Legal
Privacy Policy
Short version: We process account and billing data to run SuperCompress. Compress requests are processed to return results and meter usage. We may briefly retain compressed outputs for idempotent retries (typically up to about 48 hours), and we keep usage/billing metadata longer. We do not sell your personal information. Self-hosted open-source installs do not send your prompts to us unless you configure them to call our hosted API.
1. Scope
This Privacy Policy explains how Arjun Shah, doing business as SuperCompress (“SuperCompress,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal information in connection with:
- supercompress.dev and related subdomains;
- the hosted compression API, dashboard, billing, playground, and agent/MCP tooling we operate; and
- support and product emails related to those services.
It does not cover third-party sites or model providers you send data to after compression (OpenAI, Anthropic, Google, Cursor, etc.). Their privacy policies apply to those services.
2. Who is responsible
For personal information processed in connection with the Services, the controller (or equivalent) is:
Arjun Shah d/b/a SuperCompress
Email: arjunkshah21@gmail.com
If you need a data processing agreement (DPA) for enterprise use of the hosted API, contact us at the same address.
3. Information we collect
3.1 Account and identity
- Email address, display name, and authentication identifiers (for example Firebase Auth UID);
- Sign-in method (email/password or Google OAuth profile information Google shares with us);
- Account preferences and settings.
3.2 Billing and payments
- Stripe customer identifiers, subscription/credit status, invoices, and payment event metadata;
- Prepaid credit balances, auto-recharge preferences, and usage-derived charges;
- Limited billing contact details associated with your Stripe customer.
Payment card numbers are handled by Stripe; we do not store full card numbers on SuperCompress servers.
3.3 API usage and compression processing
- Request content you submit: context, query, and related parameters needed to compress. We process this content to produce compressed outputs and measure tokens.
- Technical fingerprints: cryptographic hashes of billing-relevant request fields used for idempotency and double-billing prevention (not a substitute for encryption of your content).
- Outputs: compressed text and savings metadata returned to you. For idempotent retries, we may temporarily store a replayable compressed response (see Retention).
- Usage metrics: tokens in/out/saved, request counts, timestamps, rate-limit counters, API key identifiers (hashed or prefixed as implemented), and error/status codes.
3.4 Device and log data
- IP address, user agent, approximate location derived from IP, request timestamps, and diagnostic logs from our hosting provider (currently Vercel) and related infrastructure;
- Security and abuse-prevention signals (for example rate-limit hits).
3.5 Communications
- Emails you send us, and transactional product emails we send you (welcome, billing receipts/thank-you, paywall notices, optional product tips if you remain subscribed);
- Support correspondence.
3.6 Information we do not intentionally collect
We do not require government ID numbers or sensitive special-category data to use SuperCompress. Please do not submit highly sensitive personal data in compress payloads unless necessary for your use case and lawful for you to process—you control what you send.
4. How we use information
We use personal information to:
- provide, operate, secure, and improve the Services;
- authenticate users, manage API keys, and enforce rate limits and quotas;
- meter usage, bill credits, prevent double-billing, and detect fraud/abuse;
- send transactional messages (account, security, billing) and, where permitted, product updates—you can unsubscribe from non-essential marketing emails;
- respond to support requests and investigate incidents;
- comply with law, enforce our Terms of Service, and protect rights, safety, and property; and
- produce aggregated, de-identified statistics (for example overall token-savings trends) that do not identify you.
We do not sell your personal information. We do not use Customer Content to train third-party foundation models for public release. We do not use your compress payloads to build a public dataset of customer prompts.
5. Legal bases (EEA/UK)
If GDPR/UK GDPR applies, we process personal data under these bases as appropriate:
- Contract — to provide the Services you request (account, API, billing);
- Legitimate interests — security, abuse prevention, product improvement with appropriate safeguards, and limited product communications;
- Consent — where required (for example certain cookies or marketing), which you may withdraw;
- Legal obligation — when we must retain or disclose information to comply with law.
6. How we share information
We share personal information with:
| Category | Examples | Purpose |
|---|---|---|
| Infrastructure | Vercel (hosting/compute), Google Firebase / Google Cloud (auth, datastore) | Run and store the Services |
| Payments | Stripe | Process payments and credits |
| Email delivery | Transactional email providers (for example Resend or similar) | Send account and product email |
| Professional advisors | Lawyers, accountants | As needed for business operations |
| Authorities | Courts, regulators, law enforcement | When legally required or to protect rights/safety |
| Business transfers | Acquirer or successor | If we are involved in a merger, acquisition, or asset sale |
Processors act on our instructions and are required to protect data appropriately. We may also share information at your direction (for example if you integrate SuperCompress into a workflow that forwards data elsewhere).
7. Retention
We retain information only as long as needed for the purposes above, including:
- Account data — for the life of the account, then deleted or de-identified within a reasonable period after closure, unless law requires longer retention.
- Billing and ledger metadata (token counts, credit burns, idempotency fingerprints, payment references) — retained as needed for accounting, dispute resolution, abuse prevention, and legal compliance (often years for financial records).
- Replayable compressed responses — retained briefly to support idempotent retries (on the order of about 48 hours), after which response bodies are intended to expire or be scrubbed while billing metadata may remain.
- Server logs — retained for a limited operational window consistent with our host’s defaults and our security needs, then deleted or aggregated.
- Email records — retained as needed to operate communications and prove delivery of transactional notices.
Exact periods may vary as we improve systems; we will not keep Customer Content longer than reasonably necessary for the Services.
8. Security
We use administrative, technical, and organizational measures designed to protect personal information, including TLS in transit, access controls on production systems, hashed or secret-managed API credentials, and least-privilege practices for operators. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
You are responsible for protecting your API keys and account credentials and for configuring your clients safely.
9. International transfers
We are based in the United States. If you access the Services from another country, your information may be processed in the U.S. and other countries where our providers operate. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) offered by our processors.
10. Your rights
Depending on where you live, you may have rights to:
- access, correct, or delete personal information;
- portability of certain data;
- object to or restrict certain processing;
- withdraw consent where processing is consent-based; and
- appeal or lodge a complaint with a supervisory authority.
10.1 California (CCPA/CPRA)
California residents may have rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information as those terms are defined by law. We do not sell personal information and do not share it for cross-context behavioral advertising in the way those statutes typically target. To exercise rights, email arjunkshah21@gmail.com. We will not discriminate against you for exercising privacy rights.
10.2 How to exercise rights
Email us from the address on your account when possible so we can verify your request. We may need additional information to confirm identity. Authorized agents may submit requests as allowed by law.
11. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child provided us personal information, contact us and we will take appropriate steps to delete it.
12. Cookies and similar technologies
We use cookies and similar technologies that are necessary to operate the site and dashboard (for example session/auth cookies from Firebase and security preferences). We may use limited analytics or performance tooling from our host; if we introduce advertising cookies or non-essential trackers, we will update this Policy and provide choices where required.
You can control cookies through your browser settings. Disabling certain cookies may break login or dashboard features.
13. Self-hosting and open source
If you run SuperCompress open-source software entirely on your own machines without calling our hosted API, your prompts stay in your environment and this Policy does not apply to that local processing. If your installation is configured to send requests to api.supercompress.dev (or another SuperCompress hosted endpoint), those requests are processed under this Policy.
14. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. For material changes, we will provide additional notice when reasonable. Continued use of the Services after the effective date means you acknowledge the updated Policy.
15. Contact
Privacy questions or requests:
SuperCompress / Arjun Shah
Email: arjunkshah21@gmail.com
Web: https://www.supercompress.dev