1Who we are, and what this covers#
Dashies is operated by Micheal Ben Nun, established in Israel. For the purposes of the UK and EU General Data Protection Regulation we are the controller of the personal data described here.
This policy covers dashies.ai, the Dashies app, the dashboards we serve, our publishing service and our documentation site. It does not cover your own data warehouse, your AI tool, or any site we link to.
2The three people this policy is about#
Keeping these apart is what makes the rest of this document readable, because we hold different things about each of them.
- You, our customer. You have an account, you build or read dashboards, and you may pay us. Most of this policy is about you.
- The people who open your dashboards. They are members of your workspace and hold accounts of their own, because there is no anonymous viewing.
- Visitors to our website. Someone reading the marketing pages or the documentation with no account at all.
3What we collect#
From your account
Your email address, the display name and profile picture your sign-in provider gives us, your account handle, and your plan and its status. If you sign in with a password, we store a hash of it and never the password itself.
From your workspaces
Workspace and team names, who is a member and with what role, invitations, and any email domain a workspace has verified.
Your dashboards, including their numbers
The dashboard specification your AI tool publishes, the SQL in it, and the results of running that SQL, which we store rather than re-querying on every view. If your query returns personal data, that personal data is in what we hold. How much of it there is depends entirely on how the query is written, which makes choosing what a dashboard selects a privacy decision as well as a design one.
Your data source connections
A label, the engine, a host and a status, plus the credential itself, which goes straight into an encrypted vault. See warehouse credentials below.
Operational records
Version history, refresh run outcomes, the administrative audit trail for a workspace, your dashboard activity feed, and the record of which AI tools have connected to your account, including the tool's reported user agent.
Billing
An identifier linking your account to a customer record at Polar, and a sanitised copy of the subscription events Polar sends us. Your card details and billing address are held by Polar and never reach us.
Approximate location
We derive a country from the network address of a request in two places: to decide which region serves your data, and for analytics as described below. We store the country. We do not store the address it came from in any of our databases.
4Why we process it, and on what legal basis#
- To provide the service you asked for, which is our performance of our contract with you: hosting, refreshing and serving dashboards, running workspaces and seats, and supporting you.
- To keep the service working and secure, which is our legitimate interest: rate limiting, bot checks, abuse prevention, diagnosing failures, and keeping an audit trail a workspace administrator can rely on.
- To take payment and meet tax and accounting duties, which is performance of our contract and compliance with a legal obligation.
- To understand how the product is used, which we do on the basis of your consent and nothing else. Decline and we do not do it.
5Who else processes your data#
We use the providers below to run Dashies. Each acts on our instructions under a contract, and each is named rather than described only by category, because a category does not let you check anything.
| Provider | What it does | Where |
|---|---|---|
| Cloudflare | Serves the app and every dashboard, and stores published dashboards, version snapshots, preview images and extracted data. Also runs the sign-up bot check and the queue that schedules refreshes. | Global edge network; stored objects as described in the next section |
| Supabase | Our main database: accounts, workspaces, dashboard metadata, operational and audit records, and the encrypted vault that holds warehouse credentials. | Sydney, Australia |
| Supabase (second project) | SAML single sign-on configuration and sign-in session state, for customers who use SSO. It holds no application data. | Frankfurt, Germany |
| Amazon Web Services | Runs the query engine that answers a served dashboard against your stored data. | Frankfurt, Germany, or Montreal, Canada |
| Fly.io | Runs the short-lived machine that connects to your warehouse and extracts rows for a refresh. It exists for one run and then stops. | Frankfurt, Germany, or Toronto, Canada |
| Polar | Our merchant of record. Takes payment, handles tax and issues invoices. Your billing name, email and address go to Polar directly and are held by them, not by us. | See the privacy notice published by Polar |
| PostHog | Product analytics, described in full below. | United States |
| Resend | Sends the email we send you: sign-in mail, refresh failure alerts and replies to the contact form. | United States |
| Google, Microsoft | Sign-in, if you choose to sign in with one of them. We receive the email address, name and profile picture they release to us. We request no other permission. | See their own privacy notices |
| Google Fonts | Serves the two typefaces this site uses. Loading a page therefore sends the IP address of your browser to Google. It receives nothing else and no account information. | The Google content delivery network |
We do not sell your data, and we do not use it to train AI models. We disclose it otherwise only where the law requires it, or where it is necessary to establish or defend a legal claim.
