Privacy Policy

Last updated: 2026-07-25

1. Information we collect

Account data (name, email, organization), authentication metadata, files and datasets you upload for analysis, API usage logs, billing information processed by Stripe, and telemetry required to operate the service.

2. How we use it

To provide analyses, deliver reports, manage subscriptions, secure the platform, comply with legal obligations, and improve DataOracle. We do not sell personal data.

3. Storage & security

Data is stored in encrypted managed cloud infrastructure with row-level security. Connector credentials are encrypted at rest with AES-256-GCM. Access is scoped by organization role.

4. Third parties

We use Stripe (payments), Supabase (database/auth), Google (optional connectors), and AI model providers to process prompts. Data shared is limited to what is necessary for each function.

5. Your rights

You may export your data, request deletion, or revoke connector access at any time from Organization Settings. Contact privacy@dataoracle.app for GDPR/CCPA requests.

6. Retention

Analyses and uploads are retained while your subscription is active. On account deletion, data is purged within 30 days except where retention is legally required.

7. Contact

privacy@dataoracle.app