1. Scope
This Privacy Policy describes how Sidekick AI (“we”, “us”) handles information when you use:
- the Microsoft 365 Office add-in for Word, Excel, and PowerPoint (task pane);
- the separate Outlook desktop add-in (Windows);
- the browser extension for Chrome, Edge, and Firefox (sidebar);
- our gateway API that those clients call; and
- this website (home, support, and legal pages).
Your use of Sidekick AI is also subject to our Terms of Use. For help, see Support.
2. Information we collect
Account and sign-in
If you sign in with Google or Microsoft, we receive your email address and basic profile fields (such as display name) from that provider. We store them on our gateway to create and manage your Sidekick AI account, plan, and credit balance.
Anonymous (guest) use
Without signing in, the client stores an anonymous ID (for example in browser local storage) and sends it to the gateway so we can apply guest credit limits and reduce abuse.
What is sent for AI requests (by product)
Chat messages and the context needed to answer them are sent to our gateway, which forwards prompts to the AI model provider you select (or a server-hosted key for that provider). We do not store full prompt or document bodies in our database. Usage ledgers store provider/model names and token/credit counts for billing and quotas.
- Excel: structured metadata such as sheet names, headers, types, row/column counts, and small samples (for example preview rows and column samples)—not every cell value in the workbook.
- Word: limited excerpts such as a short selection, a few opening paragraphs, and a heading outline—not the full document body.
- PowerPoint: slide titles (capped), selected slide indexes, and a short text preview of the current slide—not the entire deck.
- Outlook: message metadata and a body preview (length-limited). Attachment text is included only when you choose detailed attachment analysis; OCR images/PDFs may be uploaded to our gateway for recognition.
- Browser extension: text extracted from the active tab up to a maximum length. Optional web search (when you use that feature) is performed via our gateway and a third-party search provider. Office add-ins do not read arbitrary web pages.
Attachments and OCR
Files you attach in chat may be parsed on your device. Images and some PDFs may be sent as base64 to our gateway OCR endpoint (Google Cloud Vision). OCR results may be cached briefly in memory on the gateway for efficiency.
Settings and your own API keys (BYOK)
Preferences (language, theme, selected model) are stored on your device. If you save a provider API key on Basic or Pro, it remains on your device and is sent only with requests to that provider. We do not keep your BYOK keys in our user database.
Usage, IP, and billing metadata
We record credit usage, plan, and technical fields such as last IP and OS for security and quotas. Paid subscriptions (when Stripe checkout is enabled) store Stripe customer/subscription identifiers and plan status—not full card numbers. Card data is handled by Stripe.
3. How we use information
- Provide Sidekick AI features and AI completions
- Authenticate users and enforce credit / plan limits
- Operate OCR and (in the browser extension) optional search
- Prevent abuse, debug failures, and meet legal obligations
4. Where processing happens
- This website and Office add-in web UI: hosted on Cloudflare Pages.
- Gateway API: hosted on Microsoft Azure (App Service).
- AI model providers: the catalogued providers you select (for example OpenAI, Anthropic, Google, and others listed in the product), under their own terms and privacy policies.
- OCR: Google Cloud Vision via our gateway.
- Optional web search (browser extension): third-party search API via our gateway.
- Payments (when enabled): Stripe.
5. Retention and deletion
Account records, login links, credit ledgers, and subscription metadata are kept while needed to operate the service and for security, billing, and legal reasons. Prompt and document content are processed to fulfill the request and are not stored as chat archives on our servers; chat history on your device stays until you clear it. OCR cache entries on the gateway are short-lived.
You can sign out (refresh tokens are revoked). Guest anonymous IDs can be removed by clearing local storage / reinstalling. Self-serve deletion of a full registered account is not yet available in the product UI; contact us via Support and we will help.
6. Your choices
- Use guest mode without creating an account (subject to limits)
- Sign in with Google or Microsoft for a Free plan allowance
- Avoid putting sensitive data in prompts or attachments
- Use BYOK on Basic/Pro so traffic uses your provider account
- Contact Woojooin@gmail.com for privacy questions
7. Children
Sidekick AI is not directed to children under 13 (or the minimum age required where you live). We do not knowingly collect personal information from children.
8. Changes
We may update this Privacy Policy. The “Last updated” date above will change when we do. Continued use of Sidekick AI after an update means you accept the revised policy.
9. Contact
Privacy questions about Sidekick AI: Woojooin@gmail.com · Support page · Terms of Use