Legal

Privacy Policy

Last updated: April 21, 2026

This policy describes how Lynfolio ("we", "us") processes information when you use our service. Lynfolio is a third-party tool for viewing Supabase accounts you connect. It is not affiliated with Supabase.

Information we collect

  • Account data: email and authentication identifiers from our auth provider when you register or sign in.
  • Connected Supabase accounts: org and project metadata, sync status, and metrics we fetch via the Management API (for example database size, table counts, storage usage) — not your application's business data.
  • OAuth tokens: refresh tokens you grant during connect; encrypted before storage. Access tokens are not stored long-term.
  • Usage and audit logs: timestamps and technical events (connect, token refresh, disconnect, IP address) for security and troubleshooting.
  • Email for alerts: if you enable notifications, we use your address to send operational emails (for example digest or alert messages via our email provider).

How we use information

To provide the dashboard, keep connections working (including token refresh), show cost estimates and health signals, send alerts you opt into, improve reliability, and comply with law. We do not sell your personal information.

Storage, encryption, and security

Data is hosted on infrastructure we control or subcontract (for example database and compute providers). Refresh tokens are encrypted at rest. We apply access controls and database row-level security so each user's connected accounts are isolated.

Subprocessors (high level)

Depending on configuration, we rely on vendors such as: hosting / edge platform, Supabase (authentication and data store for Lynfolio itself), and email delivery (for example Resend) for transactional messages. Your Supabase customer data remains under Supabase's terms; we only access what you authorize via OAuth.

Retention

We retain account and connection data while your account is active. You may request deletion of your account and associated tokens; some records may be kept briefly for security or legal obligations.

Your rights

Depending on your region, you may have rights to access, correct, or delete personal data, or to object to certain processing. Contact us using the address below to submit a request. We may verify your identity before fulfilling requests.

International users

If you use Lynfolio from outside the country where servers are located, your information may be transferred and processed across borders. We apply appropriate safeguards as required by applicable law.

Children

Lynfolio is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children.

Changes

We may update this policy and will post the revised version with an updated date. Continued use after changes constitutes acceptance where permitted by law.

Contact

Questions or privacy requests: hello@lynfolio.com. For product context, see About.

Not legal advice; have counsel review before production.