Policy
Privacy Policy
Controller & Contact
The controller responsible for the processing described in this policy is Ivan Gushchin, reachable at the postal address stated in the Legal Notice, except where another provider acts as an independent controller for its own service. For privacy, access, deletion, or other requests, contact us at support@image-to-excel.com or through https://image-to-excel.com/support.html.
This policy explains what data Image to Excel collects, how we use it, when we share it, and how we protect it when you use the website, the Chrome extension, and the hosted extraction service.
Information We Collect
- when you use the extraction tools (the extension's Select area capture, upload, and batch flows, or the website's preview tools): the image regions you select, the images and PDFs you upload, the PDF pages you choose, and request metadata such as MIME type, file size, and selected page numbers — this content is sent off your device only when you start an extraction
- the extracted rows, columns, and table results returned to your browser for review and export
- a pseudonymous guest identifier and usage counts kept in your browser (extension storage or the website's local storage) to apply trial limits and for basic abuse prevention
- basic operational logs such as timestamps, error details, and technical request metadata, and the IP address of your requests, which we use for rate limiting and abuse prevention
- technical diagnostics about AI requests, such as model name, timeout outcome, token counts, page count, and payload size
- aggregate service-quality counts: to compare AI providers, the website sends a random share of extraction runs to a different provider and counts, per provider and as daily totals only, whether the result was usable, how long it took, and whether it was downloaded or copied; these counts contain no identifier and no file content
- if you create an account or sign in: the email address you register with and account identifiers, processed through Amazon Cognito
- support messages and files you choose to send us
- if you open one of our tracked links (addresses of the form image-to-excel.com/l/…, which we use in posts we publish ourselves): a click record holding the time, whether the link was known to us, a salted one-way hash of your IP address and of your browser's user agent, and the address of the referring page — we use these only to see which posts bring visitors, and they are scheduled for automatic deletion after 90 days
You can try the website's preview tools and start in the extension without providing your name, email, or payment details.
Local-Only Tools
The website's scanned-PDF checker (the tool that tells you whether a PDF is scanned or searchable) runs entirely in your browser using a local PDF engine. Files you open there are analyzed on your device and are never uploaded — nothing you open in that tool is sent to our servers or to any AI provider. Only the extraction tools send content for processing as described in this policy.
How We Use Your Information
- to extract structured tables, text, or JSON from the images and PDFs you submit and return a reviewable result
- to provide capture, upload, review, XLSX export, CSV export, and Google Sheets export flows
- to authenticate users, maintain sessions, enforce usage limits, prevent abuse, and protect service reliability
- to debug failures, measure reliability, and maintain operational logs
- to process support, privacy, access, deletion, and other rights-related requests
- to comply with legal and record-keeping obligations
Chrome Extension and Browser Data
The extension accesses the current tab only after a user action so you can select a visible table area from a page, image, or browser-open PDF. It does not monitor browsing history in the background to build profiles or advertising audiences.
Browser captures, uploads, and selected PDF pages are sent off device only when you choose extraction. For reviewed browser captures, the stored review-session state and extraction request do not include the current-page URL or title.
The extension may keep prepared input, review state, guest state, and sign-in recovery state in browser storage until you clear it through product controls, browser storage management, successful cleanup flows, sign-out, or uninstall.
Legal Bases
We process data for the extraction, account functions and contract-related support you request under Article 6(1)(b) GDPR. Required inputs are necessary for the relevant feature; without them we cannot provide it. Browsing the website does not require an account.
Service security, abuse prevention, technical diagnostics, general enquiries and referral-link measurement rely on Article 6(1)(f) GDPR. Our legitimate interests are operating a secure, reliable service, responding to enquiries and measuring the reach of our own posts. Hashed identifiers and guest identifiers are pseudonymous and can still be personal data.
Optional Google Analytics processing relies on your consent under Article 6(1)(a) GDPR. Processing needed to fulfil specific legal obligations relies on Article 6(1)(c) GDPR.
Infrastructure Providers
Amazon Web Services hosts the Image to Excel website and API and stores account, usage, and operational records on our behalf, including Amazon Cognito for sign-in. We do not authorize these providers to use this data for advertising or to build profiles of visitors. Email you send to our support address reaches us through Cloudflare's email routing service, which forwards it to our mailbox; our replies are sent through Amazon Simple Email Service.