6Where your data is stored#
Dashies is a distributed service and the answer is genuinely split, so here it is in full rather than summarised.
| What | Held by | Where |
|---|---|---|
| Published dashboards, version snapshots, preview images, extracted data | Cloudflare R2 object storage | Eastern Europe, or Eastern North America for customers placed in Canada |
| Accounts, workspaces, dashboard metadata, audit records, warehouse credentials | Supabase (PostgreSQL, with credentials in its encrypted vault) | Sydney, Australia |
| Single sign-on configuration and session state | Supabase (second project) | Frankfurt, Germany |
| Query processing over your stored data, including temporary spill to local disk | Amazon EC2 | Frankfurt, Germany, or Montreal, Canada |
| Warehouse rows in transit during a refresh | A one-shot Fly.io machine | Frankfurt, Germany, or Toronto, Canada |
| Product analytics events | PostHog | United States |
We do not currently offer a data residency guarantee. Our object storage is created with a location preference rather than a binding jurisdiction restriction, so while the table above is where your data sits today, it is a statement of fact and not a commitment we can contractually hold. If residency is a requirement for you, talk to us before you build on Dashies rather than after.
7International transfers#
The table above shows that data reaches Australia, the European Union, Canada, the United States and our own establishment in Israel. Where personal data leaves the UK, EU or EEA, we rely on an adequacy decision where one covers the destination, and otherwise on Standard Contractual Clauses with the provider concerned.
Israel, Canada and the United Kingdom hold adequacy decisions from the European Commission. For the United States, the transfer basis for each provider is set out where that provider is described.
8Analytics, consent and privacy signals#
We use PostHog to understand how the product is used: pageviews, feature usage, and coarse details like device type, browser, and approximate location. We send PostHog your account identifier and the email address on your account so we can support you. We never send the contents of your dashboards, the SQL behind them, or anything from a connected warehouse. That last promise is enforced in our type system rather than by convention, so an event carrying customer data does not compile.
Opening a dashboard is recorded against the account that opened it, including a dashboard someone else shared with you. Every dashboard on Dashies is access-gated and there is no anonymous viewing, so you are signed in by the time the page loads and the account is the honest way to record the view. We record the dashboard's identifier, whether you own it, and the site you arrived from if it was not one of ours. We do not record the dashboard's name.
Separately from analytics, we keep your own list of which dashboards you have opened and when, so the app can show you the ones you keep coming back to. It is one entry per dashboard rather than a log of every visit, and it is yours alone: no other user can see it, including the people who own the dashboards and the administrators of your workspace, and no Dashies product surface exposes it to anyone else. It goes with your account if you delete that, you can clear it yourself from Home at any time, and you can ask us to remove it. If you have sent a Global Privacy Control or Do Not Track signal, or declined consent, we do not keep it at all.
PostHog processes this data in the United States, as our processor and under a signed data processing agreement. For visitors in the UK, EU and EEA, that transfer relies on PostHog's certification under the EU-US Data Privacy Framework and on Standard Contractual Clauses. We do not store your IP address: approximate location is derived from it when the event is received, and the address itself is discarded. Where an event has nobody behind it, such as a scheduled refresh running on our servers, it carries no location at all rather than an approximate one.
We ask for your consent the first time you visit, and you can decline. If your browser sends a Global Privacy Control or Do Not Track signal, or you have declined, we honor that everywhere - including on shared dashboards - and collect nothing. A shared dashboard is a static page that cannot show you that prompt itself, so if you have not answered it yet, opening one is still recorded. Answering it anywhere on Dashies applies there too.
One thing survives all of those signals, and it is worth naming rather than leaving you to discover: an aggregate view counter still increments. It records that a dashboard was opened and nothing about who opened it, so there is no identifier to suppress. If your requirement is that no identifier is collected, that is met. If it is that no signal of any kind reaches the server, it is not.
The bot check on sign-up
Our sign-in form runs Cloudflare Turnstile to tell a person from a script. It receives technical signals from your browser for that purpose alone. It is not used to track you and it is not part of analytics, so declining analytics does not turn it off.
9Your warehouse credentials#
The credential you enter to connect a data source is the most sensitive thing you give us, and it is handled differently from everything else on this page.
- It is typed into the Dashies app and posted over HTTPS. That is the only way in.
- It is written into an encrypted vault. The connection record stores only a reference to the vault entry, never the credential.
- Nothing reads it back out to a person. There is no screen that shows it, no interface that returns it, and no support flow that recovers it. Changing it means replacing it.
