The policy includes a children's privacy section, consistent with standard COPPA disclosure requirements, stating that the service is not directed to children under a specified age and that Supabase does not knowingly collect personal information from minors.
This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Supabase's services are not intended for minors and that the company does not knowingly collect data from children, which is the standard COPPA-compliant disclosure framework for developer-facing platforms.
Interpretive note: The full text of the children's privacy section was not available in the provided document excerpt; this provision is inferred from the section heading referenced in the table of contents.
The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
View change record →Under this clause, Supabase states that its services are not directed to children and that personal information from minors is not knowingly collected. The full text of this section was not available in the provided document excerpt.
How other platforms handle this
When you use them, we'll validate your request by verifying your identity (for example, by confirming that you're signed in to your Google Account).
Not be Discriminated Against by us for exercising your privacy rights.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
1) REGULATORY LANDSCAPE: This provision engages COPPA (Children's Online Privacy Protection Act), enforced by the FTC for services directed to children under 13.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that Supabase's services are not intended for minors and that the company does not knowingly collect data from children, which is the standard COPPA-compliant disclosure framework for developer-facing platforms.
Under this clause, Supabase states that its services are not directed to children and that personal information from minors is not knowingly collected. The full text of this section was not available in the provided document excerpt.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.