Privacy Policy

Last updated: March 26, 2026

OSIVIA (“we”, “us”, or “our”) operates the X-Sheets application (the “Service”). This Privacy Policy explains how we collect, use, and protect your personal data when you use our Service, in compliance with the European General Data Protection Regulation (GDPR).

1. Data Controller

The data controller responsible for your personal data is:

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Email address
  • Username
  • Password (stored in hashed form only)

2.2 User Content

When you use the Service, we store the content you create:

  • Spreadsheets, sheets, and cell data
  • Column definitions and metadata
  • Uploaded files (images, documents)
  • Spreadsheet sharing and permission settings
  • Version history snapshots

2.3 Usage Data

We collect basic usage metrics to maintain and improve the Service:

  • Platform information (Android, iOS, Web, Desktop)
  • App version
  • Number of spreadsheets and data requests

2.4 Payment Data

If you subscribe to a paid plan, payment processing is handled entirely by Stripe. We do not store your credit card number or full payment details on our servers. We only receive from Stripe your subscription status, plan type, and billing period.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Provide the Service: To create and manage your account, store your spreadsheets, and enable collaboration features.
  • Authentication: To verify your identity when you sign in, including email verification and password reset.
  • Payment processing: To manage your subscription through Stripe.
  • Service improvement: To analyze aggregated, non-identifying usage metrics and improve the application.
  • Communication: To send you transactional emails (account verification, password reset).

4. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Performance of a contract: Processing is necessary to provide the Service you have signed up for (Article 6(1)(b) GDPR).
  • Legitimate interests: We process usage metrics to improve our Service, which constitutes a legitimate interest that does not override your rights (Article 6(1)(f) GDPR).

5. Data Sharing

We do not sell your personal data. We share data only with the following third party:

  • Stripe (payment processor) — When you subscribe to a paid plan, your payment information is processed by Stripe Inc. Stripe’s privacy policy is available at stripe.com/privacy.
  • Google (optional sign-in) — If you choose to sign in with Google, we receive your email address and name from Google. Google’s privacy policy is available at policies.google.com/privacy.

6. Data Retention

We do not retain your personal data after account deletion. When you delete your account, all associated data (account information, spreadsheets, uploaded files, and usage data) is permanently removed from our servers.

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data is transmitted over HTTPS (TLS encryption)
  • Passwords are stored using secure hashing algorithms
  • Authentication tokens (JWT) are used for session management
  • Credentials are stored in encrypted local storage on mobile devices

8. Your Rights (GDPR)

As a user in the European Union, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can update your account information at any time through the app settings.
  • Right to erasure: You can delete your account and all associated data at any time from the app settings.
  • Right to data portability: You can export your spreadsheet data in CSV format.
  • Right to object: You can object to the processing of your data for specific purposes.
  • Right to lodge a complaint: You have the right to lodge a complaint with the French data protection authority (CNIL) at www.cnil.fr.

To exercise any of these rights, contact us at contact@www.x-sheets.com.

9. Children’s Privacy

X-Sheets is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at contact@www.x-sheets.com so we can delete that information.

10. Cookies

The web version of X-Sheets uses essential HttpOnly cookies for session management and authentication. These are strictly necessary for the Service to function and do not track your browsing activity. We do not use advertising or analytics cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you via the app or by email. The “Last updated” date at the top of this page indicates when the policy was last revised.

12. Contact Us

If you have any questions about this Privacy Policy or your personal data, please contact us: