NymForm for Excel / Open source release coming soon Get release updates →

Documentationv0.1.0-alpha

How NymForm protects data

The privacy flow in plain English: what NymForm replaces, what it checks, what the model receives and what happens to its reply.

The short version

NymForm is designed to reduce what an AI model sees, and to show you what that is. It does not make a model private, and it can't protect data you don't mark private. What it does:

  1. Your spreadsheetYou pick the range and mark private columns.
  2. Protection layerStructure only, or sample rows with private values replaced.
  3. Checked requestEvery private cell and the full text are checked. A match or an error blocks it.
  4. AI modelReceives only checked requests (yours, and at most one automatic correction).
  5. Back in ExcelThe formula is checked, your values go back in, Excel calculates.

Two ways to give the model context

Structure only is the default. The request describes your range: the sheet and table name, the range address and its data rows, headers, each column's inferred type, and simple counts (blanks and distinct values, plus average words and longest length for text columns). No data cell is included.

Include sample rows adds rows from the top of your range: 50 by default, at most 200, for the selection and for each lookup range. A range with no more data rows than that is sent in full. Rows hidden by a filter or by hand count like any other row. Every value in a column you mark private is replaced before sending. Columns you don't mark private are sent as they are. Use sample rows only when the model needs to see what values look like.

How private values are replaced

In sample rows, each private column gets one of these treatments:

TreatmentWhat the model receivesExample
Stand-inA label for each distinct valuePERSON_014, EMAIL_003, ID_021
RangeA coarse range instead of a number80000-89999
MonthYear and month instead of a date2026-03
Leave outNo values: the column is dropped from the rows, though its header and counts are still described—

By default, private number columns get Range, date columns get Month, long free text is left out, and other private columns get stand-ins. You can change it per column under In sample rows on the Columns screen, once Include sample rows is chosen on the Ask screen. A range or month still reveals something, such as a salary band or a birth month.

A stand-in stays the same for the same value until you choose Refresh from selection, change the header-row setting, or add or remove a lookup range; then new stand-ins and an empty conversation start. So the model can still count, group and look things up. Private values that you type in your question are replaced too: "total for Maria Lopez" is sent as "total for PERSON_014".

The table of which stand-in belongs to which value (the stand-in map) lives only in the add-in's memory. It is never sent, saved, logged or exported, and it is gone when you close the pane.

The check before anything is sent

Before a request can be sent, NymForm checks the exact text that will leave Excel:

  • Every private cell in the sample rows must be a stand-in, a range, a month, or absent. Anything else blocks, however short it is.
  • The full text is scanned for your private values of 4 or more characters, including common rewritings: different case and accents, digits-only forms of values with 7 or more digits (such as phone numbers), JSON-escaped text, dates written other ways, and amounts with separators.

A match, an error or an unexpected failure blocks the request. The add-in's code only sends a request that passed this check, byte for byte. When a request is blocked, you see why and where, and you can mark another column private, rephrase, or switch to Structure only (in a follow-up after sample rows, choose Clear conversation first). The check has stated limits, listed in Alpha limitations.

What is sent and what isn't

SentNot sent
Headers (or the names you give them), the name of the sheet and table you selected, range addresses and row numbersValues in columns you mark private (replaced or left out)
Each column's type, whether it is marked private and its treatment, and simple countsAny data cell, in Structure only mode
Notes you add to columnsThe stand-in map
Your question, with private values replacedYour API key, except to the model endpoint to authorize the request
Earlier messages of the conversation, in stand-in formNames of sheets, tables and defined names you haven't selected or added as a lookup range
Lookup ranges you add, described the same way (and their rows in sample rows mode)Anything to a NymForm server: there is none
In sample rows mode: values in columns you did not mark privateYour workbook's file name

Headers (or, for a column you rename under Header sent, the name you give it), sheet and table names, notes and your question always reach the model, so avoid putting private details in them.

When the model responds

The model is asked to reply with a formula, a short answer about the sample rows, or a clarifying question. Its reply is treated as untrusted:

  1. NymForm checks the formula against a list of allowed worksheet functions and the ranges you chose. Whole-column references to those columns are allowed, so a formula can read rows above and below your selection in them. Functions that reach the web, files or other workbooks are refused.
  2. Your real values are put back into the formula's text, in the pane.
  3. The finished formula is checked again.
  4. You review it and choose Insert formula. Excel then calculates it in your workbook, on your real data.

If the reply can't be read, NymForm automatically sends one correction request (your request plus the model's reply and a fixed note asking for the right format). It is checked the same way and appears in the Log, but it isn't shown on What gets sent first. Conversation history kept for follow-up questions holds only stand-ins, never the restored values.

Where this stops

NymForm reduces exposure; it doesn't remove it. It can't protect columns you leave unmarked, what headers or small groups reveal, or what the model provider does while it processes a request. Read Alpha limitations and the Security & data flow page before using real data.

Describes NymForm for Excel v0.1.0-alpha · Last reviewed 2026-09-27. Found something inaccurate? Tell us.