ROBUR PACIS
Family Office AI

Privacy policy

Last updated: 18 September 2026

AI-assisted Raw intake is under development and is not yet enabled. The sections describing OpenAI processing explain the intended feature; they do not mean that transaction data is currently being sent.

Purpose and operator

Family Office AI is a personal Google Sheets tool operated by the workbook owner for the owner and invited users. It prepares transactions for review and appends approved entries to the workbook’s Transactions sheet. This website describes the tool and does not display the private workbook.

Information processed

The existing staging workflow reads and updates transaction fields in the current workbook: account, date, currency, amount, description, project, and category. It also uses workbook reference labels, formatting, and import-control metadata to support validation and avoid unintended repeat imports.

The planned Raw intake will process the transaction text that an authorized user pastes into the Raw sheet, together with the account, project, and category labels needed to interpret it. Pasted descriptions may contain personal or financial information. Users should include only information needed for this task.

How information is used

Workbook data is used to prepare, validate, reconcile, review, and record transactions. The planned AI feature will extract transaction fields and propose classifications for human review. Its results must be reviewed before posting to the ledger.

Google access

The app requests access to the current spreadsheet to read input and reference values and write the workflow’s results. The planned external-request permission allows the script to contact the OpenAI API. Access to the workbook remains governed by its Google sharing settings.

Service providers and AI processing

Google provides Sheets, Apps Script, and the associated cloud services. When enabled and initiated by a user, the planned AI feature will transmit Raw transaction text and relevant account, project, and category labels to OpenAI for extraction and classification. That processing will be subject to the API account’s applicable terms, settings, and retention rules. The app does not require sending the whole transaction ledger for this feature.

Information supplied through Google permissions will be used only to provide the user-facing workflow described here. It will not be sold or used for advertising. Family Office AI’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Storage and deletion

Raw inputs, staging entries, and ledger records are stored in the owner’s Google spreadsheet until an authorized user removes them. Google may retain version history, backups, and service logs under its own settings and policies. The script uses import-control metadata to support safe posting. API credentials, if configured, are stored separately from spreadsheet cells in the script user’s properties.

The planned OpenAI requests will be subject to OpenAI’s applicable API retention policies; this app does not promise zero retention by service providers. To remove workbook data, contact the workbook owner. Access to the app can also be revoked through your Google Account’s third-party connections settings.

Access and security

Only trusted people should receive workbook and bound-script edit access. An editor may be able to change the script, so workbook sharing is part of the security boundary. Do not paste passwords or API keys into Raw or Staging. No system can guarantee absolute security.

This website

This informational site contains no transaction-entry form, application analytics code, or advertising trackers. Its hosting providers may process ordinary web-request information to deliver and secure the pages.

Questions and requests

Invited users can contact the workbook owner directly or use the support email shown on the app’s Google consent screen for questions about access, correction, or deletion.

Changes

This policy will be updated when the workflow or its data handling changes. The date above identifies the latest revision.