Privacy Policy

Effective · July 3, 2026

1. Personal Information We Collect

(1) Account: email address, name, and social-login (Google, GitHub) profile identifier. (2) Usage data: service usage logs and access records. (3) Payment: payments are processed through Paddle, and the Company does not itself store payment-method information such as card numbers. (4) Connected databases: the Company does not replicate or store your database in full, and queries it on a read-only basis only when you request an analysis. However, to provide the service (analysis-result records, dashboards, and KPI previews), a portion of query results (sample rows, up to 200), AI analysis answers, and schema-structure information (such as table and column names) may be stored in the Company's database. The connection credentials used to query your database are stored protected by envelope encryption.

2. Purpose of Collection and Use

Member identification and management; provision of the service (queries, analysis, dashboards, alerts); payment and settlement for paid services; responding to customer inquiries; and improving the service and preventing abuse.

3. Retention and Use Period

As a rule, personal information is destroyed without delay upon account withdrawal. However, transaction and payment records that must be retained under applicable laws (such as the Act on Consumer Protection in Electronic Commerce) are kept for the period prescribed by those laws.

4. Outsourcing and Provision to Third Parties

To provide the service, the Company entrusts the processing of personal information to the following processors: Supabase (database and authentication), Vercel (hosting), Trigger.dev (infrastructure that executes analysis jobs), Paddle (payment and tax processing), Anthropic (AI analysis processing), Resend (email delivery), Sentry (error tracking), Google Cloud (cloud infrastructure, social login, and usage analytics), and GitHub (social login and repository access for code analysis). In addition, if you enable a Slack or Discord integration, notifications and analysis results are sent to that service. Some of these processors are located outside your country (for example, in the United States). Except where based on law or where the user has consented, the Company does not provide personal information to third parties.

5. Users' Rights

Users may at any time request access to, correction of, deletion of, or suspension of the processing of their personal information, and may withdraw membership by deleting their account. Requests are received at admin@supalens.ai.

6. Destruction of Personal Information

Personal information whose retention period has elapsed or whose purpose of processing has been achieved is destroyed without delay. Electronic files are deleted using a method that makes recovery impossible.

7. Security Measures

Sensitive information such as database credentials is stored using envelope encryption (KEK/DEK), and personal information is protected through encryption in transit (TLS), access-privilege controls, audit logs, and similar measures.

8. Data Protection Officer

Data Protection Officer: JuChan Park (admin@supalens.ai). Inquiries, complaints, and requests for redress relating to personal information may be submitted to this contact.

9. Duty of Notification

If content is added to, deleted from, or amended in this Policy, notice will be given through an in-service announcement before the change takes effect.

Streamize Co., Ltd. · CEO JuChan Park · Business Reg. No. 677-87-02793 · admin@supalens.ai