Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how DataParade, Inc. ("DataParade", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use our website at dataparade.io, our web application, our command-line interface (CLI), and related services (together, the "Service").
We act as a data controller for the personal data we collect about our account holders, website visitors, and prospects. Where we process data contained in code, repositories, or diagrams that you submit through the Service, we act as a data processor / service provider on your behalf, and you (or your organization) are the controller of that data.
1. Who we are and how to contact us
- Controller: DataParade, Inc., registered address 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, USA
- Privacy / data protection contact: privacy@dataparade.io
- General contact: support@dataparade.io
- EU/EEA & UK representative (if applicable under GDPR Art. 27): Not applicable
- Data Protection Officer: We have not appointed a DPO; direct privacy enquiries to privacy@dataparade.io.
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland and have questions about this policy, please contact our privacy contact above.
2. Personal data we collect
We collect the following categories of personal data. We have indicated the source and, for clarity, mapped each to the CCPA statutory categories.
2.1 Account and authentication data
We use Auth0 for authentication (passwordless email sign-in and OAuth). When you create an account or sign in, we collect and store:
- Email address
- Display name (if provided by you or your identity provider)
- Email verification status
- A unique authentication identifier from Auth0
- Account and workspace timestamps (created/updated, last active workspace)
We do not store passwords. Authentication credentials are handled by Auth0.
CCPA category: identifiers.
2.2 Workspace and collaboration data
When you use workspaces, we collect:
- Workspace names and membership (your role and the workspaces you belong to)
- Invitations you send or receive (invitee email address, role, who invited/accepted, expiry and status; invitation tokens are stored only as a salted hash)
- Comments and threads you create on diagrams, including comment content, mentions, and author/timestamp metadata
- Workspace API keys (we store only a non-sensitive key prefix and a hash of the key, plus creation/last-used/revocation metadata)
- Audit logs of workspace activity (e.g., API key creation/revocation, scan started/completed/failed, quota changes, CLI import events). Audit metadata is sanitized to exclude secrets, keys, tokens, and passwords.
CCPA categories: identifiers; commercial information; internet/network activity; professional information.
2.3 Scanning, code, and repository data
The Service analyzes code you submit in order to produce dataflow and risk diagrams. Depending on how you scan, we process:
- Uploaded ZIP archives of your code, stored in our cloud storage (AWS S3) for processing.
- Git repository content accessed via GitHub or GitLab. If you connect a git provider, we store the resulting OAuth access tokens in encrypted form. We request the minimum scopes needed to read repositories (for example, GitLab
read_api read_repository). For GitHub, you may instead use a GitHub App installation. - Scan job metadata: project name, source type (local ZIP, git repository, or local CLI), repository URL/ref/provider, status, storage references, AI token usage, and the submitting user.
- Scan results, including inferred properties on diagram nodes.
Code you submit may incidentally contain personal data. We process it only to perform the scan and generate diagrams for you. You are responsible for ensuring you have the right to submit any code or data you provide, and for not submitting personal data you are not permitted to process.
CCPA categories: identifiers; commercial information; potentially other categories present in your code.
2.4 AI/LLM processing
To infer security and privacy properties on diagram nodes, portions of scan data are processed by a third-party large language model provider (Anthropic). Only the data required for inference is sent. See Subprocessors.
2.5 Email and notification data
- Email delivery for sign-in links, workspace invitations, and comment/mention notifications.
- Your notification preferences (immediate, daily digest, or none) and digest schedule.
CCPA category: identifiers; commercial information.
2.6 Demo request / waitlist data
If you submit a demo request or waitlist form, we collect: first and last name, email, role, company size, regulatory frameworks of interest (e.g., GDPR, CCPA, HIPAA, SOX), and any notes you include.
CCPA categories: identifiers; professional information; commercial information.
2.7 Technical, diagnostic, and error data
- We use Sentry for error and crash reporting. In production, error reports may include personally identifying information such as your user ID and email to help us diagnose issues tied to an account.
- Standard server and request metadata (e.g., IP address, timestamps, user agent) generated when you use the Service.
- Limited browser storage: a theme preference and transient diagram save-error state stored locally in your browser.
