Skip to content
Supaboard

Privacy Policy

Last updated

This Privacy Policy explains how Fyipen Private Limited ("Supaboard", "we", "us") handles personal data when you use supaboard.ai, the Supaboard application and the services around them (together, the "Service"). For the data you connect from your own sources and process through the Service ("Customer Data"), Supaboard acts as a processor on your behalf under our data processing agreement. This policy covers the account, website and usage data for which we are the controller.

Who we are

The controller for account and website data is Fyipen Private Limited, #210, 16th Main, Yellukunte, Indira Canteen Road, Bengaluru, Karnataka, India. Privacy contact: [email protected].

Data we collect

  • Account and identity data — name, email address, organisation, the identifiers we receive when you sign in with Google or Microsoft, and your role and seat assignment in each workspace.
  • Configuration data — data-source connection settings (encrypted at rest), workspace metadata, role-based access assignments, and automation and sync definitions.
  • Product content — dashboards, widgets, AI agents and their knowledge files, saved queries, query history, conversation history, generated exports, and the embeddings derived from agent knowledge.
  • Customer Data — the records returned by your read-only queries during a session, to the extent needed to display a result, build a widget or produce an export.
  • Billing data — plan, seat count, invoices, renewal dates and payment-event records. Card details are handled by our payment processor, XPay, and are not stored by Supaboard.
  • Usage and technical data — log data, API request metadata, device and browser information, IP address, and product-analytics events used for security, debugging, reliability and understanding how the Service is used.

How we use data

  • To provide, operate, secure and improve the Service.
  • To authenticate users and enforce access controls.
  • To run the queries, dashboards, agents, automations and exports you ask for.
  • To process subscriptions, seats and invoices.
  • To provide support and send service and transactional email, such as invitations, share links and billing notices.
  • To monitor, prevent and investigate security incidents, abuse and fraud.
  • To comply with legal obligations.

Legal bases

Where the GDPR or UK GDPR applies, we rely on performance of a contract (providing the Service), legitimate interests (security, service improvement, fraud prevention), consent where it is required (for example certain cookies or marketing), and legal obligation (for example tax and accounting records). For Customer Data, your instructions under the data processing agreement govern the processing.

Sharing and subprocessors

We share data with vetted subprocessors that help us run the Service. We may also disclose data to comply with law, to enforce our terms, or in a corporate transaction, with continued protection of personal data. We do not sell personal data. Our current subprocessors are:

  • Amazon Web Services — object storage for files and exports, regional hosting.
  • Google Cloud — cloud data services and OAuth.
  • MongoDB — the primary application database.
  • Chroma Cloud — vector storage for agent knowledge.
  • Anthropic, OpenAI, Google (Vertex AI and Gemini), OpenRouter and Voyage AI — language-model and embedding providers for search, agents and exports.
  • Fivetran — managed data syncs for non-database connectors such as Stripe, Google Analytics and Google Ads.
  • XPay — payment processing and subscription billing.
  • Resend and Loops — transactional and product email.
  • PostHog — product analytics on supaboard.ai and in the application.

The data processing agreement carries the full list with regions, and customers on it receive notice before a new subprocessor is added.

AI processing and model training

  • Natural-language questions, agents and export generation send the relevant prompt, schema and query context to the language-model providers listed above in order to produce a result.
  • Customer Data, prompts, schemas and query outputs are not used to train or fine-tune Supaboard's models, and are not shared with any provider for training theirs. We maintain zero-data-retention arrangements with model vendors where they are available.

Data retention

  • Account, configuration and product content are retained for the life of your subscription and deleted within 30 days after the account is closed, unless a longer period is required by law or for legitimate business records such as invoices.
  • Customer Data returned by a query is processed transiently to answer the request. Saved artefacts built from it — dashboards, exports, embeddings — follow the retention above.
  • Backups rotate on a 30-day cycle.

International transfers and data residency

Supaboard runs regional data planes in the United States, the European Union and Asia, and a workspace's data is stored in the region it selects. Where personal data crosses regions we rely on appropriate safeguards, including the EU Standard Contractual Clauses and the UK Addendum.

Security

We protect data with encryption in transit, encryption at rest for sensitive configuration such as connection credentials, signed authentication tokens, role-based access control, network controls and least-privilege access. Connections to your data sources are read-only: the query layer rejects any statement that would write to or alter your database.

Signing in

You can create an account and sign in with Google, with Microsoft, or with an email address and password. When you sign in with Google or Microsoft we receive the name, email address and profile picture associated with that account, and nothing else from it. We never see your Google or Microsoft password.

Your rights

Depending on where you live — under the GDPR, UK GDPR, CCPA/CPRA and similar laws — you may have the right to access, correct, delete, port or restrict your personal data, and to object to certain processing. For Customer Data, direct your request to the customer that controls it; we will assist them as its processor. To exercise rights over your account data, email [email protected]. You may also lodge a complaint with your supervisory authority.

California residents: we do not sell personal information, and we do not share it for cross-context behavioural advertising. You may exercise your access, deletion and correction rights as described above.

Cookies and tracking

The Service uses cookies and similar technologies that are strictly necessary for authentication and session management, and limited product-analytics tooling on the website and in the application. Analytics is not used for advertising. You can block non-essential cookies in your browser without losing access to the Service.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

Changes to this policy

We will post updates on this page and change the date at the top. For material changes we will also notify you by email or in the application before they take effect.

Contact us

Questions about this policy, or a request about your data: [email protected].