Legal

Privacy Policy

This policy explains what data Dafine collects when you use it, how that data is used, and what choices you have. We have written it in plain language because we believe you deserve to understand it without a law degree.

calendar_todayEffective: 15 June 2025 tagVersion 1.0 Last reviewed: 15 June 2025
Overview

Introduction

Dafine ("we", "us", "the project") is an open-source data cleaning platform. When you use Dafine — whether on a hosted instance or by running it yourself — you may provide personal information and data files. This Privacy Policy describes how that information is handled.

By creating an account and using Dafine, you agree to the data practices described in this policy. If you are running a self-hosted instance, this policy applies to you as the operator and you should update it to reflect your own practices before sharing it with your users.

Open source & self-hosted

Dafine is open source under the MIT License. If you are self-hosting Dafine, you are the data controller for your users, and you are responsible for your own privacy obligations (e.g. GDPR, CCPA). This policy covers the reference hosted deployment only.

Identity

Who We Are

Dafine is an open-source project created and maintained by Michael Vincent Sebastian Handojo. The hosted instance is provided for general use and evaluation purposes.

For any privacy-related enquiries, contact us at the address listed in the Contact section below.

Data Practices

Data We Collect

We collect only the minimum data necessary to provide the service.

Account information

  • Email address — used as your login identifier. Never shared with third parties for marketing.
  • Password (hashed) — stored as an Argon2id hash. We cannot recover your plain-text password.
  • OpenRouter API key (encrypted) — if you choose to save your key in Account Settings, it is stored encrypted with AES-256-GCM. It is never returned to the browser or logged.
  • Account creation timestamp — used to display your "Member Since" date.

Cleaning session data

  • Session title — the optional label you give a cleaning session.
  • Original filename and file type — stored as metadata so you can identify sessions in History.
  • Row counts (before and after) — a summary statistic stored with each session.
  • Column context strings — the optional descriptions you provide for individual columns. Stored as a JSON object linked to the session.
  • Generated SQL query — the DuckDB SQL produced by the AI. Stored so you can review it later in History.
  • AI reasoning text — the model's explanation of its cleaning decisions. Stored with the session.
  • Cleaned file (Parquet) — the output of the cleaning pipeline, stored in a private Supabase Storage bucket. Accessible only to you via your authenticated session.

Technical data

  • JWT session token — stored in your browser's localStorage. Expires after 24 hours (configurable).
  • Email address (localStorage) — cached in the browser for display in the navigation bar.
Data Practices

Data We Do Not Collect

We want to be explicit about what Dafine does not do:

  • We do not store your uploaded raw files. Your original uploaded file is written to a temporary location on the server and deleted immediately after cleaning, inside a finally block that runs even if an error occurs.
  • We do not send your raw data to any AI. The AI prompt contains only statistical summaries (null counts, value distributions, column types). Your actual row data is never included in any API call.
  • We do not use tracking cookies. Dafine does not use analytics cookies, advertising cookies, or any third-party tracking scripts.
  • We do not sell your data. Your data is never sold, rented, or traded to any third party for any purpose.
  • We do not collect payment information. Dafine does not process payments. Billing for AI model usage is handled entirely between you and OpenRouter.
  • We do not log your file contents. Application logs capture request metadata (endpoint, timestamp, HTTP status) but not file contents or query results.
Data Practices

How We Use Your Data

DataPurposeLegal basis
Email address Account login and identification Contract (providing the service)
Password hash Authenticating your login Contract
Encrypted API key Decrypted server-side to call OpenRouter on your behalf Contract
Session metadata (title, filename, row counts) Displayed in your History page; lets you identify past sessions Contract
Generated SQL & AI reasoning Displayed in History detail view for your review and audit Contract
Cleaned Parquet file Stored so you can re-download from History at any time Contract
Column context strings Passed to the AI prompt to improve cleaning quality; stored with the session Contract

We do not use any of your data for advertising, profiling, model training, or any purpose not listed above.

Infrastructure

Data Storage & Retention

Where your data is stored

  • Account data & session metadata — stored in a Supabase (PostgreSQL) database. Supabase infrastructure is hosted on AWS. Data is encrypted at rest.
  • Cleaned files — stored in a private Supabase Storage bucket. Files are only accessible via authenticated, signed requests from the backend.
  • Dashboard configurations — stored only in your browser's localStorage. They never leave your device.

How long we keep your data

  • Account data — retained for as long as your account exists. Deleted upon account deletion (see Your Rights).
  • Cleaning sessions & stored files — retained indefinitely until you delete them from the History page. Each deletion removes both the database record and the Parquet file from storage.
  • Uploaded raw files — retained for zero time. Deleted from server memory immediately after processing.
  • JWT tokens — expire after 24 hours. No server-side token revocation list is currently maintained.
Self-hosted instances

If you are running your own Dafine deployment, retention is entirely determined by your own Supabase configuration and infrastructure choices.

