What We Collect

Account data

  • Name
  • Email
  • Organization
  • Role (provided via Clerk authentication).

Usage data

  • Pages viewed
  • Actions taken
  • IP address
  • User-agent (server logs).

Integration data

  • When you connect Jira/Bitbucket/Azure DevOps, we store OAuth tokens encrypted at rest.
  • We do NOT store payment card details — those are handled by Stripe.

How We Use Your Data

  • To provide the service you signed up for.
  • To communicate operational notices (account changes, security alerts, billing).
  • To improve product quality via aggregate analytics — never to sell or share with third-party advertisers.

How We Protect Your Data

  • All data is encrypted in transit (TLS 1.2+) and at rest (Supabase-managed Postgres encryption).
  • Access is controlled via row-level security policies and audited.
  • See our Security page for the full security model.

Your Rights

  • You can access, export, correct, or delete your personal data at any time.
  • To exercise these rights, email hello@lathe.studio with your account email.
  • EU residents have additional rights under GDPR; UK residents under UK GDPR; California residents under CCPA. We honor all of them.

Data Transfers

  • Data is processed on Supabase infrastructure (US/EU regions, depending on your account).
  • Stripe processes payments in the US under standard contractual clauses for EU data.

Contact