data note · 4 Sep 2026
What happens to your files
You are about to drop a staffing file and a budget into a tool you had never heard of this morning, and the numbers in it may not even be yours. This is the page to forward to whoever asks you about that. It is written to be read in 3 minutes and it states the awkward parts too.
We never keep the spreadsheet
This is the part worth reading twice. When you drop a file, it is read into memory, parsed, and discarded. It is never written to a disk, never stored in a bucket, and there is no copy of your workbook anywhere in this product to leak, subpoena or forget about.
What survives the upload is a description of what we read. The list below is complete: if something is not on it, we do not have it.
The file name, verbatim
staffing_2026_v3_FINAL_(2).xlsx stays exactly as you named it, because the pack has to be able to tell you which file a number came from.
The tab names and the row count per tab
Staffing, Staffing (old), DO NOT EDIT, Sheet7, and how many rows each held. This is what lets the pack say which tabs it ignored.
A text extract of the rows we read
The cell values we used, as text. Not the workbook: no formulas, no macros, no formatting, no charts, no hidden sheets we did not read.
The finished pack
The figures, the portfolio table, the allocation, the findings and the unresolved list, so the link keeps working when you come back to it.
The work email you type to open the pack
Used to send you the pack link and, if you buy a pass, the receipt and the expiry reminders. Nothing else.
What we never hold at all
- —The spreadsheet file itself. It is read in memory and never written to disk, never put in a bucket, never attached to anything.
- —Passwords. There is no account to have a password for.
- —Anything from a file we could not read. A password-protected or unsupported file leaves no trace beyond its name.
- —Payment card numbers. Checkout happens on Stripe's own pages and we never see the card.
Where the extract sits
In a managed Postgres database, encrypted at rest by the provider and reached over TLS. The pack link is an unguessable token rather than a login, which is what lets you open your pack with no account and no password.
The honest consequence of that, stated rather than buried: the link is the credential. Anyone you send it to can read the pack — not your sources, but the figures, the allocation and the findings. Treat it like the PDF you would have emailed anyway, and delete the data when the cycle is closed if the numbers are sensitive enough to warrant it.
Which model reads it, and what it is allowed to do
The text extract is sent to Anthropic's Claude API through NanoCorp's model gateway, and the model returns the reconciliation and the findings. Anthropic's published API terms state that inputs and outputs submitted through the API are not used to train its models. We do not fine-tune anything on your data, and we do not build a shared model across firms: what makes the next pack sharper is the reconciliation you confirmed on your own firm, stored on your own firm.
Deleting it, in one click
At the bottom of your pack there is a link that says Delete our data. It names exactly what will go — this pack, the past packs of your firm, the sources counted across them, and the firm record — and then it deletes them immediately and tells you the counts. The pack link stops opening anything. It cannot be undone, which is the point.
For a written confirmation to put in front of a client or a compliance officer, write to ope@nanocorp.app and a person answers with what was deleted and when.
We do not expire data on a timer today. It stays until you delete it or ask us to, which is worth knowing rather than assuming.
What we do not have
No SOC 2 report and no ISO 27001 certificate. We are a small company and we are not going to pretend otherwise on the page where you are deciding whether to trust us. If your client contract requires either one, we are not yet the right supplier, and the sample pack is there so you can judge the output without sending us anything at all.
If the data has to stay in a particular jurisdiction, write to us before you upload and we will tell you where it actually sits rather than guess in your favour.
Judge the output before you send anything.
The example pack is a real run of the engine on an invented firm whose 3 files are as broken as yours: 2 dead tabs, a #REF! in the budget total, and one consultant spelled 2 ways.