optional voice input |
| Voice typing (only when you tap the microphone) | With an offline speech pack on your device: your voice is turned into text on your computer and nothing is sent. Downloading a pack is a one-time download from your browser maker that the add-in asks you about first; it does not contain your voice. Otherwise the add-in asks you first, every session. If you allow your browser's online speech service, your voice goes to the browser maker (Google or Microsoft) under their privacy terms, not to us. If you are signed in for Pro and allow it, a short recording (at most 20 seconds) passes through our server to Google (Gemini API, paid tier) only to turn it into text. This uses AI credits. We do not store the recording or the text on our server; only the credit count and AI cost are recorded, as for any AI request. You always see the words in an editable "I heard" box, and nothing runs until you press Run. |
Optional voice input |
| Razorpay (payment gateway) | You enter your payment details (card, UPI, net banking, name, email, phone) directly on Razorpay's page. We give Razorpay the item, the amount, your account email and the scrambled account ID so the payment reaches the right account. We receive only a payment ID, amount, status and the item bought. | Taking payment and fraud checks |
Your headings and your typed words can themselves be personal data (for example a column named after a person, or a name you type in a request). Please do not type passwords, bank details, health information or other sensitive information into requests.
4. What we do not do
- We do not sell or rent personal data, and we do not show advertising.
- We do not train AI models on your requests or sheets. Under Google's terms for the paid Gemini API, Google does not use prompts or responses to improve its products; Google keeps them for up to 55 days, only to detect abuse and meet legal obligations.
- We do not upload your workbook, read other sheets, or send cell values except the first row when you turn Privacy Shield off.
- We do not store your card number, UPI PIN, password or your name.
5. Legal basis
- India (DPDP Act): your consent, given with the "I agree" box, for AI processing and your account; and "legitimate uses" permitted by section 7, such as complying with law and processing a payment you start.
- Information Technology Act, 2000 and SPDI Rules, 2011: we publish this policy, collect only what is needed, keep reasonable security practices, and appoint a Grievance Officer.
- EU/UK (GDPR): performance of our contract with you (Art. 6(1)(b)) for your account, Pro and payments; consent (Art. 6(1)(a)) for sending requests to the AI provider; legitimate interests (Art. 6(1)(f)) for abuse prevention.
6. International transfers
Cloudflare, Google and Microsoft process data in data centres in India and other countries, including the United States. The DPDP Act allows transfers except to countries the Government of India restricts; if a country used by a provider is restricted, we will stop using it there. For EU/UK users we rely on our providers' data processing terms, including Standard Contractual Clauses where they apply.
7. How long we keep data
| Data | Kept for |
|---|---|
| Account record (scrambled account ID, email, plan, credits, AI cost, consent) | About 400 days after its last change, then deleted automatically; sooner if you ask us to delete it |
| Payment status records | About 400 days, then deleted automatically; longer only if tax or accounting law requires |
| Checkout link records (account ID and item) | 7 days |
| AI requests | Not stored by us. Google's retention is described in section 4. |
| Settings, history and token on your computer | Until you sign out, use "Reset this seat", or remove the add-in |
8. Your rights and choices
- Use without an account: free features never need sign-in and send nothing to us.
- Privacy Shield: keep it on so no cell values are sent.
- Access, correction and erasure: ask what we hold about your account, ask us to correct it, or ask us to delete it.
- Withdraw consent at any time by emailing us, signing out, or removing the add-in. Withdrawal stops AI processing; requests solved on your computer keep working. It does not affect processing already done.
- Nominate a person to exercise your rights if you die or become unable to (DPDP Act section 14).
- EU/UK users also have rights to data portability, to object, and to complain to their data protection authority.
- Complaints in India: contact our Grievance Officer first. If you are not satisfied with the answer, you may complain to the Data Protection Board of India.
- How fast we reply: we answer requests to access, correct or erase your data, nominations and grievances within one month of receipt, and never later than 90 days.
Write to support@udainiya.com from the email of your Microsoft account, with your Razorpay payment ID if you have one. We may ask for reasonable proof before acting.
9. Children
Children's data. Arrayora is only for adults aged 18 and above. We do not knowingly collect or process personal data of anyone under 18 (a "child" under India's Digital Personal Data Protection Act, 2023), and we do not offer parental-consent accounts. When you first open Arrayora, and before you can use Pro/AI features, we ask you to confirm that you are 18 or older (we keep the date, time and the version of these terms you accepted). If we learn that an account belongs to someone under 18, we will close the account, stop processing, and delete the related personal data, except where the law requires us to keep it (for example, payment and tax records). We do not track, profile or show targeted advertising to anyone. If you believe a child has given us personal data, contact us at support@udainiya.com.
10. Security and breaches
All connections use HTTPS. Secret keys stay on our server, account tokens are signed and work on one device at a time, Microsoft sign-in tokens are checked against Microsoft's published keys, and data is kept only as long as listed above. If a personal data breach happens, we will inform affected users and the authorities as required by law, including the Data Protection Board of India and CERT-In within the time limits they set. Under the DPDP Rules, 2025, we will tell each affected user without delay what happened, the likely impact, what we are doing about it and what you can do, and we will send the Data Protection Board of India a detailed report within 72 hours. Reportable cyber incidents are reported to CERT-In within 6 hours.
11. Grievance Officer
Name: Mithlesh Udainiya
Designation: Grievance Officer (Proprietor)
Email: support@udainiya.com
Phone: +91 96960 82548
Address: Near Amul Franchise Store, Ait, District Jalaun, Uttar Pradesh 285201, India
We acknowledge a complaint within 48 hours and resolve it within one month of receipt, or sooner if the law requires. This person also answers any question about how we process your personal data.
12. AI-generated results
Formulas may be prepared with the help of an AI model. Arrayora always shows a preview before anything is written. The preview says whether the formula was prepared on your computer, prepared by Arrayora's AI, or prepared on your computer because the AI did not answer, and when the AI was used it says exactly what was sent. Please check the preview before inserting.
13. Changes to this policy
If we change this policy in a way that affects how your data is used, the add-in will show the new version and ask you to agree again. The version date at the top always shows the current version.