Privacy Policy
This policy explains what data Dafine collects when you use it, how that data is used, and what choices you have. We have written it in plain language because we believe you deserve to understand it without a law degree.
Introduction
Dafine ("we", "us", "the project") is an open-source data cleaning platform. When you use Dafine — whether on a hosted instance or by running it yourself — you may provide personal information and data files. This Privacy Policy describes how that information is handled.
By creating an account and using Dafine, you agree to the data practices described in this policy. If you are running a self-hosted instance, this policy applies to you as the operator and you should update it to reflect your own practices before sharing it with your users.
Dafine is open source under the MIT License. If you are self-hosting Dafine, you are the data controller for your users, and you are responsible for your own privacy obligations (e.g. GDPR, CCPA). This policy covers the reference hosted deployment only.
Who We Are
Dafine is an open-source project created and maintained by Michael Vincent Sebastian Handojo. The hosted instance is provided for general use and evaluation purposes.
For any privacy-related enquiries, contact us at the address listed in the Contact section below.
Data We Collect
We collect only the minimum data necessary to provide the service.
Account information
- Email address — used as your login identifier. Never shared with third parties for marketing.
- Password (hashed) — stored as an Argon2id hash. We cannot recover your plain-text password.
- OpenRouter API key (encrypted) — if you choose to save your key in Account Settings, it is stored encrypted with AES-256-GCM. It is never returned to the browser or logged.
- Account creation timestamp — used to display your "Member Since" date.
Cleaning session data
- Session title — the optional label you give a cleaning session.
- Original filename and file type — stored as metadata so you can identify sessions in History.
- Row counts (before and after) — a summary statistic stored with each session.
- Column context strings — the optional descriptions you provide for individual columns. Stored as a JSON object linked to the session.
- Generated SQL query — the DuckDB SQL produced by the AI. Stored so you can review it later in History.
- AI reasoning text — the model's explanation of its cleaning decisions. Stored with the session.
- Cleaned file (Parquet) — the output of the cleaning pipeline, stored in a private Supabase Storage bucket. Accessible only to you via your authenticated session.
Technical data
- JWT session token — stored in your browser's
localStorage. Expires after 24 hours (configurable). - Email address (localStorage) — cached in the browser for display in the navigation bar.
Data We Do Not Collect
We want to be explicit about what Dafine does not do:
- We do not store your uploaded raw files. Your original uploaded file is written to a temporary location on the server and deleted immediately after cleaning, inside a
finallyblock that runs even if an error occurs. - We do not send your raw data to any AI. The AI prompt contains only statistical summaries (null counts, value distributions, column types). Your actual row data is never included in any API call.
- We do not use tracking cookies. Dafine does not use analytics cookies, advertising cookies, or any third-party tracking scripts.
- We do not sell your data. Your data is never sold, rented, or traded to any third party for any purpose.
- We do not collect payment information. Dafine does not process payments. Billing for AI model usage is handled entirely between you and OpenRouter.
- We do not log your file contents. Application logs capture request metadata (endpoint, timestamp, HTTP status) but not file contents or query results.
How We Use Your Data
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account login and identification | Contract (providing the service) |
| Password hash | Authenticating your login | Contract |
| Encrypted API key | Decrypted server-side to call OpenRouter on your behalf | Contract |
| Session metadata (title, filename, row counts) | Displayed in your History page; lets you identify past sessions | Contract |
| Generated SQL & AI reasoning | Displayed in History detail view for your review and audit | Contract |
| Cleaned Parquet file | Stored so you can re-download from History at any time | Contract |
| Column context strings | Passed to the AI prompt to improve cleaning quality; stored with the session | Contract |
We do not use any of your data for advertising, profiling, model training, or any purpose not listed above.
Data Storage & Retention
Where your data is stored
- Account data & session metadata — stored in a Supabase (PostgreSQL) database. Supabase infrastructure is hosted on AWS. Data is encrypted at rest.
- Cleaned files — stored in a private Supabase Storage bucket. Files are only accessible via authenticated, signed requests from the backend.
- Dashboard configurations — stored only in your browser's
localStorage. They never leave your device.
How long we keep your data
- Account data — retained for as long as your account exists. Deleted upon account deletion (see Your Rights).
- Cleaning sessions & stored files — retained indefinitely until you delete them from the History page. Each deletion removes both the database record and the Parquet file from storage.
- Uploaded raw files — retained for zero time. Deleted from server memory immediately after processing.
- JWT tokens — expire after 24 hours. No server-side token revocation list is currently maintained.
If you are running your own Dafine deployment, retention is entirely determined by your own Supabase configuration and infrastructure choices.
