Privacy policy
Last updated 30 August 2026 · Applies to the TableDI desktop application and tabledi.com
The short version. Your tables, files and formulas stay on your computer — we have no copy of them and no way to get one. The only things that reach us are an anonymous startup ping (switchable off), crash reports if you leave them on (switchable off), and your email address if you buy a license. That's the whole list.
1. Your data stays on your machine
TableDI is a desktop application, not a web service with a desktop wrapper. Your workspace — tables, sheets, formulas, dashboards, imported files — is stored in a normal folder in your user directory:
- macOS —
~/Library/Application Support/tabledi-desktop/ - Windows —
%APPDATA%\tabledi-desktop\
You can back that folder up, copy it to another drive, or delete it. We never receive it, we have no server-side copy, and there is no cloud account it could be synced to. The app works with the network switched off.
When you connect TableDI to an external source (an API, a database, a spreadsheet service), that connection goes straight from your machine to that system using credentials you enter locally. It doesn't pass through us.
2. AI features: your key, your provider, your data
The AI features work on a bring-your-own-key basis. You paste an API key from an AI provider into the app's settings; the key is stored locally with the rest of your settings. When you ask for a formula, a cleanup, or a chart, TableDI calls that provider directly from your machine with the prompt and the data you selected for that request.
We are not in the middle of that call. We do not see your key, the prompt, the data, or the answer, and we receive no record that the call happened. What that provider does with the request is governed by their policy — so read it, the same way you would for any tool you paste an API key into. Leave the key blank and everything else in TableDI works identically.
We say "your tables live on your machine" rather than "AI is offline", because that's what's true: the local guarantee covers your workspace, and the AI call is an outbound request you choose to make, to a provider you chose.
3. What we do receive
a. Anonymous startup ping
On launch, and roughly every six hours while running, the app sends a small ping so we can count installs and active users. It contains exactly four things:
| Field | Example | What it is |
|---|---|---|
machineId | 9f2a… | A SHA-256 hash of your machine's hardware UUID. We store the hash; it can't be reversed into an identifier, and it isn't linked to a name or email. |
appVersion | 0.0.7 | Which version to keep supporting. |
platform | darwin-arm64 | OS and CPU architecture. |
edition | free / paid | Whether a license is active. |
No file names, no table contents, no license key, no account. The receiving server also records the request's IP address in its logs, as any web server does. You can switch this off: Desktop settings → Privacy. It stops at the next launch.
b. Crash reports
If the app or its local engine crashes, an error report is sent to Sentry (our error tracking provider) so we can fix it. Before sending, the report is scrubbed: the user object is deleted outright, and email addresses, long tokens and your home directory path are redacted out of messages, breadcrumbs and stack data. Cookies and request headers are dropped. Same switch: Desktop settings → Privacy.
c. License activation
When you activate or release a license, the app sends the license key and the same hashed machine id to our license server, so that one key stays bound to one machine at a time. Verification of an already-activated license happens locally against a signed file — the app does not need to phone home to keep working, and it keeps working offline.
d. Purchases
If you buy a license we store your email address, the order number, the plan, the amount and the payment status. We use the email to identify your order for support, resends and refunds — not for marketing. Payment itself is processed by Stripe via our payment provider; card details are entered on their page and never reach us.
e. Website and downloads
tabledi.com is a static site with no analytics scripts, no advertising pixels and no third-party trackers. Fonts are loaded from Google Fonts, which sees the request. When you click a download button, our server records the platform, the version, the source region and the IP address so we can count downloads; it then redirects you to the file.
4. What we never do
- We don't sell, rent or share your personal data.
- We don't train anything on your data — we don't have your data.
- We don't run advertising or behavioral tracking, on the site or in the app.
- We don't require an account, so we hold no password of yours.
5. How long we keep things
- Ping records — kept in aggregate for product statistics; the hashed machine id has no other use.
- Crash reports — retained by Sentry under their default retention, then deleted.
- Orders and licenses — kept for as long as the license is valid plus the period required for accounting and tax records.
- Server logs — rotated regularly.
6. Your rights
If you're in the EU/EEA or the UK, the GDPR gives you the right to access, correct, export, or delete the personal data we hold about you, and to object to processing. Practically, the only personal data we're likely to hold is the email address attached to a purchase.
Email us and we'll act on it. We'll ask you to write from the address on the order, so we don't hand someone else's order details to the wrong person. Deleting the order record also removes our ability to resend or refund that key, so we'll say so before doing it.
Our lawful basis is contract performance for purchase data, and legitimate interest for the anonymous ping and crash reports — both of which you can switch off in the app.
7. Children
TableDI is a tool for professional work and is not directed at children under 16.
8. Changes
If we change what we collect, we change this page and update the date at the top. Since the collection lives in the application, a change also means a new release — so the version you have keeps behaving the way the policy did when you installed it.
9. Who we are, and how to reach us
TableDI is published by 上海鑫沃克斯信息科技有限公司, a company registered in Shanghai, China. (We give the name in its registered form rather than a translation, so it matches company records.)
Privacy questions and data requests: contact us.