- Analytics (Google Analytics 4). On our public website we use Google Analytics 4, a web-analytics service provided by Google LLC, to understand how the site is used so we can improve it. This includes page views, feature interactions, approximate location derived from IP address, device/browser type, and a pseudonymous analytics identifier stored in cookies (e.g.,
_ga). Google Analytics is a third-party tool that acts as our processor for this purpose, and we use it in a first-party capacity — the data is used solely to measure and improve our own site and is never sold, shared, or used for advertising. We deploy it with Google Consent Mode v2: until you consent through our cookie banner, analytics runs in a consent-denied state that sets no analytics cookies. We disable Google's advertising features —ad_storage,ad_personalization, andad_user_dataare denied and IP data is redacted — so we do not use retargeting, cross-context behavioral advertising, Google Signals, or ad networks. See Cookies to manage your choices. - Product analytics and session replay (web application). Within the signed-in web application we use PostHog (hosted in the EU) as a first-party product-analytics tool to understand how features — especially the diagram canvas — are used, so we can improve them. This includes interaction events (for example, opening a diagram, connecting nodes, or selecting and deleting elements), your account identifier, and device/browser type. We also use PostHog session replay, which reconstructs how you interacted with the interface (clicks, navigation, and on-screen layout). Session replay is configured with aggressive masking: all text and input content is masked before a recording is created, so we do not capture the content of your diagrams, the code or data you submit, panel or label text, or anything you type. We use this data only in a first-party capacity to operate and improve the Service; it is never sold, shared, or used for advertising, and we honor your browser's Do Not Track signal as an opt-out.
CCPA category: internet/network activity; identifiers.
We do not intentionally collect special categories of data (e.g., health, biometric, racial/ethnic data) or the data of children. See Children.
3. How we use personal data (purposes and GDPR legal bases)
| Purpose | Personal data used | GDPR legal basis |
|---|---|---|
| Create and manage your account; authenticate you | Account/auth data | Contract (Art. 6(1)(b)) |
| Provide workspaces, collaboration, comments, invitations | Workspace/collaboration data | Contract (Art. 6(1)(b)) |
| Perform scans and generate diagrams | Code/repository/scan data | Contract (Art. 6(1)(b)); for code, on your behalf as processor |
| Send transactional emails (sign-in, invitations, notifications) | Email/notification data | Contract (Art. 6(1)(b)) |
| Send digest emails per your preferences | Notification preferences | Contract; Consent where required |
| Maintain audit logs, API keys, and quotas; secure the Service | Workspace/audit/technical data | Legitimate interests (Art. 6(1)(f)) — security and integrity |
| Diagnose errors and improve reliability | Error/diagnostic data | Legitimate interests (Art. 6(1)(f)) |
| Respond to demo/waitlist requests and contact you | Demo/waitlist data | Consent (Art. 6(1)(a)); Legitimate interests |
| Measure website usage and improve the site (analytics) | Analytics/technical data (cookies) | Consent (Art. 6(1)(a)), via our cookie banner |
| Comply with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object to such processing (see Your rights).
We do not sell personal data and we do not use it for targeted advertising or profiling that produces legal or similarly significant effects.
4. How we share personal data
We share personal data only as described here:
- With subprocessors that help us operate the Service (see Section 7).
- Within your workspace: other members of a workspace can see workspace content, comments, and membership as part of the collaboration features.
- With git providers (GitHub/GitLab) when you choose to connect them, to access the repositories you authorize.
- For legal reasons: to comply with law, enforce our terms, or protect the rights, safety, and security of users and the public.
- In a business transfer: if we are involved in a merger, acquisition, or asset sale, subject to this policy.
We do not otherwise disclose personal data to third parties for their own purposes.
5. "Sale" and "sharing" of personal data (CCPA/CPRA)
We do not sell personal data and do not share personal data for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, as amended by the CPRA. We have not done so in the preceding 12 months. Because we do not sell or share personal data, there is no "Do Not Sell or Share My Personal Information" action required, but you may still exercise the rights described in Section 10.
We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA (i.e., to provide the Service you request).
6. International data transfers
We host the Service on Amazon Web Services (AWS) and use subprocessors — including Google (Google Analytics) — that may process data in the United States and other countries. If you are located in the EEA, UK, or Switzerland, your personal data may be transferred outside your jurisdiction.
Where we transfer personal data internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by additional technical and organizational measures. You may request a copy of the relevant safeguards using the contact details above.
7. Subprocessors and third-party recipients
We engage the following third parties to process personal data on our behalf:
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Auth0 (Okta) | Authentication / sign-in | Email, name, auth identifiers | US |
| Amazon Web Services (AWS) | Hosting, database (Aurora PostgreSQL), file storage (S3), compute (Lambda), email scheduling, CDN, secrets | All stored data | US |
| SendGrid (Twilio) | Transactional and digest email delivery | Email address, message content | US |
| Sentry | Error and crash reporting | User ID, email, diagnostic data | US |
| Anthropic | AI inference of diagram node properties | Portions of scan/diagram data | US |
| GitHub / GitLab | Repository access for scans (when you connect them) | OAuth tokens, repository content | US |
| Vercel | Hosting of the public landing site | Website request data | US |
| Google LLC (Google Analytics 4) | Website analytics to improve the public site | Page views, pseudonymous identifier (_ga), device/browser, IP-derived approximate location | US |
| CookieYes | Cookie consent management (banner and consent records) | Consent choices, IP-derived region | EU / UK |
| PostHog | Product analytics and masked session replay for the web app | Interaction events, account identifier, device/browser, masked session recordings | EU |
We maintain data processing agreements with our subprocessors. A current list is available on request and may be updated from time to time.
