Always current and audit-ready legal terms

Legal

Privacy Policy

This policy explains what we collect, why we collect it, and how we safeguard your data across the website, dashboard, APIs, and SDK event pipeline.

Last updated: July 10, 2026Learn about OverruleVersioned policy snapshotsEnterprise-ready controls

Data model

Minimal

Operational metadata first

Storage

Encrypted

In transit and at rest

Control

User-owned

Export and deletion rights

1. Introduction

Overrule ("we," "us," or "our") operates the overrule.dev website and the Overrule cloud dashboard (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

Account Information

When you sign up via Google OAuth, we receive your name, email address, and profile picture from your Google account. We do not receive or store your Google password.

Usage Data

We collect information about how you interact with the Service, including pages visited, features used, and timestamps. This helps us improve the product.

SDK Event Data

When you use the Overrule Python SDK, it sends governance events to our cloud. These events contain metadata about LLM calls (model, provider, latency, policies applied, violations detected). We do not store the actual content of your LLM inputs or outputs unless you explicitly include them in event metadata.

API Keys

We store hashed API keys for authentication. The full key is shown once at creation and cannot be retrieved afterward.

3. How We Use Your Information

  • To provide, maintain, and improve the Service
  • To authenticate your identity and manage your account
  • To process and display your governance event data in the dashboard
  • To send transactional emails (account changes, security alerts)
  • To detect and prevent abuse or unauthorized access
  • To comply with legal obligations

4. Data Storage & Security

Your data is stored in Supabase (PostgreSQL) with Row Level Security enabled. All data is encrypted in transit (TLS 1.3) and at rest. We implement security headers (HSTS, X-Frame-Options, CSP) and rate limiting on all API endpoints.

We do not sell your data. We do not share your data with third parties for marketing purposes.

5. Data Retention

Account data is retained for as long as your account is active. Event data is retained according to your plan limits. You may request deletion of your account and all associated data at any time via the Settings page or by contacting us.

6. Third-Party Services

We use the following third-party services:

  • Supabase — Authentication and database hosting
  • Vercel — Application hosting and CDN
  • Google — OAuth authentication provider

Each of these services has their own privacy policies. We recommend reviewing them.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent for data processing

If you are in the European Economic Area (EEA), you have additional rights under GDPR. Contact us to exercise any of these rights.

8. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics that track you across websites.

9. Children

Our Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date and, where appropriate, by email.

11. Contact

For privacy-related questions or requests, contact us at: support@overrule.dev

For data protection inquiries (GDPR, deletion requests): admin@overrule.dev