Alpha status
NymForm for Excel v0.1.0-alpha is the first test release. It is not publicly available yet; it is planned to be published with the source repository. Its privacy check is covered by automated tests, and the maintainer's recorded sessions are in Excel on the web; checks inside desktop Excel are still listed as to do. Answer quality has not yet been measured against a live model: the benchmark has so far run only against a scripted model. Treat it as software to evaluate, starting with synthetic data.
- It is installed by sideloading from its source folder, with a local server running. It is not in Microsoft's add-in store, and no tagged, hosted release build exists yet: the version you run is the one you build.
- The source repository is not public yet. It will be published under the GNU AGPL-3.0 (AGPL-3.0-only).
- Security problems will be reported through GitHub's private vulnerability reporting once the repository is public. There is no security email address yet.
Supported environments
- Built for Excel on the web, Excel for Windows and Excel for Mac, with the Excel JavaScript API 1.9 or later. So far it has been used only in Excel on the web; desktop Excel is untested.
- Excel only, in the desktop and web layouts. There is no version for Excel on phones or tablets, or for Word, PowerPoint or other apps.
- The pane is in English only.
- One model provider: OpenRouter, with your own API key. The endpoint is fixed when the add-in is built.
- Every request to OpenRouter asks for zero-data-retention routes only, whatever the model; the default model is
openai/gpt-6-luna. If no such route is available for the model, requests fail until one is. A build pointed at another endpoint sends no such request.
Size and performance
| Limit | Value |
|---|---|
| Cells in the selected range | at most 20,000 |
| Rows in a range | at least one data row (a header row is optional) |
| Sample rows sent | 50 by default, at most 200, per range (the selection and each lookup range) |
| Earlier messages kept for follow-ups | 6 (yours and the model's) |
| Formula length | 2,000 characters |
| Time to wait for the model | 60 seconds per request; errors are not retried, but an unreadable reply triggers one automatic correction request |
| Log entries kept in the pane | 200 |
Larger ranges and more sample rows make requests bigger and slower. Structure only keeps requests small.
What NymForm does not cover
- Columns you don't mark private. In sample rows mode their values are sent as they are. Suggestions are only defaults.
- What is always sent. Headers (or their aliases), sheet and table names, addresses and row numbers, each column's type and whether it is marked private, notes you write, simple counts (blanks, distinct values, and for text columns average words and longest length), the ranges a formula may use, the model ID, and your question with private values replaced. A follow-up also resends up to six earlier messages, including any sample rows they held.
- The header row. Row 1 of your range is read as headers unless it looks like data (numbers, dates, emails and similar); the This range has a header row checkbox on Columns changes this. A first row of ordinary text that is really data, such as a name, is still read as a header and sent as one. Check the headers on the Columns screen.
- Short values in free text. The text scan looks for private values of 4 or more characters. A shorter private value typed in your question is replaced only if you type it exactly.
- Other ways of writing a value. Abbreviations, misspellings, nicknames, split, reversed, translated or encoded forms are not caught, nor are names written with decorative Unicode letters or ligatures anywhere you type (question, notes, header aliases), private values in scripts such as Deseret or Osage written in the other case, or a word of a private value you keep as typed whose pieces are all under 4 characters, such as O'Bob.
- Small groups. Counts, ranges and months can still point to a person when a group is small.
- Prompt injection. Text in the sheet can still mislead the model's answer, although the formula gate still refuses unsafe formulas.
- Provider processing. Zero data retention limits storage, not processing. The request still reaches the provider.
- Your workbook and device. NymForm doesn't protect the workbook itself, your computer or Excel.
Behaviors to know
- Parts of private values. A word you type that is part of exactly one private name, email or ID is replaced with that value's stand-in automatically, even an ordinary word such as "park" when a customer is called Jordan Park; the pane says so (
Read "park" as Jordan Park.). Check it before you send. When several values match, the pane asks which you meant. If you keep the word as typed, the check blocks the request. - False blocks. The check blocks rather than guesses. A private value that also appears somewhere else, such as the same amount in an unmarked column, blocks the request. Mark that column private too, rephrase, or use Structure only (in a follow-up after sample rows, choose Clear conversation first).
- Hidden rows are included. Rows hidden by a filter or by hand are read, counted and, in sample rows mode, sent like any other row.
- Switching back to Structure only. After a sample-rows exchange, a Structure only follow-up is blocked, because the earlier messages still hold sample rows. Choose Clear conversation first.
- Restored values are text. A private value restored into a formula becomes text. A private numeric ID compared with numbers won't match, and a restored value containing
*,?or~acts as a wildcard in functions such as SUMIFS and COUNTIF. - Whole columns. A formula may use whole-column references for the columns you chose, so it can read every row of those columns, above and below your selection.
- Dates in 1904 workbooks are read from the stored value four years off. Months sent in sample rows for them are four years off, and when a cell doesn't display a full date, the check may not recognise that date typed in full, so it can be sent.
- Insert can't be undone by Excel's Undo, because Excel can't undo an add-in's writes. Insert asks before replacing cells that hold values.
- Excel errors after Insert. If an inserted formula shows an Excel error such as
#NAME?or#N/A, the pane still reports the insert as done. Check the cells. - Newer functions. The model may use recent functions such as GROUPBY, PIVOTBY or REGEXTEST. Older Excel versions don't have them, and the formula then shows an error.
- Too old an Excel. The add-in requires the Excel JavaScript API 1.9, so Excel without it normally doesn't load the add-in at all. If the pane does open there, it shows "Open Nymform from the Home tab in Excel." rather than saying Excel needs an update.
- Export log holds sent values. An exported log file contains the requests as sent, including the values of any unmarked columns sent in sample rows. Treat the file like the data it came from.
- Preview works without a key. You can build and check a request before adding your key; only Send needs it.
- Nothing persists. Your key, the stand-in map and the log are gone when you close the pane.
Check these yourself
- The range and headers on the Columns screen.
- That every sensitive column is marked Keep private.
- The request on What gets sent, including your question and headers, before choosing Send.
- The formula and its explanation before choosing Insert formula.
- The result on a few rows you can verify by hand.