Privacy Policy
Last updated:
Plain English: Hypertab stores provisioned workspace data in a logically separate tenant database, encrypts stored secrets, does not sell customer Table contents, and handles account closure through a verified support request with a documented retention process.
Operator disclosure status: The verified controller legal-entity name and physical notice address are not yet published. This remains an external legal-review gate, so this page must not be treated as evidence that legal launch review is complete. Public launch requires the operator to supply those facts and qualified counsel to approve the final policy. Send privacy requests to [email protected].
1. Data we collect
- Account data: email address, name, authentication identifiers, and timestamps. Supabase handles passwords and login sessions; Hypertab does not store your raw password.
- Workspace data: Projects, Tables, records, columns, smart column configurations, API keys, and webhooks. Stored in a provisioned tenant database and scoped by workspace and tenant controls; managed database infrastructure is shared at the provider level.
- Operational logs: HTTP request metadata, MCP tool invocations, smart column run results, IP address, and user agent. Incoming webhook-route logs store operational metadata only; request/response payloads and value-bearing previews are not retained. Logs are used to debug issues, enforce rate limits, and detect abuse.
- Billing data: no paid public plan or checkout is currently available, so Hypertab does not collect payment-card data through the service. A Pro waitlist message is treated as ordinary contact data, not an order.
- Telemetry: the marketing site may use Cloudflare Web Analytics for aggregate page and referral measurement. Cookie-based analytics, advertising pixels, and session-recording tools are disabled unless a future consent flow explicitly enables them.
2. How we use your data
- To provide the service: store your tables, run your smart columns, deliver webhooks, authenticate your API requests.
- To operate the Free plan: calculate ops usage and enforce its published limits.
- To improve the product: analyze aggregated usage patterns, reliability signals, and support feedback. We do not use customer Table contents to train AI models.
- To respond to you: when you contact support at [email protected] we read your message and any data you reference.
- To meet legal obligations: respond to lawful requests from authorities with valid legal basis.
3. Sub-processors
- Cloudflare: hosting for the API, marketing site, and edge services (Workers, Durable Objects, Queues, and R2). Edge processing can occur in multiple locations; this policy does not promise a single processing country.
- Turso: managed libSQL database hosting. Processing region depends on the provisioned database; ask before signup if a specific region is required.
- Supabase: authentication and user management. Processing location and transfer terms follow the configured project and Supabase agreement.
- GitHub: source hosting and, when the production backup job is enabled, encrypted backup workflow artifacts with configured retention. Artifact processing follows GitHub settings and terms.
- Sentry: error monitoring and crash reporting only when the production integration is configured. Processing location follows the configured Sentry project and agreement.
- External API providers: only when you configure an HTTP or integration column with your own endpoint and credential. The selected provider receives configured request data under its own terms and processing locations.
4. Data isolation
- Provisioned tenant data is stored in a separate logical Turso database and scoped by tenant controls. Turso remains shared managed infrastructure at the provider level. Public-beta workspaces are single-user.
- Workspace API key values are stored as one-way hashes. Recoverable API account credentials, webhook auth headers, and environment secrets are encrypted at rest using AES-256-GCM before being written to the database.
- Operator access is limited to provisioning, security, recovery, legal obligations, and support work authorized by the customer. Application-level administrative actions are recorded where the product has an audit event; provider-console access may have separate provider logs.
5. Data retention
- Active workspaces: retained while the account and workspace remain active, subject to verified closure requests and applicable legal obligations.
- Soft-deleted Tables: restorable for 30 days. After that window Hypertab no longer offers restoration and the data is eligible for permanent removal during retention maintenance.
- Operational logs: audit and column-run logs are normally retained for up to 90 days; outgoing webhook, incoming webhook-route, and error-cell logs are normally retained for up to 30 days. Endpoint maintenance also scrubs any payload columns left by older versions. Unresolved recovery records may remain longer until the incident is resolved.
- Closed accounts: request closure by verified email. Active workspace data is scheduled for removal after identity and scope are confirmed. Encrypted backups age out under their configured retention window; the current target is 35 days.
- Billing and transaction records: retained for the period required by applicable tax, accounting, fraud-prevention, and legal obligations.
6. Your rights
- Access: request a copy of all data we hold about you. Email [email protected].
- Correction: update supported account fields in the app, or email us for help.
- Deletion: self-service account deletion is not currently available. Email us from your account address; we verify the requester and confirm the deletion scope and schedule.
- Portability: export a Table to CSV in the app or with the hypertab_export_csv MCP tool.
- Privacy rights: applicable law may provide rights to access, correct, delete, restrict, or receive your data. Email us with a request; we respond within the legally required period after verification.
8. Security
- Supported browser and API traffic is encrypted in transit with HTTPS/TLS.
- Recoverable API account credentials, webhook auth headers, and environment secrets are encrypted at rest using AES-256-GCM.
- Authentication uses Supabase sessions and signed tokens; workspace API key values are one-way hashed and scoped by the Hypertab service.
- Suspected security issues: email [email protected]. Current reporting instructions are published at /.well-known/security.txt.
9. Children
- Hypertab is not intended for children under 13. We do not knowingly collect data from children. If you believe we have, email us and we will delete it.
10. Changes to this policy
- We post policy changes here and update the date above. When legally required, or when a change materially reduces existing privacy commitments, we provide additional notice before the change takes effect.
11. Contact
- Questions or requests: [email protected].
- Service and trading name: Hypertab.
- Hypertab currently acts as the service operator for account and service-administration data, while workspace owners remain responsible for personal data they place in Tables. The verified controller legal-entity name and physical notice address are not yet published; completing those disclosures requires verified business facts and external legal review.
Questions? Email [email protected].