Privacy Policy

Last updated: April 21, 2026

This is what data Deputary collects, how we use it, and the rights you have over it.

What we collect

  • Account data: your email, display name, optional password hash, last sign-in timestamp.
  • Workspace data: the SKUs, suppliers, purchase orders, and reorder recommendations you create or sync.
  • Connected platform data: inventory + sales pulled from Amazon SP-API and Shopify, and supplier emails fetched from your connected Gmail account. We store it to power the dashboard + assistant.
  • OAuth tokens: Gmail refresh tokens, Shopify access tokens, and SP-API refresh tokens — required to keep the integrations alive between sessions.
  • AI conversations: the questions you ask the assistant, Claude's replies, and the tool calls executed. Used to build context across sessions and so you can review history.
  • Usage analytics: we may collect basic page-view counts, request latency, and error reports (via Sentry) to keep the service running.

How we use it

Workspace data is used solely to power the features you see — KPI calculations, reorder recommendations, supplier email drafting, AI chat. We don't sell it, share it with advertisers, or use it to train external AI models. Anthropic does not train on the content of API requests by default; see Anthropic's commercial terms.

Where it lives

Data is stored in a PostgreSQL database hosted on Supabase (US region). The application runs on Fly.io (US). Backups are managed by Supabase. Tokens are stored in plaintext today; encrypted-at-rest columns are on the roadmap.

Who can see it

Inside your workspace: every invited team member has the same access. Outside your workspace: nobody, except (a) the founders of Deputary for support purposes when you ask, and (b) compelled disclosure to lawful authorities. We don't share data with third parties except the platforms you connect (Amazon, Shopify, Google) and our infrastructure providers (Supabase, Fly, Anthropic, Sentry).

Your rights

  • Access: request a copy of your workspace data anytime via support.
  • Correction: edit or delete records directly through the app.
  • Deletion: ask us to wipe your account; we'll delete it within 30 days, except backup retention up to 90 days.
  • Disconnection: revoke any third-party integration from Settings → Integrations at any time. Tokens are deleted from our DB on disconnect.

Cookies

We use a single session cookie for sign-in. No third-party tracking cookies. No advertising cookies.

Changes

We'll notify in-app for material changes.

Contact

Questions, data requests, or deletion: support@herd-group.com.

See also: Terms of Service