Legal
Privacy policy
Last updated August 7, 2026
This is the plain-language version, followed by the specifics. We read what you connect, we never use your product's data to train a shared model, you can revoke any connection with one click, and you can export or delete your data at any time.
What we collect
Account details you give us at signup (name, email, workspace name). Content you create in Supaprod: decisions, specs, opportunities, and their outcomes. Content from any source you explicitly connect (GitHub, Slack, Linear, and similar), scoped to the permissions you grant at connect time and shown to you before you grant them. Usage data (page views, feature interactions) so we can tell what is working.
What we never touch
Supaprod never merges code, ships a release, or takes an irreversible action without your explicit approval. The merge gate is always human-reviewed. We do not read sources you have not connected, and we do not expand a connection's scope without asking again.
No training on your data
Your decisions, specs, code, and outcomes are not used to train a shared or public AI model. When Supaprod calls an underlying model provider to do its work, your data is sent for that request only, under that provider's standard API terms, not their consumer product terms.
Where your data lives
In your workspace's own Postgres database (hosted on Supabase), isolated from other workspaces by row-level security. You can export your data in open formats at any time from Settings. The third parties that process data on Supaprod's behalf, and what each one receives, are listed publicly on the sub-processor disclosure.
Cookies and local storage
Supaprod sets no cookies, and loads no third-party script. No advertising network, no tag manager, no session recorder, no analytics SDK runs in your browser, so no third party can store anything there or learn that you visited. That is also why you see no consent banner: there is nothing here that consent law asks us to ask you about.
What we do store is kept in your browser and stays there. Your sign-in session (so you are not signed out on every page), the workspace and product you last had open, and the preferences you set yourself: theme, density, rail width, sound, and the notices you have already dismissed. Those persist until you clear them. A second, shorter-lived group is held only until you close the tab: where you got to in onboarding, a demo in progress, and the palette's recent items.
One item is measurement rather than function. The first time you land on the marketing site we generate a random 32-character value that lets us tell that one visit and one signup were the same person, instead of two unrelated numbers. It contains nothing about you, your device or your network, it is random and nothing else. It never leaves Supaprod, it is destroyed when you close the tab, and it is deleted the moment an account claims it.
Clearing your browser storage for this site removes all of it, and nothing breaks except that you sign in again. The full technical inventory, every key with the file that writes it, is kept alongside the code so this page can be checked rather than trusted.
Bring your own AI keys
If you prefer, you can run Supaprod against your own model provider key instead of ours. Nothing about your data handling changes either way. This is a routing choice, not a trust boundary.
Revoking access
Disconnect any connected source from Settings → Connected accounts at any time. Access ends immediately; nothing further is read from that source.
Who can see your data
Members of your workspace, per the role you grant them. We do not sell your data. Supaprod staff access production data only to operate the service (debugging, support you have requested) and that access is logged.
Contact
Questions about this policy or a request to export or delete your data: email privacy@supaprod.ai, or see the security page for how to report a concern.
Changes to this policy
Supaprod is in beta and this policy will get more detailed as we add capabilities (billing, more connectors). We will date every revision here; material changes get a notice inside the product, not a silent edit.