Privacy Policy
This policy explains how Premsan Inc (“Premsan”, “we”, “us”) handles personal data in Susignal — this website, the console, the API, and the Susignal apps for iPhone, iPad and Android. Premsan is the controller of that data. It says what we hold, why, who else touches it, and how to make us stop.
1. What we collect
- Your account. Your name, your email address, and either a password — stored only as a hash — or, when you sign in with Apple or Google, your identifier there and the sign-in tokens they hand us. Each session records the IP address and the browser or device it was opened from, and when it expires. We also record the date on which you accepted the Terms, and which version.
- The Supabase projects you connect. When you connect a project, you sign in to Supabase and allow Susignal in; Supabase hands us a grant — an access token and a refresh token — which we keep encrypted, with the name, region and id of each project you chose. Supabase grants SQL access only with read and write together, so the grant could change your database; Susignal only ever reads it, inside a read-only transaction.
- What the assistant reads. To answer you and to keep your signals, the
assistant reads your project’s database through Supabase’s API: the names
of its tables and columns, their keys and statistics, and the rows its
queries return — sample rows as well as totals. What it reads is sent to
the model so it can answer. It never reads Supabase’s own schemas, such as
your
authusers. - What we keep for you. Your board — each signal’s name, its SQL, how it is drawn, how often it is read and the line it is watched against — and the results of its last 400 readings; the times a signal crossed its line; a log of the last 500 statements we ran on your project, with how long each took and how many rows came back; a summary of your project’s tables; and the messages you exchange with the assistant.
- Notifications. When you allow notifications on your phone, we keep the push token the operating system gives the app, the platform, and the language the app last used, so we can tell you when a signal moves.
- The plan. The day your free week began, and the state of your subscription. On the web, payment is taken by Stripe: it receives your email address and your account id, and your card details go to Stripe and never reach us. In the app, payment is taken by the App Store or Google Play; we receive the transaction’s id, confirm it with Apple or Google, and record it against your account.
- Usage. Counts of reads, token refreshes and assistant turns per month, kept inside your own account’s storage for our books. Server logs hold request metadata, your IP address among it, and error reports for a short time, for security and debugging.
- The bot check. Cloudflare Turnstile runs on our sign-in and sign-up pages, and in the app’s sign-in screen, to tell a person from a script.
- Nothing else. There is no advertising, no analytics, no tracking across sites or apps, no advertising identifier, and no data broker.
2. What we do with it
We use personal data to run Susignal: to read your connected projects, keep your board and watch your signals, answer your questions, tell you when a signal moves, sign you in, send you the emails the account needs — a verification link and a password reset — take payment and keep your subscription’s state, keep the service up and abuse out, answer you when you write to us, and meet legal obligations. We do not use your data or your conversations to train models, we do not sell personal data, and we do not share it for advertising.
3. Why we are allowed to
Where the GDPR or a law like it applies, we rely on these bases:
- Performing our contract with you — your account, your connected projects, your board, your conversations, and the subscription.
- Our legitimate interests — keeping Susignal up, finding failures, and stopping abuse and automated sign-ups, held to the usage counts, the logs and the bot check.
- A legal obligation — payment records and anything else the law requires us to keep.
- Your instructions — for the personal data of other people that your own database holds. When the assistant reads rows about your customers, it does so on your instruction and for you; you decide what your database holds and which project to connect.
4. Who else processes it
Susignal runs on Cloudflare: the servers, the storage that holds your account and your board, the model that reads your database and answers you, the email that leaves, and the bot check are all Cloudflare services on our own account. Nothing the assistant reads goes to any other AI provider. Email may instead be sent through Resend where we route it there.
Your database lives at Supabase, under your own agreement with them; Susignal reaches it only through Supabase’s Management API, with the grant you gave. Stripe takes payment on the web and keeps the card; Apple and Google take payment in the app, and each tells us when a subscription you bought there renews, is cancelled or is refunded. A notification to your phone is handed to Expo’s push service, which passes it to Apple or Google to deliver; it carries the push token and the sentence we show you. When the app opens it asks Expo’s update service whether newer code of ours is waiting; that request carries the operating system, our project id and a random token the app made for itself — no account and no device identifier — and Expo sees the IP address it came from. These providers process data only on our instruction, and we give notice here before a new one starts.
