Privacy Policy
Effective · September 4, 2026
1. Personal data we collect
(1) Account: email address, name, and the profile identifier from social sign-in (Google, Kakao, GitHub). (2) Usage: service logs and access records. (3) Payments: payments are processed by Paddle; we never store card numbers or other payment-instrument details. (4) Connected databases: we do not copy or store your database in full. To provide the service (analysis history, dashboards, KPI previews) we store parts of query results (sample rows, up to 200), AI answers, and schema structure (table and column names). Database credentials are stored under envelope encryption. (5) Code context: if you connect a GitHub repository, we store a business-context document (SUPALENS.md) generated from your code and schema, per data source. The repository itself is cloned only for the duration of an analysis job and discarded afterwards. (6) Monitoring and investigation records: KPI definitions and proposals, monitor (alert) settings, alert event history, and AI root-cause investigation results.
2. Purposes
Identifying and managing members; providing the service (natural-language analysis, business-context generation, KPI proposals, dashboards, scheduled monitoring and alerts, AI root-cause investigation, MCP integration); billing and settlement of paid plans; customer support; service improvement and abuse prevention.
3. What we access in connected services
(1) Databases: besides the questions you ask, we run read-only queries against your connected database to evaluate the monitors you have enabled — a scheduler runs every 5 minutes, and each monitor is evaluated at the check interval of your plan (every 2 hours on Free, every 10 or 5 minutes on paid plans) — and re-run saved queries when you open a dashboard. Every query is SELECT-only and runs inside a read-only transaction with a statement timeout and a row cap. Projects connected through Supabase OAuth are queried with a dedicated read-only role (supalens_ro). (2) GitHub: through the GitHub App installation we access only the metadata and contents of the repositories you selected, with read permission, using short-lived installation tokens — never your GitHub sign-in token. Repository code is never built, installed, or executed. (3) Slack and Discord: if you enable the integration, alert messages (metric name, current value, baseline, the AI investigation summary) and answers to mentions (question, answer, charts) are sent to that service.
4. Retention
When you close your account, access to the service is disabled and every stored credential is revoked at once, so it can no longer be used. Remaining operational records are erased automatically on the following retention schedules: analysis runs and AI answers 180 days, alert event history 180 days, credential access logs 180 days, audit logs 365 days, webhook receipts from external services (Paddle, GitHub, Slack) 90 days. Transaction and billing records that must be kept under applicable law (e.g. e-commerce regulations) are retained for the statutory period.
5. Disconnecting and deleting your account
You can disconnect at any time. Disconnecting a Supabase account revokes the OAuth token and revokes the read-only role credentials held in our vault, so they can no longer be used (the supalens_ro role created in your database can be dropped by you). Credentials for directly connected databases and Firestore are revoked and rendered unusable the moment the data source is deleted, and the cached connection is closed immediately. The GitHub App can be disconnected in the app or uninstalled on GitHub, after which repository access stops. Deleting your account revokes every credential your organization holds and disables access; the remaining records are erased on the retention schedules in section 4.
6. Processors and third parties
We entrust processing to the following processors: Supabase (database, authentication), Vercel (hosting), Trigger.dev (analysis and monitoring job infrastructure), Paddle (payments and tax), Anthropic (AI analysis), Resend (email), Sentry (error tracking), Channel Corp (Channel Talk, customer-support chat), Google Cloud (cloud infrastructure, social sign-in, usage analytics), Kakao (social sign-in), GitHub (social sign-in and repository access for code analysis). If you enable Slack or Discord, alerts and analysis results are sent to that service. Some processors are located outside Korea (e.g. the United States). We do not disclose personal data to third parties except as required by law or with your consent.
7. Your rights
You may request access, correction, deletion, or suspension of processing of your personal data at any time, and you may close your account. Send requests to admin@supalens.ai.
8. Destruction
Personal data is destroyed once its retention period under section 4 has expired or its purpose has been fulfilled. Electronic files past their retention period are deleted irrecoverably.
9. Security measures
Sensitive data such as database credentials is stored under envelope encryption (KEK/DEK), and protected in transit (TLS) with access controls and audit logging. The analysis AI runs in an isolated environment with connection details stripped; database credentials are never passed to the AI model.
10. Data protection officer
Data protection officer: Juchan Park (admin@supalens.ai). Inquiries, complaints, and remedies regarding personal data can be filed at this address.
11. Notice of changes
Additions, deletions, or amendments to this policy are announced in the service before they take effect.
Streamize Co., Ltd. · CEO JuChan Park · Business Reg. No. 677-87-02793 · admin@supalens.ai