The plain-language version: we collect what you grant, use it only to run your genome, never sell it, never train shared models on it, and delete it when you leave. The rest of this page is the detail.
01Who we are and what this covers
Supasprinkles makes gija, the platform that keeps your operations correct. This policy covers the data we handle when you visit this site, explore the demo workspace, or run gija on your own operation. It is written to be read, not skimmed past.
02What we collect
We collect three kinds of data, and nothing beyond them:
- Account data. Your name, email and workspace settings when you sign up or join the early-access list.
- Connected-tool data. The data your integrations expose, limited to the scopes you grant per tool. This is what your genome is built from.
- Usage and diagnostics. How the product is used and how it is performing, so we can keep it fast and find what is broken.
03How we use it
Connected-tool data is used for exactly one thing: building and maintaining your genome, so gija can detect drift and propose corrections in your workspace. Account and usage data keep the service running, secure and improving, and let us reach you about things that matter, like an approval waiting on you.
04What we never do
- We never sell or rent your data. To anyone, for anything.
- We never train models shared across customers on your operational data. Your genome is yours alone.
- We never read beyond the scopes you grant, and every read is logged in your audit trail.
- We never let an agent take an irreversible action without your sign-off, whatever data it can see.
05Integrations and scopes
Every integration is connected with explicit, per-tool scopes: you choose the data, workflows and events gija may observe, and whether the connection is read-only or action-enabled. Scopes are revocable in one click, and disconnecting a tool stops syncing immediately. The integrations page explains the model; Security & Trust covers the controls behind it.
06Retention and deletion
Your data is kept while your workspace is active. Disconnect an integration and its data stops flowing; delete your workspace and we purge your data from production systems within 30 days, with encrypted backups rolling off on their own schedule shortly after. Export is available any time before that, in open formats.
07How we protect it
Data is encrypted in transit and at rest. Access inside Supasprinkles follows least privilege, and every action an agent takes is recorded in a plain-language audit trail you can read. The full picture, including scopes, approval gates and reversibility, lives on the Security & Trust page.
08Your rights
You can access, export, correct or delete your data at any time. Most of this is self-serve in the product; for anything that is not, write to privacy@supasprinkles.com and a human will handle it. We respond within one business day.
09Changes to this policy
When this policy changes, the date at the top changes with it. If a change is material, we tell you directly, in the product and by email, before it takes effect.