Contact-form messages (name, email address, subject, message, language and page path) are delivered to our support mailbox through Amazon Simple Email Service. Technical request data is processed to prevent abuse. For postal correspondence, the address service named in the Legal Notice receives and forwards your message. We retain support correspondence until the enquiry is resolved, and longer only where specific statutory retention duties or establishing, exercising or defending legal claims require it.
Third-Party AI Services (Google Gemini, Amazon Bedrock)
Image to Excel uses Google Gemini through a backend-owned Gemini API integration to process submitted images, PDFs, and extraction instructions and to return structured table data. This covers the website's preview tools as well as the extension's capture, upload, and batch flows. The content you submit for extraction and our instructions are sent to Google's servers for AI processing as part of delivering the result you request.
- Google terms apply: data sent to Gemini is subject to the Gemini API Additional Terms and Google Privacy Policy.
- Processing only: we use Gemini to generate the extraction result you request, not to train models on our side.
- No optional training submissions: we do not intentionally share submitted files, prompts, or Gemini responses with Google through optional datasets or feedback features for model training.
- Paid API handling: Google states that for Gemini API Paid Services it does not use prompts, files, or responses to improve Google products and processes them under its data processing terms.
Even for Paid Services, Google may temporarily log prompts and responses to detect abuse and meet legal obligations. No model training does not mean immediate deletion by Google. See the Gemini API Paid Services terms for details.
Some extraction requests may instead be processed by AI models hosted on Amazon Bedrock, a service of Amazon Web Services (AWS). These are currently Gemma, an open model developed by Google that AWS runs in its Frankfurt (Germany) region, and OpenAI GPT models, which AWS may process in any AWS region worldwide. AWS operates these models itself; the model developers do not receive your content.
- AWS terms apply: processing on Amazon Bedrock is subject to the AWS Service Terms, the AWS GDPR Data Processing Addendum, and the AWS Privacy Notice.
- No training: AWS states that Amazon Bedrock does not use prompts or outputs to train models and does not share them with model providers.
- Retention: for Gemma, AWS states that Amazon Bedrock does not store inputs or outputs by default. For OpenAI GPT models, AWS may retain inputs and outputs flagged by its automated abuse classifiers for up to 30 days, in the region where the request was processed. AWS may also store and review input flagged as apparent child sexual abuse material to meet legal reporting obligations.
Google Sheets Export
If you click Export to Google Sheets, the extension starts a separate Google sign-in and consent flow and sends the reviewed table content to the Google Sheets API to create a new spreadsheet in your Google account. This is separate from Image to Excel account sign-in and only happens after that explicit export action.
- Scope: the extension requests the minimal
drive.filescope for files it creates. - Data sent to Google Sheets: spreadsheet title, worksheet names, headers, rows, and formatting needed to create the reviewed table.
- No existing-sheet access: the reviewed flow creates a new spreadsheet and does not edit existing spreadsheets.
- Google terms apply: Sheets export is subject to Google's applicable terms and Google Privacy Policy.
International Data Transfers
Our providers may process data outside the EU/EEA, particularly in the United States. An adequacy decision under Article 45 GDPR can permit a transfer; the EU-U.S. Data Privacy Framework applies only to appropriately certified U.S. recipients and covered processing. The Framework does not replace missing certification.
Without an applicable adequacy decision, appropriate safeguards under Article 46 GDPR are required, such as EU Standard Contractual Clauses and supplementary measures where necessary. For information about the safeguards applicable to your data and a copy, contact support@image-to-excel.com.
AI-Generated Output
AI-assisted extraction can make mistakes. The extracted table may contain incorrect, missing, merged, or misread values. Review the rows, columns, and exported XLSX or CSV files against the original image or PDF before relying on them for anything important.