Signing in with Apple or Google sends us your identifier and email from that provider. Each acts on its own behalf there, not as our processor, and its handling of your account with it is governed by its own privacy policy; if you hide your email from us with Apple, mail reaches you through Apple’s relay. The App Store and Google Play are the sellers of what you buy inside the app, and their handling of your payment is governed by theirs.
5. Where it is
Your data is processed on Cloudflare’s network, which spans the world, and stored on it under Cloudflare’s own commitments for international transfers. Your database stays in the Supabase region you chose for it. Premsan is in Japan, a country the European Commission recognises as protecting personal data adequately.
6. On the phone
The app keeps on your device a sign-in token, the language and appearance you picked, and the random token its update check is known by. Connecting a project opens Supabase’s sign-in in the operating system’s own browser sheet. The app asks to send notifications once, when you connect a project, and you can turn them off in the operating system’s settings. It asks for no other permission, carries no advertising or analytics library, and purchases go through the store’s own sheet.
7. Cookies
On the web we set the cookies the product cannot work without: the one that keeps you signed in, and the ones Cloudflare Turnstile sets to tell a person from a bot on the sign-in and sign-up pages. The site and the console keep your theme and language in your browser’s own storage. That is the whole list: no advertising cookies, no cross-site trackers, and no analytics that follows you between sites. Clearing them signs you out.
8. How long we keep it, and deleting it
We keep your account and everything in it for as long as the account exists. Readings and the statement log keep only their latest entries, as section 1 says. Disconnecting a project deletes its board, its readings, its findings, its statement log and its conversation, and when no other connection of yours uses the grant, we revoke it at Supabase.
You can delete your account at any time, from the console’s Account page or from Account in the app. Everything we hold for you is erased at once — every connection and grant, board, reading, finding, statement log, conversation, push token, usage count and the subscription’s state — and then the account itself. There is no recovery window and no undo. Your database at Supabase is yours and is not touched.
Three things outlive that. A subscription bought in the app leaves a record of the store’s transaction id, the date, and the id of the account it was kept for, so that the store replaying the receipt cannot credit it to someone else and because payment records must be kept by law. Stripe, Apple and Google keep their own records of a payment under their own obligations. Server logs age out on their own after a short time.
9. Your rights
You can read your board, your readings and every statement we ran from the console, disconnect any project, and delete your account, without asking us. Depending on where you live, you may also have the right to a copy of the rest of what we hold about you, to restrict how we process it, to object to processing we base on legitimate interests, and to move your data elsewhere. Write to support@susignal.com and we will answer within one month.
If you live in California or another U.S. state with a law like its, you have the right to know what personal data we hold about you, to delete it, and to correct it; the controls above do that. We do not sell or share personal data as those laws define the words, so there is no opt-out to offer.
If you think we have handled your personal data wrongly, you can complain to a data protection authority — in the EEA or the United Kingdom, the one where you live or work or where the problem happened; in Japan, the Personal Information Protection Commission. We would rather you told us first, but you do not have to.
10. Security
Every connection is encrypted in transit. Passwords are stored as hashes, and your Supabase grant is stored encrypted and is decrypted only for the moment a read is made. Each account and each connected project lives in its own isolated storage object, and every byte of it is deleted with the account. The app keeps its sign-in token in the operating system’s secure store. Credentials never enter our logs. If you find a weakness, write to security@susignal.com and give us a chance to fix it before you tell anyone else.
11. Children
Susignal is not for anyone under 16, and we do not knowingly hold a child’s data. If you think a child has an account, tell us and we will delete it.
12. Changes
We may update this policy. When a change matters we will say so in the console or the app, or by email. The date at the top is the version that stands.
13. Contact
Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. support@susignal.com.