Trains on customer data
unclear
Not stated in the documents we could read. An absence here is an unknown, not a no.
Opt-out mechanism
* Nevada: Chapter 603A of the Nevada Revised Statutes permits a Nevada resident to opt out of future sales of certain covered information that a website operator has collected or will collect about the resident.
“* Nevada: Chapter 603A of the Nevada Revised Statutes permits a Nevada resident to opt out of future sales of certain covered information that a website operator has collected or will collect about the resident.”
AI features
present
“This includes any inputs you provide to our AI-powered support tools and outputs generated in response to your inputs.”
Model providers named
none named
Not stated in the documents we could read. An absence here is an unknown, not a no.
Retention
60 days
“(f) Contact information – if you have an account with us, we retain this for as long as you have an account on our services, and for 60 days after you close your account.”
Hosting regions
not stated
Not stated in the documents we could read. An absence here is an unknown, not a no.
Subprocessor notice
5 days
“Customer shall notify Supabase if it objects to the proposed change to the Authorized Sub-processors (including, where applicable, when exercising its right to object under clause 9(a) of the SCCs) by providing Supabase with written notice of the objection within five (5) days after Supabase has provided notice to Customer of such proposed change (an “Objection”).”
Downstream
Who's behind Supabase, as listed in its own subprocessor documents. 0 listed.
Model providers
- none listed
Hyperscalers
- none listed
Other subprocessors
- none listed
Reviewer notes
Extracted by deterministic rules (rules/v1), no language model. Coverage is limited to recognisable clauses and a gazetteer of common subprocessors; absent values mean 'not matched', not 'not present'. no training clause matched
Documents read
- privacy policy https://supabase.com/privacyHTTP 200 · 2026-09-06
- dpa https://supabase.com/legal/dpaHTTP 200 · 2026-09-06
Document changes
- high 2026-09-06 · dpa +2 / −2 lines
show diff
+ Customer grants Supabase general authorization (or, where applicable, has Customer's Controller's general authorization) to engage any of the Sub-processors provided in Supabase’s Sub-processor list, available at https://supabase. (“Subprocessor List”), as amended from time to time in accordance with clause 6.3 (the “Authorized Sub-processors”), to Process Covered Data. Supabase shall: (a) enter into a written agreement with each Authorized Sub-processor imposing data protection obligations that, in substance, are no less protective of Covered Data than Supabase's obligations under this DPA; and (b) remain liable for each Authorized Sub-processor's compliance with the obligations under this DPA.+ Supabase offers a mechanism for Customer to subscribe to notifications of changes to the Subprocessor List via https://supabase.. If Customer subscribes to receive such updates, Supabase will provide Customer with at least thirty (30) days' notice of any proposed changes to the Authorized Sub-processors. Customer shall notify Supabase if it objects to the proposed change to the Authorized Sub-processors (including, where applicable, when exercising its right to object under clause 9(a) of the SCCs) by providing Supabase with written notice of the objection within five (5) days after Supabase has provided notice to Customer of such proposed change (an “Objection”). In the event Customer submits an Objection to Supabase, Supabase and Customer shall work together in good faith to find a mutually acceptable resolution to address such Objection. If Supabase and Customer are unable to reach a mutually acceptable resolution within a reasonable timeframe, which shall not exceed thirty (30) days, Customer may terminate the portion of the Agreement relating to the Services affected by such change by providing written notice to Supabase.− Customer grants Supabase general authorization (or, where applicable, has Customer's Controller's general authorization) to engage any of the Sub-processors provided in Supabase’s Sub-processor list, available at https://supabase.com/legal/customer-resources/subprocessor-list (“Subprocessor List”), as amended from time to time in accordance with clause 6.3 (the “Authorized Sub-processors”), to Process Covered Data. Supabase shall: (a) enter into a written agreement with each Authorized Sub-processor imposing data protection obligations that, in substance, are no less protective of Covered Data than Supabase's obligations under this DPA; and (b) remain liable for each Authorized Sub-processor's compliance with the obligations under this DPA.− Supabase offers a mechanism for Customer to subscribe to notifications of changes to the Subprocessor List via https://supabase.com/legal/customer-resources/subprocessor-list. If Customer subscribes to receive such updates, Supabase will provide Customer with at least thirty (30) days' notice of any proposed changes to the Authorized Sub-processors. Customer shall notify Supabase if it objects to the proposed change to the Authorized Sub-processors (including, where applicable, when exercising its right to object under clause 9(a) of the SCCs) by providing Supabase with written notice of the objection within five (5) days after Supabase has provided notice to Customer of such proposed change (an “Objection”). In the event Customer submits an Objection to Supabase, Supabase and Customer shall work together in good faith to find a mutually acceptable resolution to address such Objection. If Supabase and Customer are unable to reach a mutually acceptable resolution within a reasonable timeframe, which shall not exceed thirty (30) days, Customer may terminate the portion of the Agreement relating to the Services affected by such change by providing written notice to Supabase. - high 2026-09-06 · privacy policy +1 / −1 lines
show diff
+ You also have the right to lodge a complaint to your local data protection authority. If you are based in the European Union, information about how to contact your local data protection authority is available here. If you are based in the UK or Switzerland, your local data protection authorities are the UK Information Commissioner's Office (https://ico.org.uk/global/contact-us/) and the Swiss Federal Data Protection and Information Commissioner (https://www.edoeb.admin..html).− You also have the right to lodge a complaint to your local data protection authority. If you are based in the European Union, information about how to contact your local data protection authority is available here. If you are based in the UK or Switzerland, your local data protection authorities are the UK Information Commissioner's Office (https://ico.org.uk/global/contact-us/) and the Swiss Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact/address.html).
Fact changes
No changes recorded yet. Changes appear here when a later reading differs from an earlier one.
Corrections
No correction requests. Anyone may dispute a fact with a source; requests and resolutions are public and ledger-entered.
Facts are as stated in Supabase's public documents on the date read. This is a record, not legal advice. Work for Supabase? Claim this profile · Something wrong? Request a correction.