Last updated June 10, 2026
This Privacy Policy explains how LATO Tec Inc. (“LATO,” “we,” “us,” or “our”) handles your data when you use LATO in Excel.
Contact: legal@latolabs.io | LATO Tec Inc., 251 Little Falls Drive, Wilmington, DE 19808, United States
| Purpose | Details | Legal basis (GDPR) |
|---|---|---|
| AI processing | Process your prompts and conversation context through our AI provider to generate responses and complete tasks | Contract performance |
| Conversation continuity | Store conversation history so you can continue previous sessions | Contract performance |
| Account management | Maintain your account and authenticate your sessions | Contract performance |
| Analytics | Measure website and add-in usage to improve the product | Legitimate interest (product improvement) |
| Debugging and reliability | Use error logs and performance data to fix issues and improve stability | Legitimate interest (service reliability) |
| Legal compliance | Meet regulatory requirements and respond to legal requests | Legal obligation |
Providing your account information is necessary to use the service. If you do not provide it, we cannot create your account or deliver the service.
| Data | Storage | Retention |
|---|---|---|
| Account information | Supabase | While your account is active |
| Conversation history (messages, attachments, and AI-generated files) | Supabase | While your account is active, or until you delete a conversation |
We share your data with the following service providers, solely to operate the LATO service:
| Provider | Purpose | Data shared | Retention by provider |
|---|---|---|---|
| Anthropic (Claude API) | AI processing | Conversation content | Retained up to 30 days for safety and abuse prevention, then automatically deleted. Not used for model training. |
| Supabase | Database, authentication, file storage | Account data, conversation history | Customer-controlled (we control deletion) |
| Railway | Backend hosting | API requests, session data | Infrastructure provider. Data passes through but is not independently stored by Railway. |
| E2B | Sandboxed code execution | Code and data passed to Python execution | Ephemeral. Sandbox destroyed after use (max 24 hours). |
| Daytona | Sandboxed agent workspaces | Files and data your agent processes during a task | Workspace auto-stops after idle; filesystem archived after inactivity and deleted with your agent. |
| Exa | Web search for agents | Search queries issued by your agent | Per Exa’s retention policy. No account or conversation data shared. |
| Vercel | Website and add-in hosting, analytics | Page views, feature usage | Per Vercel’s retention policy |
| Logfire | Application monitoring | Error logs, performance traces | Per Logfire’s retention policy |
| Google Workspace | Outbound email from your agent (agent@latolabs.io) | Email content sent to you and your invitees | Per mailbox retention |
All providers are bound by data processing agreements.
LATO is not intended for anyone under 16. We do not knowingly collect data from minors. If you believe we have, contact us at legal@latolabs.io.
We may update this policy to reflect changes in our practices or legal requirements. We will notify you by updating the “Last updated” date at the top of this page.