- Your AI tool never receives it. No publishing tool takes a password, key or token as a parameter, and the service your AI connects to holds no administrative database key with which it could read one.
- Deleting the connection deletes the vault entry.
The full mechanism, including what is enforced per engine, is at docs.dashies.ai/trust/warehouse-credentials (opens in a new tab).
10How we protect it#
- In transit: HTTPS across the service, and TLS on every warehouse connection with no option to turn the encryption off.
- At rest: warehouse credentials in an encrypted vault, service secrets in an encrypted parameter store, and platform-level encryption at rest from our storage providers.
- Access control in the database: row-level security on every application table, so a query that reaches for another tenant's row returns nothing rather than relying on the application to remember.
- Audit records that cannot be quietly edited: the audit tables reject updates and deletes at the database level, not by convention.
- Isolation of published dashboards: a dashboard runs in a sandbox that cannot reach your Dashies session, and a dashboard you are not entitled to see returns a response identical to one for a dashboard that never existed, so guessing at URLs reveals nothing.
- Signed-in access only: there is no public dashboard, and a signed-out visitor is redirected to sign in before anything is looked up.
- Enterprise controls: SAML single sign-on, SCIM directory sync, and a workspace email-domain bind proven by DNS.
What we do not claim. Dashies has no SOC 2 report, no ISO 27001 certification and no third-party audit. We would rather say so here than let the absence of a sentence imply one. Our vulnerability disclosure policy is at docs.dashies.ai/trust (opens in a new tab).
11How long we keep it#
Dashies deletes very little on a timer, which means deletion rather than time is what removes your data.
- Account and workspace records are kept while the account or workspace exists.
- Dashboards and their stored numbers are kept until you delete them.
- Version history is capped. We keep the 20 most recent unlabelled autosaves per dashboard and prune older ones. Labelled versions are kept, up to 30 per dashboard.
- Audit, activity and refresh history have no expiry. There is no retention window to configure and no automatic purge; they are kept for the life of the workspace or dashboard they belong to.
- Uploaded files that are never attached to a dashboard are deleted after 7 days, and a failed upload after 24 hours.
- Billing records are kept as long as tax and accounting law requires.
The detail behind these figures is at docs.dashies.ai/trust/privacy (opens in a new tab).
12Your rights, and how to use them#
Depending on where you live you have the right to access the personal data we hold about you, to have it corrected, to have it deleted, to receive a portable copy, to restrict or object to our processing, and to withdraw consent to analytics at any time without affecting what came before.
If you are in California, we do not sell or share personal information as those terms are defined there, and we will not discriminate against you for exercising a right.
Email mickey@dashies.ai and we will answer. If you are in the UK, EU or EEA you can also complain to your local supervisory authority, though we would rather you came to us first.
Deleting your account
You can delete your account in Settings, under Account. Before you confirm, we show you what it removes and what survives, including which of your workspaces change hands; you then type your email address to go ahead. It happens immediately and it cannot be undone. If you would rather we did it, email mickey@dashies.ai and we will.
One thing can stop it, and it is about a plan rather than about your data: a workspace you are the only member of that is still on a paid plan. Deleting your account would leave that workspace with a plan nobody can manage or cancel, so we ask you to cancel the subscription first. The cancel control acts on the workspace you are currently in, so if the one holding the plan is not the one you are standing in, you will need to switch to it first.
Deleting an account removes your sign-in record, your account, your personal dashboards including deleted ones, your data source connections and their vault credentials, your workspace memberships, your dashboard activity feed, your refresh alert history, the record of which AI tools connected to your account, and your private list of dashboards you have opened.
Two things deliberately survive it, and both are worth knowing before you ask. Dashboards that live in a workspace stay with the workspace, which is what stops one person leaving from destroying a team's work. And entries in a workspace audit log survive with the names they were written with, so a record of who was invited, promoted and removed does not develop gaps when someone leaves. That is the behaviour an audit trail has to have to be worth keeping, and if it is a problem for you, tell us and we will discuss it.
Deleting a workspace removes its audit log permanently, with no export and no recovery. If you need that record, read it before you delete the workspace.
13Children#
Dashies is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, tell us at the address below and we will delete it.
14Changes to this policy#
We may update this policy. If a change materially affects how we handle your personal data, we will tell you by email or in the app before it takes effect. The date at the top of this page is the date of the version you are reading, and we do not re-date it unless the text has changed.
15Contact#
Contact us or email mickey@dashies.ai with privacy questions or a request to delete your data.
Micheal Ben Nun, Israel