Privacy Policy
Effective: 2026-02-10 | Last Updated: 2026-02-10 | Version 2.0
1. Introduction
This Privacy Policy describes how DataAgent ("we," "us," or "our") collects, uses, and protects information when you use the DataAgent web application, Excel Add-in, and associated services (the "Service"). By using the Service you consent to the practices described herein.
2. Information We Collect
2.1 Account Information
Email address and authentication credentials (managed by Supabase Auth).
2.2 Research Data
Entity names, attribute names, descriptions, and research results you create or generate through the Service. Research queries are processed by our AI agents and may be sent to third-party subprocessors (see Section 7).
2.3 Usage & Technical Data
IP addresses, browser type, device information, and interaction patterns collected automatically for security monitoring and service improvement.
2.4 Payment Information
Payment processing is handled entirely by Stripe. We never store credit card numbers or sensitive payment details.
3. How We Use Your Information
- Provide, maintain, and improve the Service
- Process research queries and deliver results
- Authenticate users and enforce access controls
- Process payments and manage credit balances
- Monitor for security threats and abuse
- Comply with legal obligations
4. Data Retention
| Data Category | Retention Period |
|---|---|
| User accounts | Account lifetime + 30 days |
| Research projects & results | Account lifetime |
| Excel cache | 30 days (automatic expiry) |
| Agent traces / logs | 90 days |
| Credit transactions | 2 years |
| Application logs | 30 days |
5. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest (Supabase managed), Row-Level Security for tenant isolation, security headers on all responses, and SSRF protection on outbound requests.
6. Your Rights
- Access: Request information about your stored data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and data
- Portability: Export your research data via the Service
To exercise these rights, contact us at privacy@data-agent.ai.
7. Subprocessors
We use the following third-party services to deliver the Service:
| Subprocessor | Purpose | Data Processed |
|---|---|---|
| Supabase | Database, authentication | User accounts, research data |
| Render | Application hosting | Application code, logs |
| OpenRouter | AI model access | Research queries (no PII) |
| Stripe | Payment processing | Payment information (PCI-handled) |
| Serper.dev | Web search | Search queries (no PII) |
8. International Transfers
Your data may be processed in the United States and other jurisdictions where our subprocessors operate. We ensure appropriate safeguards for international transfers.
9. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated with at least 30 days notice via the Service. Continued use after changes take effect constitutes acceptance.
11. Contact
For privacy inquiries: privacy@data-agent.ai