Skip to content
AutoSuggesAutoSugges home
Start free
Menu
Appearance
Appearance: System.

Data processing agreement

Last updated 2026-09-22.

Roles

When you author lists containing personal data of your own end users, you are the data controller and AutoSugges is the data processor, processing that data only to compile and serve the autocomplete artifacts you configure.

Scope of processing

Processing is limited to: storing the rows you author in your isolated tenant schema, compiling them into runtime artifacts, serving those artifacts from the edge in response to a query, and recording aggregate selection signal (which canonical item was shown and picked, tied to a request id rather than an end-user identity) to improve future ranking.

Sub-processors

The following sub-processors are engaged, each for the purpose stated:

  • Supabase System of record (PostgreSQL) for account and tenant data, and authentication (Supabase Auth / GoTrue) for sign-in.
  • Cloudflare Edge runtime (Workers), compiled artifact storage (Workers KV) and bot/abuse challenge (Turnstile) at sign-up and key provisioning.
  • Stripe Payment processing and subscription billing.
  • Bird Delivery of transactional email (e.g. account and billing notifications).

Isolation and access controls

Your rows are isolated by row-level security, enabled and forced on every relevant table. Runtime autocomplete cannot query PostgreSQL at all — it reads only compiled, verified artifacts. Credential material and internal ledgers live in a schema no API role can address.

Retention and deletion

The active published version of a list plus the five most recently superseded versions are retained; a superseded artifact is deleted from the edge store 30 days after it is deactivated. Requesting deletion of a list or an account removes the corresponding control-plane rows; deletion of already-superseded edge artifacts follows the same 30-day schedule.

Governing jurisdiction

This agreement is governed by the jurisdiction of the operator: [jurisdiction to be determined by the operator].

Requests

For a signed copy, a sub-processor list update or a data-subject request, email support@autosugges.com.

Data processing agreement — AutoSugges