What We Do Not Do
- we do not sell your personal data
- we do not use submitted files or browser-derived data for advertising or build browsing profiles
- we do not share submitted files, extracted tables, or browser-derived data with data brokers or similar resellers
- we do not send reviewed table content to Google Sheets unless you explicitly choose Export to Google Sheets
- we do not collect browsing history in the background for unrelated purposes
- we do not store or transmit the current-page URL or title as part of reviewed browser-capture extraction requests
- we do not use AI output to make legal, employment, health, credit, or similarly significant decisions about you
Local Storage and Cookies
The website keeps a small pseudonymous guest identifier and usage
counts in your browser's local storage to apply the preview
tools' trial limits. The site does not set advertising or
cross-site tracking cookies. Optional analytics cookies
(Google Analytics 4) are strictly opt-in: nothing is set and
the analytics script is not loaded unless you choose
Accept analytics in the cookie banner, and
you can change or withdraw your choice at any time via the
Cookie settings button shown on every page.
Your decision itself is stored for up to 12 months in a
first-party consent cookie (i2e_analytics_consent).
When you accept, Google Analytics sets cookies such as
_ga and _ga_<id> to measure
visits and traffic sources; this data is processed by Google
under the
Google Privacy Policy
(see also
how Google uses data from sites that use its services).
Choosing reject removes the analytics cookies we can clear
from your browser.
The Chrome extension stores prepared input, review-session state, a pseudonymous guest identifier, optional sign-in tokens, and sign-in recovery state in local extension storage so the current workflow can continue after popup close, refresh, retry, or sign-in. This on-device data remains until you clear it through product controls, browser storage management, successful cleanup flows, sign-out, or uninstall.
Strictly necessary storage or access for expressly requested features (such as guest limits, sign-in and consent preferences) relies on Section 25(2)(2) TDDDG. Optional analytics storage and access rely on consent under Section 25(1) TDDDG. Google Analytics processes cookie identifiers, page views, interactions, referral sources, and browser and device information; Google also receives your IP address during transmission. The provider is Google Ireland Limited, with possible processing by Google LLC in the United States. The _ga and _ga_<id> cookies have a default lifetime of up to two years from creation or renewal; browser settings may shorten this. Withdrawal stops future analytics collection but does not automatically delete data already sent.
Data Retention
- Submitted content is processed to produce the result you request (see Third-Party AI Services above, which governs the transfer to Google) and is retained by us only as long as needed to process the extraction, return the result, troubleshoot reliability or security issues, handle support, or meet legal obligations — not for advertising or model training.
- Regular CloudWatch retention for API and operational logs is configured to 30 days. Short-lived operation and reservation records have a 30-minute expiry; IP-based guest-creation counters have a 25-hour expiry. Expired DynamoDB records are physically deleted asynchronously, which can take a few additional days.
- Account and usage records are kept while your account exists and are deleted when your account is deleted, except where records must be kept longer under statutory retention obligations.
- Browser-held data (guest identifiers, usage counts, review and recovery state) stays on your device until you clear it.
- Backup and business-continuity copies may persist for a limited additional period before deletion cycles complete.
- Tracked-link click records expire after 90 days and are then deleted asynchronously. Aggregate click counters without individual visitor identifiers may remain longer.
Your Rights
Under the conditions set out in the GDPR, you have rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18) and data portability (Article 20). You can withdraw consent at any time for the future; this does not affect the lawfulness of earlier processing. Disable analytics through “Cookie settings”.
Right to object (Article 21 GDPR): You may object to processing based on legitimate interests on grounds relating to your particular situation. For direct marketing, an objection would be possible at any time without giving reasons.
For requests, including deletion of your account and associated usage records, email support@image-to-excel.com. Identify the account email where relevant; proportionate identity verification may be needed. We normally respond within one month and will explain any legally permitted extension. You can clear browser-held data through product or browser settings.
Under Article 77 GDPR you can complain to a supervisory authority, particularly where you habitually reside, work or believe an infringement occurred. Contact details are available in the directory of German data protection authorities.
Children
Image to Excel is not directed to children and is intended for users who are at least 18 years old, consistent with the Gemini API terms.
Changes to this Policy
We may update this policy as the product, providers, or laws change. Material changes will be reflected on this page with an updated date.
Questions About this Privacy Policy
If you have questions about this Privacy Policy or our privacy practices, contact us at support@image-to-excel.com or visit https://image-to-excel.com/support.html.