Third Parties

Third-Party Services

Dafine integrates with a small number of third-party services. Here is exactly what is shared with each:

ServiceData sharedPurpose
Supabase Account data, session metadata, cleaned Parquet files Hosted database and file storage. Data subject to Supabase Privacy Policy.
OpenRouter Statistical column profile (no raw data). Your decrypted API key is sent in the Authorization header of each AI call. AI model routing. Data subject to OpenRouter Privacy Policy.
Railway (deployment) Backend application and environment variables (including .env secrets) Cloud hosting for the backend server. Data subject to Railway Privacy Policy.
Google Fonts Browser IP address (standard web font request) Loading DM Mono and Syne typefaces. Subject to Google Privacy Policy.
jsDelivr (CDN) Browser IP address (standard CDN request) Loading Chart.js from CDN.

No other third-party services receive any data from Dafine. In particular, there are no analytics providers, advertising networks, or social media tracking pixels.

Your Rights

Your Rights & Controls

You have control over your data. Here is what you can do directly within the Dafine interface:

  • View your account data — your email and account creation date are shown on the Account Settings page.
  • Change your password — available in Account Settings at any time.
  • Update or remove your API key — you can paste a new key to overwrite the stored one at any time.
  • Delete individual cleaning sessions — the delete button in History removes the database record and the stored Parquet file from Supabase Storage permanently.
  • Download your cleaned data — available from the History page at any time while the session exists.
  • Delete your dashboard configurations — available in the Dashboard History tab; clears from your browser's localStorage.
  • Log out — clears your JWT token and cached email from localStorage on this device.

Account deletion

Self-service account deletion is not yet implemented in the UI. To request full deletion of your account and all associated data, contact us using the details in the Contact section. We will process deletion requests within 30 days.

Data portability

Your cleaned datasets can be downloaded at any time from the History page in CSV format. Column context and session metadata can be viewed in the History detail panel. If you need a machine-readable export of all your stored data, contact us.

GDPR / regional rights

If you are located in the European Economic Area (EEA), the United Kingdom, or another region with specific data protection laws, you may have additional rights including the right to access, rectification, erasure, restriction of processing, and the right to lodge a complaint with your local supervisory authority. Contact us to exercise these rights.

Security

Security

We take reasonable steps to protect your data:

  • Passwords — hashed with Argon2id. Never stored in plain text.
  • API keys — encrypted at rest using AES-256-GCM with a server-side master key. Never stored unencrypted, never logged, never returned to the browser.
  • Session tokens — HS256 JWTs with a 24-hour expiry, signed with a secret key set by the operator.
  • Transport — all communication between the frontend and backend uses HTTPS in the hosted deployment.
  • Database access — the backend uses Supabase's service role key, which is only present in server-side environment variables and never exposed to the browser.
  • Uploaded files — never persisted. Processed in a temp file and deleted in a finally block.

No system is completely secure. If you discover a security vulnerability, please disclose it responsibly by contacting us privately before making it public.

Browser Storage

Cookies & Browser Storage

Dafine does not use cookies. It uses browser localStorage for three purposes:

KeyContentsCleared on
dafine_token Your JWT session token (expires after 24 hrs) Logout or manual clear
dafine_email Your email address (display only in nav bar) Logout or manual clear
dafine_user_id Your user ID integer Logout or manual clear
dafine_dashboards Up to 30 saved dashboard configurations (chart type, axes, filters, title) Manual delete from Dashboard History, or browser data clear

You can clear all of this data at any time by clicking Logout (which clears the first three keys) or by clearing your browser's localStorage for the Dafine domain.

Third-party resources loaded by Dafine (Google Fonts, jsDelivr CDN) may set their own cookies or use other browser storage. We do not control these. Refer to their respective privacy policies.

Eligibility

Children's Privacy

Dafine is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has created an account, please contact us and we will delete the account promptly.

Open Source

Open Source Notice

Dafine's source code is publicly available under the MIT License. Anyone can inspect the code to verify the data practices described in this policy.

If you fork and self-host Dafine, you become the data controller for your own deployment. This Privacy Policy applies only to the reference hosted instance. As operator, you are responsible for updating this policy to reflect your own infrastructure and data flows before publishing it to your users.

The MIT License permits commercial and private use. It does not override your legal obligations under applicable data protection law. Running Dafine on data that belongs to others (e.g. your customers) means you must have a lawful basis for processing that data under the laws of your jurisdiction.

Updates

Changes to This Policy

We may update this policy from time to time. When we make significant changes, we will update the "Effective" date at the top of this page. Continued use of Dafine after a policy change constitutes acceptance of the new terms.

We encourage you to review this page periodically. Because Dafine is open source, all historical versions of this policy are visible in the project's git history.

VersionDateSummary of changes
1.0 15 June 2025 Initial policy published.
Contact

Contact

For any questions about this Privacy Policy, to request data deletion, or to report a security concern, please reach out:

Michael Vincent Sebastian Handojo

Project maintainer, Dafine

GitHub github.com/your-username/dafine

We will respond to all privacy-related requests within 30 days.