What We Collect
Account data
- Name
- Email
- Organization
- Role (provided via Clerk authentication).
Usage data
- Pages viewed
- Actions taken
- IP address
- User-agent (server logs).
Integration data
- When you connect Jira/Bitbucket/Azure DevOps, we store OAuth tokens encrypted at rest.
- We do NOT store payment card details — those are handled by Stripe.
How We Use Your Data
- To provide the service you signed up for.
- To communicate operational notices (account changes, security alerts, billing).
- To improve product quality via aggregate analytics — never to sell or share with third-party advertisers.
How We Protect Your Data
- All data is encrypted in transit (TLS 1.2+) and at rest (Supabase-managed Postgres encryption).
- Access is controlled via row-level security policies and audited.
- See our Security page for the full security model.
Your Rights
- You can access, export, correct, or delete your personal data at any time.
- To exercise these rights, email hello@lathe.studio with your account email.
- EU residents have additional rights under GDPR; UK residents under UK GDPR; California residents under CCPA. We honor all of them.
Data Transfers
- Data is processed on Supabase infrastructure (US/EU regions, depending on your account).
- Stripe processes payments in the US under standard contractual clauses for EU data.
Contact