Spreadsheet rendering SDK · self-hosted CLI, Docker, and .NET no Office · no LibreOffice · BUSL-1.1
DRAFTformal privacy notice pending counsel review — the architecture below is decided

PLACEHOLDER — NOT THE FORMAL NOTICE. Swiss counsel is preparing the formal privacy notice under the Swiss nFADP and, where applicable, the GDPR. What this page states meanwhile is not aspiration: it is how the product and the site are actually built, and the built architecture is the strongest privacy statement we can make.

Privacy

Architecture summary as of 2026-08-23. The formal counsel-issued notice will replace this page at the same URL.

1. The software: no phone-home, by contract

The Rendlio engine, at every tier and in every mode, never opens a network connection. It sends no telemetry, no usage data, no crash reports; it reads no hardware identifiers, hostnames, or usernames; it has no activation, no licence server, and no remote kill-switch. Licence verification is pure computation over the licence file and keys embedded in the software. This is not a settings toggle — it is a contractual warranty in the EULA (Section 9), enforced in CI by analyzers that forbid network calls in engine code. The simplest privacy statement about your spreadsheets is the true one: we never see them.

2. The playground: one hour, then gone

The browser playground is the one place a file of yours touches our infrastructure. Its rules:

  • Uploaded workbooks and their converted outputs are processed for the conversion only and deleted within one hour of upload (automatic TTL).
  • Files are never read by humans, never used for training, testing, corpus-building, or any other purpose, and never shared with anyone — with exactly one exception: if you tick the optional, off-by-default corpus checkbox on the playground, you donate a copy of that file to Rendlio's private test corpus under the conditions stated next to the checkbox (deleted on request to privacy@rendlio.com).
  • No account is required and no upload is linked to an identity.

If a workbook is too sensitive even for that, the product answer is the product itself: run the engine on your own machines and nothing ever leaves them.

3. The website: exactly what runs, and under what consent

  • No accounts. rendlio.com has no login and stores no user profiles.
  • Analytics: Plausible — cookieless, aggregate-only analytics that set no cookies, store no personal data, and use no cross-site identifiers. Because it collects nothing personal, it needs no consent and is not gated on the banner. Alongside it, Cloudflare Web Analytics — equally cookieless — is enabled at the edge for traffic-level counts.
  • Advertising measurement: a Google Ads conversion tag runs under Google Consent Mode v2 with every consent category denied by default. It stores nothing on your device unless you grant consent in the CookieYes banner; declining — or simply ignoring the banner — keeps everything denied. There is no Google Analytics (GA4) on this site.
  • Consent management: the CookieYes banner owns that choice. Accept and decline carry equal weight, and the "Cookie settings" link in the footer reopens your preferences at any time.
  • Bot defence: Cloudflare Turnstile protects the playground and the licence forms. It is strictly necessary — it exists so the services stay usable — and runs without consent.
  • Nothing else. No other analytics, advertising, or tracking scripts run on this site — the only remaining third party is Paddle's checkout (section 4), which loads only when you start a purchase.
  • Forms: the trial and community licence forms collect what the licence file needs — your legal entity name and a delivery email address — and are used to issue and re-deliver your licence, nothing else.
  • Hosting: the site is served by Cloudflare Pages; Cloudflare processes connection data (such as IP addresses) as any CDN does, to serve and protect the site.

4. Purchases: Paddle is the merchant of record

Paid licences are sold by Paddle, which handles checkout, payment, invoicing, and taxes under its own terms and privacy policy. Rendlio Association never sees your payment details; we receive from Paddle what licence issuance requires — the purchased tier, the legal entity name, and the delivery email address.

5. What we hold about customers

Our records are the licence ledger: licence id, tier, the licensed legal entity's name, maintenance date, delivery email address — plus ordinary email correspondence with support and billing. For sole proprietors the entity name and email can be personal data; the counsel-issued notice will state retention periods and your rights (access, correction, deletion) under the nFADP and, where applicable, the GDPR.

6. Contact

Privacy questions and requests: hello@rendlio.com. Security reports: security@rendlio.com. Controller: Rendlio Association (Verein Rendlio), Aarau, Switzerland — see the association page.