Supabase · Supabase Terms of Service · View original document ↗

Customer Data Ownership and License to Supabase

Low severity High confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Supabase Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

You own your data, but you grant Supabase a broad license to use, copy, and display it as needed to operate the service.

This analysis describes what Supabase's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

While customer data ownership is confirmed, the operational license granted to Supabase is broad in scope and includes worldwide rights to reproduce and distribute customer data, which is the standard mechanism by which Supabase can store, back up, and deliver your data through its infrastructure.

Recent Activity

This document changed recently

Medium May 6, 2026

The relocation of Supabase's legal entity from Delaware to Singapore may affect which jurisdiction's courts and laws apply to disputes, potentially impacting your ability to pursue claims in US courts and changing which consumer protection laws govern your relationship. The requirement to explicitly click 'I Accept' rather than accepting through sign-up or service use clarifies consent but does not substantively change the agreement's terms. The new section on AI-powered tools discloses that Supabase may use AI chatbots for customer support; review that section to understand how such tools may process your inquiries.

View change record →

Consumer impact (what this means for users)

You retain ownership of all data you upload to Supabase, but the agreement grants Supabase a worldwide, royalty-free license to use and process that data to provide the service. This license is standard for cloud services but means your data may be processed across global infrastructure; review the DPA for data residency and transfer details.

How other platforms handle this

MetaMask Medium

We may share your personal information with our affiliates, meaning entities that control, are controlled by, or are under common control with Consensys. We also share information with service providers who assist in operating our services, subject to confidentiality obligations.

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Target Medium

RedCard. We share information with our financial partners to operate the Target RedCard program.

See all platforms with this clause type →

Monitoring

Supabase has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
As between Customer and Supabase, Customer is and will remain the sole and exclusive owner of all right, title, and interest in and to all Customer Data, including all intellectual property rights therein. Customer hereby grants to Supabase a non-exclusive, royalty-free, worldwide license to reproduce, distribute, and otherwise use and display the Customer Data and perform all acts with respect to the Customer Data as may be necessary for Supabase to provide the Services to Customer.

— Excerpt from Supabase's Supabase Terms of Service

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The customer data ownership clause and associated license engage GDPR Article 28 (processor obligations) and the principle that data controller instructions govern processor actions. The license language 'reproduce, distribute, and otherwise use and display' is operationally necessary for cloud services but should be read alongside the DPA to confirm that processing is limited to service delivery purposes. CCPA compliance depends on whether Supabase's processing is limited to the service provider role. GOVERNANCE EXPOSURE: Low to Medium. The data ownership confirmation is favorable to customers, but the breadth of the operational license and the interaction with the Aggregated Data carve-out means customers should confirm the DPA limits Supabase's processing to service delivery and does not permit secondary uses beyond aggregation. JURISDICTION FLAGS: EU/EEA customers should ensure the DPA includes appropriate Standard Contractual Clauses (SCCs) for international data transfers given Supabase's global infrastructure. Customers subject to data residency requirements (e.g., German Landesdatenschutz, French CNIL guidance) should confirm available regional hosting options. CONTRACT AND VENDOR IMPLICATIONS: The DPA is a critical companion document to this provision and should be reviewed to confirm scope limitations, sub-processor obligations, breach notification timelines, and data return/deletion procedures at contract end. COMPLIANCE CONSIDERATIONS: Data mapping exercises should capture Supabase as a processor and confirm that the processing scope in the DPA aligns with customer privacy notices; confirm sub-processor list and change notification mechanisms; assess data return and deletion procedures upon termination.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC oversees data handling representations in service agreements and can act where data use exceeds disclosed purposes
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Supabase Terms of Service
Entity
Supabase
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-009142
Document ID
CA-D-00681
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
b05f1426ea2945724132049d0ec22530b3eef85e9a34314efce12ed1efa3c1f0
Analysis generated
May 10, 2026 15:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Supabase
Document: Supabase Terms of Service
Record ID: CA-P-009142
Captured: 2026-05-10 15:04:09 UTC
SHA-256: b05f1426ea294572…
URL: https://conductatlas.com/platform/supabase/supabase-terms-of-service/customer-data-ownership-and-license-to-supabase/
Accessed: June 27, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Supabase's Customer Data Ownership and License to Supabase clause do?

While customer data ownership is confirmed, the operational license granted to Supabase is broad in scope and includes worldwide rights to reproduce and distribute customer data, which is the standard mechanism by which Supabase can store, back up, and deliver your data through its infrastructure.

How does this clause affect you?

You retain ownership of all data you upload to Supabase, but the agreement grants Supabase a worldwide, royalty-free license to use and process that data to provide the service. This license is standard for cloud services but means your data may be processed across global infrastructure; review the DPA for data residency and transfer details.

Is ConductAtlas affiliated with Supabase?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Supabase.