jarrah

Privacy

What Jarrah does with your data.

Jarrah is a hosted API: you send it rows, it sends back a spreadsheet. This page says what happens to those rows, how long anything is kept, and who else touches it. The numbers come from the code that enforces them.

Who we are

Jarrah is operated by Clinton Boys, trading as Waratah Software, a sole trader established in England and Wales. We are the data controller for the account information described below, and a processor for the spreadsheet data you send us.

Questions about anything on this page, including requests about your own data, go to hello@waratahsoftware.com.

Your spreadsheet data

What happens to the rows you send depends on which endpoint you use, and the difference is worth knowing.

Synchronous renders

POST /v1/workbooks is handled entirely in memory. The request is parsed, the workbook is built, and the file comes back in the response. Nothing you send is written to disk or stored in our database. We record that the render happened — row count, cell count, output size and timestamps — and nothing of what was in it.

Asynchronous jobs

POST /v1/jobs works differently because a background worker has to read the data after the request has returned. The body is written to object storage, the worker reads it, and it is deleted once the job reaches a final state — succeeded or failed. Inputs have no retention period. They are scratch, kept only long enough to be rendered and to survive a retry.

The generated file is kept for your plan's retention period, below, and then deleted.

We do not read your data. It is not inspected, not used to train anything, and not shared with anyone beyond the infrastructure providers listed below, who store it on our behalf.

How long files are kept

Generated files are deleted once your plan's retention period has elapsed. This is enforced by a sweep that runs every ten minutes.

PlanGenerated files kept for
Free24 hours
Starter7 days
Growth30 days
Scale90 days

Retention follows the account's current plan. Upgrading makes new and existing files live longer; nothing is backfilled or brought back.

Test-mode renders are kept under exactly the same rules. They are excluded from usage counts and from billing, but not from deletion.

A download redirects to a pre-signed link that is valid for fifteen minutes. That link carries its own signature, which means anyone holding it can fetch the file until it expires, without an API key.

Treat a download link as a credential. Do not paste one into a support ticket, a bug report, or a log you keep. Request a fresh link instead of storing one.

Your account

We store, for as long as you have an account:

API keys are stored as a SHA-256 hash alongside the first few characters, so you can tell keys apart in a list. The key itself is shown once when you create it and is never stored. We cannot recover it for you, and a copy of our database does not yield a working key.

Sign-in links are handled the same way: a hash rather than the token, valid for fifteen minutes, and usable once.

Logs

Our logs record metadata only — job identifiers, account identifiers, byte counts, timings and error messages. Request bodies are never logged. Neither are API keys, which are redacted wherever they could otherwise be printed.

Cookies

This site sets no cookies. Analytics are collected with GoatCounter, which uses no cookies and no cross-site identifiers, so there is nothing to ask you to consent to and no banner.

The dashboard at app.jarrah.sh sets one cookie, jarrah_session, when you sign in. It holds your account identifier, email and plan in a signed value, lasts seven days, and is marked HttpOnly, Secure and SameSite=Lax. It is necessary to keep you signed in and is used for nothing else.

Who else processes it

ProviderWhat they doWhere
Hetzner Runs the API, the worker and the database Falkenstein, Germany
Cloudflare R2 object storage: generated files, and async inputs until the job finishes EU jurisdiction
Vercel Hosts this site and the dashboard Outside the UK and EEA
Stripe Takes payments and stores card details Outside the UK and EEA
Resend Sends sign-in emails, so it processes your email address Outside the UK and EEA
Migadu Receives mail sent to our contact address Europe
GoatCounter Analytics on this site — no cookies, no cross-site identifiers Europe

Your spreadsheet data stays in the EU. The application, the database and the file storage are all in the EU, and the data you send to the API does not leave them. Where a provider above sits outside the UK and EEA, that transfer relies on the standard contractual clauses and UK addendum in their own terms.

Business customers on the Scale plan can request a data processing agreement. Ask at the address above.

Payments

Payments are handled by Stripe. Card details go from your browser to Stripe and never reach us — there is no card handling anywhere in our code, and no card number, expiry or security code is ever sent to our servers. What we store is the Stripe customer identifier, so a subscription can be matched to an account.

Legal basis

Your rights

You can ask us for a copy of the personal data we hold about you, to correct it, to delete it, to take it elsewhere, or to object to how we use it. Email hello@waratahsoftware.com and we will respond within one month, which is the period UK data protection law allows.

Ask us to delete your account and we will remove it, your API keys, your sign-in tokens, and any generated files still inside their retention window. Billing records are kept where tax law requires it.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.

Changes

When this page changes, the date below changes with it. If a change materially affects what we do with your data, we will email account holders rather than relying on you to notice.

Last updated 12 August 2026. Jarrah is operated by Clinton Boys, trading as Waratah Software. See also the terms of service.