Third-Party Services
Dafine integrates with a small number of third-party services. Here is exactly what is shared with each:
| Service | Data shared | Purpose |
|---|---|---|
| Supabase | Account data, session metadata, cleaned Parquet files | Hosted database and file storage. Data subject to Supabase Privacy Policy. |
| OpenRouter | Statistical column profile (no raw data). Your decrypted API key is sent in the Authorization header of each AI call. | AI model routing. Data subject to OpenRouter Privacy Policy. |
| Railway (deployment) | Backend application and environment variables (including .env secrets) | Cloud hosting for the backend server. Data subject to Railway Privacy Policy. |
| Google Fonts | Browser IP address (standard web font request) | Loading DM Mono and Syne typefaces. Subject to Google Privacy Policy. |
| jsDelivr (CDN) | Browser IP address (standard CDN request) | Loading Chart.js from CDN. |
No other third-party services receive any data from Dafine. In particular, there are no analytics providers, advertising networks, or social media tracking pixels.
Your Rights & Controls
You have control over your data. Here is what you can do directly within the Dafine interface:
- View your account data — your email and account creation date are shown on the Account Settings page.
- Change your password — available in Account Settings at any time.
- Update or remove your API key — you can paste a new key to overwrite the stored one at any time.
- Delete individual cleaning sessions — the delete button in History removes the database record and the stored Parquet file from Supabase Storage permanently.
- Download your cleaned data — available from the History page at any time while the session exists.
- Delete your dashboard configurations — available in the Dashboard History tab; clears from your browser's localStorage.
- Log out — clears your JWT token and cached email from localStorage on this device.
Account deletion
Self-service account deletion is not yet implemented in the UI. To request full deletion of your account and all associated data, contact us using the details in the Contact section. We will process deletion requests within 30 days.
Data portability
Your cleaned datasets can be downloaded at any time from the History page in CSV format. Column context and session metadata can be viewed in the History detail panel. If you need a machine-readable export of all your stored data, contact us.
GDPR / regional rights
If you are located in the European Economic Area (EEA), the United Kingdom, or another region with specific data protection laws, you may have additional rights including the right to access, rectification, erasure, restriction of processing, and the right to lodge a complaint with your local supervisory authority. Contact us to exercise these rights.
Security
We take reasonable steps to protect your data:
- Passwords — hashed with Argon2id. Never stored in plain text.
- API keys — encrypted at rest using AES-256-GCM with a server-side master key. Never stored unencrypted, never logged, never returned to the browser.
- Session tokens — HS256 JWTs with a 24-hour expiry, signed with a secret key set by the operator.
- Transport — all communication between the frontend and backend uses HTTPS in the hosted deployment.
- Database access — the backend uses Supabase's service role key, which is only present in server-side environment variables and never exposed to the browser.
- Uploaded files — never persisted. Processed in a temp file and deleted in a
finallyblock.
No system is completely secure. If you discover a security vulnerability, please disclose it responsibly by contacting us privately before making it public.
Cookies & Browser Storage
Dafine does not use cookies. It uses browser localStorage for three purposes:
| Key | Contents | Cleared on |
|---|---|---|
dafine_token |
Your JWT session token (expires after 24 hrs) | Logout or manual clear |
dafine_email |
Your email address (display only in nav bar) | Logout or manual clear |
dafine_user_id |
Your user ID integer | Logout or manual clear |
dafine_dashboards |
Up to 30 saved dashboard configurations (chart type, axes, filters, title) | Manual delete from Dashboard History, or browser data clear |
You can clear all of this data at any time by clicking Logout (which clears the first three keys) or by clearing your browser's localStorage for the Dafine domain.
Third-party resources loaded by Dafine (Google Fonts, jsDelivr CDN) may set their own cookies or use other browser storage. We do not control these. Refer to their respective privacy policies.
Children's Privacy
Dafine is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us and we will delete the account promptly.
Open Source Notice
Dafine's source code is publicly available under the MIT License. Anyone can inspect the code to verify the data practices described in this policy.
If you fork and self-host Dafine, you become the data controller for your own deployment. This Privacy Policy applies only to the reference hosted instance. As operator, you are responsible for updating this policy to reflect your own infrastructure and data flows before publishing it to your users.
The MIT License permits commercial and private use. It does not override your legal obligations under applicable data protection law. Running Dafine on data that belongs to others (e.g. your customers) means you must have a lawful basis for processing that data under the laws of your jurisdiction.
Changes to This Policy
We may update this policy from time to time. When we make significant changes, we will update the "Effective" date at the top of this page. Continued use of Dafine after a policy change constitutes acceptance of the new terms.
We encourage you to review this page periodically. Because Dafine is open source, all historical versions of this policy are visible in the project's git history.
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 15 June 2025 | Initial policy published. |
Contact
For any questions about this Privacy Policy, to request data deletion, or to report a security concern, please reach out:
We will respond to all privacy-related requests within 30 days.