Privacy Policy
Effective Date: December 13, 2025
Mecha Data LLC ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the MechaDataCleaner application, website, and related services (collectively, the "Service").
Please read this Privacy Policy carefully. By using the Service, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, and password when you register
- Profile Information: Any additional information you add to your profile
- Payment Information: Billing address and payment method details (processed by Stripe)
- Your Data: Data files you upload for cleaning and processing
- Communications: Messages you send to us for support or feedback
1.2 Information Collected Automatically
- Usage Data: Pages viewed, features used, time spent, and actions taken
- Device Information: Browser type, operating system, and device identifiers
- Log Data: IP address, access times, and referring URLs
- Cookies: Session cookies, authentication tokens, and preference cookies
1.3 Information from Third Parties
- OAuth Providers: If you sign in with Google, we receive your name, email, and profile picture
- Payment Processor: Stripe provides transaction status and billing information
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process your data files and deliver cleaned outputs
- Process payments and manage subscriptions
- Send you transactional emails (account verification, password resets, receipts)
- Send you marketing communications (with your consent)
- Respond to your inquiries and provide customer support
- Monitor and analyze usage patterns to improve user experience
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
3. How We Share Your Information
We may share your information with:
3.1 Service Providers
Third-party vendors who assist us in operating the Service:
- Supabase: Database and authentication services
- OpenAI: AI-powered features (schema detection, cleaning suggestions)
- Stripe: Payment processing
- Vercel: Website hosting and analytics
- Email Provider: Transactional email delivery
3.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
3.4 With Your Consent
We may share your information for other purposes with your explicit consent.
4. Your Data and AI Processing
When you upload data for cleaning, portions of your data may be sent to third-party AI services (currently OpenAI) to provide features such as:
- Automatic schema detection and column type inference
- Intelligent cleaning recommendations
- DAX measure generation
- Chat-based data assistance
Important: We only send the minimum data necessary for these features (typically column names, data types, and sample values). We do not send your entire dataset to AI services. Please review OpenAI's privacy policy for information on how they handle data.
No Training: Your data is not used to train AI models. OpenAI's API usage policy states that API data is not used for training their models.
5. Data Retention
- Your Data Files: Retained only for the duration of your session or as needed to complete processing. Cleaned files are available for download and then deleted from our servers.
- Account Information: Retained for as long as your account is active or as needed to provide services.
- Usage Logs: Retained for up to 90 days for security and debugging purposes.
- Payment Records: Retained as required by law (typically 7 years for tax purposes).
Upon account deletion, we will delete your personal information within 30 days, except for data we are required to retain by law.
6. Data Security
We implement appropriate security measures to protect your information, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Secure password hashing
- Two-factor authentication (optional)
- Regular security audits and monitoring
- Access controls limiting employee access to user data
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request a machine-readable copy of your data
- Objection: Object to certain processing of your information
- Withdraw Consent: Withdraw consent where processing is based on consent
To exercise these rights, please contact us at privacy@mechadata.com.
8. Cookies
We use cookies and similar technologies to:
- Essential Cookies: Required for authentication and security
- Preference Cookies: Remember your settings (e.g., dark mode)
- Analytics Cookies: Understand how users interact with the Service
You can control cookies through your browser settings. Disabling essential cookies may affect Service functionality.
9. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using the Service, you consent to such transfers.
We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses where required.
11. California Privacy Rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information is being collected
- Know whether your personal information is sold or disclosed
- Opt out of the sale of personal information (we do not sell personal information)
- Request deletion of your personal information
- Not be discriminated against for exercising your rights
12. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, you have additional rights under GDPR, including the right to lodge a complaint with your local data protection authority.
Our legal bases for processing personal information include: performance of a contract, legitimate interests, compliance with legal obligations, and consent.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions about this Privacy Policy, please contact us at: