Legal
Privacy Policy
This policy explains what we collect, why we collect it, and how we safeguard your data across the website, dashboard, APIs, and SDK event pipeline.
Data model
Minimal
Operational metadata first
Storage
Encrypted
In transit and at rest
Control
User-owned
Export and deletion rights
1. Introduction
Overrule ("we," "us," or "our") operates the overrule.dev website and the Overrule cloud dashboard (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
2. Information We Collect
Account Information
When you sign up via Google OAuth, we receive your name, email address, and profile picture from your Google account. We do not receive or store your Google password.
Usage Data
We collect information about how you interact with the Service, including pages visited, features used, and timestamps. This helps us improve the product.
SDK Event Data
When you use the Overrule Python SDK, it sends governance events to our cloud. These events contain metadata about LLM calls (model, provider, latency, policies applied, violations detected). We do not store the actual content of your LLM inputs or outputs unless you explicitly include them in event metadata.
API Keys
We store hashed API keys for authentication. The full key is shown once at creation and cannot be retrieved afterward.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To authenticate your identity and manage your account
- To process and display your governance event data in the dashboard
- To send transactional emails (account changes, security alerts)
- To detect and prevent abuse or unauthorized access
- To comply with legal obligations
4. Data Storage & Security
Your data is stored in Supabase (PostgreSQL) with Row Level Security enabled. All data is encrypted in transit (TLS 1.3) and at rest. We implement security headers (HSTS, X-Frame-Options, CSP) and rate limiting on all API endpoints.
We do not sell your data. We do not share your data with third parties for marketing purposes.
5. Data Retention
Account data is retained for as long as your account is active. Event data is retained according to your plan limits. You may request deletion of your account and all associated data at any time via the Settings page or by contacting us.
6. Third-Party Services
We use the following third-party services:
- Supabase — Authentication and database hosting
- Vercel — Application hosting and CDN
- Google — OAuth authentication provider
Each of these services has their own privacy policies. We recommend reviewing them.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Withdraw consent for data processing
If you are in the European Economic Area (EEA), you have additional rights under GDPR. Contact us to exercise any of these rights.
9. Children
Our Service is not directed to individuals under 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date and, where appropriate, by email.
11. Contact
For privacy-related questions or requests, contact us at: support@overrule.dev
For data protection inquiries (GDPR, deletion requests): admin@overrule.dev