Supabase has a section addressing how long it keeps your data and what security measures it applies, though the specific retention periods and security standards are not reproduced in the available document text.
This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Knowing how long Supabase retains your personal data and what security protections are in place is important for assessing your ongoing privacy exposure after you stop using the service.
Interpretive note: The document was truncated before the data retention and security section could be reviewed, so no specific retention periods, deletion practices, or security standards can be confirmed from the available text.
The updated policy discloses that Supabase may use business contact information, including email domains, to identify organizations for sales and marketing outreach. The policy now explicitly states that personal information will be shared with Customer.io, a marketing communications service provider. For marketing communications, the policy relies on user consent for three purposes: sending marketing messages, using approximate location information to determine relevant communications, and combining personal information from different sources for relevance determination. These three consents operate independently, meaning you can grant or withdraw any of them without affecting the others. You can manage these marketing-related consents separately through the consent mechanisms available in your account or in response to marketing communications.
View change record →The policy includes data retention and security provisions, but the full text was not available for review. Users concerned about how long their data is kept should contact privacy@supabase.com to request specific retention period information.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"Data retention and securityExcerpt from Supabase's Privacy Policy
REGULATORY LANDSCAPE: Data retention obligations are governed by GDPR Article 5(1)(e) (storage limitation principle), CCPA's implied reasonableness standard, and applicable sector-specific regulations.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Knowing how long Supabase retains your personal data and what security protections are in place is important for assessing your ongoing privacy exposure after you stop using the service.
The policy includes data retention and security provisions, but the full text was not available for review. Users concerned about how long their data is kept should contact privacy@supabase.com to request specific retention period information.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.