8. Data retention
We retain personal data for as long as needed to provide the Service and for the purposes described in this policy, then delete or anonymize it. General guidelines:
- Account data: retained while your account is active and for a reasonable period afterward, unless you request deletion.
- Workspace, comment, and audit data: retained for the life of the workspace. Deleting a workspace cascades to its diagrams, members, invitations, and comments. Comments are soft-deleted (marked deleted) before permanent removal.
- Uploaded code (S3): the ZIP archive (or the temporary copy staged from a connected git repository) is deleted from our storage automatically as soon as the scan completes, whether it succeeds or fails, and the references to it are cleared from our database.
- Scan results: retained so we can display and reproduce your diagrams, and kept until you delete the scan job, at which point the results are removed from storage. We do not impose an automatic time-based expiry on results.
- Invitation tokens / API keys: stored only as hashes; revoked keys retain non-sensitive metadata for audit.
- Demo/waitlist data: retained until we have responded to your request and for our legitimate business follow-up, then deleted on request.
- Error reports (Sentry): retained for approximately 90 days, in line with our error-tracking configuration.
We may retain certain data longer where required by law or to resolve disputes and enforce agreements.
9. Your GDPR rights
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing;
- Object to processing based on legitimate interests, and to direct marketing at any time;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, without affecting prior processing;
- Not be subject to solely automated decisions producing legal or similarly significant effects (we do not carry out such decision-making).
To exercise these rights, contact us at privacy@dataparade.io. We will respond within one month (extendable by two further months for complex requests). You also have the right to lodge a complaint with your local supervisory authority.
Where DataParade processes data on behalf of an organization (controller) — for example, code submitted through a workspace — please direct rights requests to that organization; we will assist them as their processor.
10. Your California (CCPA/CPRA) rights
If you are a California resident, you have the right to:
- Know / Access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it;
- Delete personal information we collected from you, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of sale/sharing — note that we do not sell or share personal information;
- Limit use of sensitive personal information — we do not use sensitive personal information beyond permitted purposes;
- Non-discrimination — we will not discriminate against you for exercising your rights.
Categories collected in the preceding 12 months: identifiers; commercial information; internet/network activity; professional or employment-related information; and any personal information contained in code you submit. Sources and purposes are described in Sections 2–3. We disclose these categories to the subprocessors listed in Section 7 for business purposes only.
To exercise these rights, contact privacy@dataparade.io. We will verify your request using information associated with your account. You may use an authorized agent; we may require proof of authorization. We will respond within the timeframes required by the CCPA (generally 45 days, extendable to 90).
11. Security
We use technical and organizational measures to protect personal data, including:
- Encryption of git provider tokens and hashing of secrets, invitation tokens, and API keys;
- Storage of credentials in a managed secrets store (AWS Secrets Manager);
- Network isolation (VPC with private subnets) for the database and compute;
- Access controls, audit logging, and sanitization of sensitive values in logs.
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Cookies and local storage
We use cookies and similar technologies for a limited set of purposes. We do not use them for advertising or cross-context behavioral tracking.
- Strictly necessary cookies set via Auth0 to keep you signed in.
- Analytics cookies set by Google Analytics 4 on our public website to measure usage and improve the site (see Section 2.7). These are set only after you consent via our cookie banner.
- Consent cookie set by our consent manager (CookieYes) to remember your cookie choices.
- Product-analytics storage set by PostHog in the web application to measure feature usage and create masked session replays (see Section 2.7). Session replay masks all text and input content, so it does not record the content of your diagrams or anything you type.
- Browser local storage for a theme preference and to recover from diagram save errors (not a cookie; not used for tracking).
| Cookie | Set by | Purpose | Typical duration |
|---|---|---|---|
_ga, _ga_<id> | Google Analytics | Distinguish users; measure site usage | Up to 2 years |
cookieyes-consent | CookieYes | Store your cookie consent choices | 1 year |
| Auth0 session cookies | Auth0 | Keep you signed in | Session / short-lived |
Your choices. When you first visit our public website, a cookie banner lets you accept or reject analytics cookies. In the EEA, the UK, and Switzerland, analytics cookies are set only if you opt in; elsewhere you may opt out at any time. You can change your choice at any time via the cookie-preferences link in the banner. We deploy Google Analytics with Google Consent Mode v2, so no analytics cookies are set until you consent. We also honor browser-level opt-out signals such as Global Privacy Control (GPC). Disabling strictly necessary cookies may prevent you from signing in.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, notify you. Your continued use of the Service after changes take effect constitutes acceptance.
15. Contact
Questions or requests regarding this policy or your personal data:
- Privacy contact: privacy@dataparade.io
- Postal: DataParade, Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, USA