82 Total
28 High severity
47 Medium severity
7 Low severity

Key Facts

What may Supabase share with advertising and marketing partners?
Supabase may share limited personal information, such as contact identifiers including email addresses or cryptographic hashes of email addresses, with advertising and marketing partners.
Does Supabase share limited personal information, such as contact identifiers including email addresses or cryptographic hashes of email addresses, with advertising and marketing partners?
Supabase may share limited personal information, such as contact identifiers including email addresses or cryptographic hashes of email addresses, with advertising and marketing partners.
What level of protection may a country not provide?
Supabase warns that a country to which personal data is transferred may not provide the same level of protection for personal information as the country from which it was transferred.
To what extent will Supabase use personal information to send marketing communications?
Supabase will only use personal information to send marketing communications to the extent the user has given consent to do so.
When may Supabase transfer any information it collects?
Supabase may transfer any information it collects in the event it sells or transfers all or a portion of its business or assets.
May Supabase transfer any information it collects in the event it sells or transfers all or a portion of its business or assets?
Supabase may transfer any information it collects in the event it sells or transfers all or a portion of its business or assets.
Does Supabase knowingly solicit or collect personal information from children under the age of 13?
Supabase does not knowingly solicit or collect personal information from children under the age of 13.
What are Supabase's third-party service providers subject to?
Supabase's third-party service providers are subject to reasonable confidentiality terms and provisions restricting their use of users' personal information.
What will Supabase collect when a user submits a query through the Supabase AI tool?
When a user submits a query through the Supabase AI tool, Supabase will collect the content of the query including the user's inputs or prompts and the corresponding generated output.
Does Supabase collect the content of the query including the user's inputs or prompts and the corresponding generated output?
When a user submits a query through the Supabase AI tool, Supabase will collect the content of the query including the user's inputs or prompts and the corresponding generated output.
Stay ahead of the changes
Track Supabase and get the diff the day its terms change.
Summary

This document explains what data Supabase collects about you, how it uses and shares that data, and your rights around it. Supabase collects everything you submit to its AI tools and uses your personal information for marketing, but it will not share the content of your databases or your User Content with third parties for advertising purposes. Supabase can change these privacy terms at any time in its sole discretion.

Analysis

The Supabase Privacy Policy establishes the conditions under which Supabase collects, uses, shares, and transfers personal information and User Content. Supabase collects the full content of AI tool interactions — both user inputs and generated outputs — as part of normal Service operation, while committing not to access the content of user databases without consent. Personal information may be shared with advertising and marketing partners, including via hashed email addresses, and may be transferred in connection with a business sale or asset transfer, though User Content is absolutely prohibited from third-party marketing use absent explicit user submission for that purpose. International data transfers carry an acknowledged risk of reduced legal protection in destination countries. Supabase reserves the right to amend the policy in its sole discretion.

What this means for you

Supabase collects both the prompts you submit to its AI tools and the outputs generated in response, and uses your personal information — including potentially a hashed version of your email address — for marketing and advertising purposes. Supabase will not send you marketing communications unless you have given consent, so withdrawing or withholding that consent limits its authority to contact you for marketing. The content of your databases and the information you manage through the Service will not be accessed by Supabase without your consent, and your User Content will not be shared with third parties for marketing or advertising unless you have explicitly submitted it for that purpose.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

2 important changes detected

3 versions captured · Last updated: July 2026

What changed Supabase removed the explicit publication date and version history from the opening of their Privacy Policy in an update detected on July 31, 2026. The policy previously stated 'Last Modified: 13 May 2026' and 'Previous Version: 16 March 2026' directly in the opening paragraph; the revised version replaces this with a generic 'Legal Privacy Policy Version' header. This change removes publicly visible version tracking from the policy's opening, though the substantive privacy terms themselves were not altered in this particular update.
Why this matters This change is a formatting update to the Privacy Policy header with no material impact on the substantive privacy rights or obligations described in the policy. The removal of explicit version tracking from the opening does not alter what data Supabase collects, how it uses that data, or what rights users retain. Users operating under this policy are subject to the same privacy terms as before; only the visibility of version history in the policy's opening has changed.
View full change record →

May 15, 2026

medium
What changed Supabase updated its privacy policy on May 15, 2026 to disclose expanded use of business contact information for sales and marketing outreach, expanded sharing of personal information with the marketing service provider Customer.io, and clarified consent requirements for marketing communications including location-based and cross-source data analysis. The updated policy establishes that marketing-related consents are independent and can be managed separately.
Why this matters The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
View full change record →

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

82 provisions
12 featured
12 clause types
28 high severity
Targeting and Audience Restrictions 1 1 high
Stay ahead of the changes

Monitoring

Supabase has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Access and deletion requests not guaranteed to be satisfied and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 31, 2026 01:15 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000682
Version ID CA-V-005409
SHA-256 6e376ec44870410b2ce0c025ab8578c57da42625f8cca775c27951481da57504
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans