Privacy Policy

Last updated: July 20, 2026

This policy covers the RefreshRadar product: the app you sign into and connect your Power BI to. RefreshRadar is operated by an independent sole proprietor (an individual, not a registered company). In plain terms: we read the refresh metadata of the Power BI you connect (never the data inside your datasets), we use it to alert you and explain failures, we don't sell it, and you can delete it at any time by disconnecting or closing your account.

Who we are

RefreshRadar ("we", "us") is a Power BI dataset-refresh monitoring service operated by an independent sole proprietor (an individual, not a registered company); you can request the operator's legal contact details at any time by emailing hello@refreshradar.com. For your organization's Power BI refresh metadata you are the data controller and we act as your processor; for your own account and login details we are the controller. A Data Processing Addendum (DPA) is available on request: email hello@refreshradar.com.

What we collect, and why

Account and identity. When you sign in with Microsoft, we receive your email address and basic profile from Microsoft (via Supabase Auth), and we store your account/organization name. To verify that you are a tenant administrator when you connect Power BI, we store an immutable Microsoft directory identifier: your tenant ID and object ID. We identify your account by those directory IDs, not by your email address. We use this to sign you in, secure your account, and confirm admin consent.

Power BI refresh metadata. For each workspace and dataset you connect, we read and store refresh metadata: the connected tenant/organization's directory name, workspace and dataset names, refresh status, start/end times, the refresh schedule, and (when a refresh fails) the Power BI error code and error detail (serviceExceptionJson). We do not read the data inside your datasets; your report data never leaves Power BI. We use this to detect failures, build your status board and history, and explain what broke.

Alert settings. The email addresses and/or webhook URLs you ask us to send alerts to. We use these only to deliver the alerts you configure.

Billing. If you subscribe to a paid plan, payment is handled by Stripe. We store your plan and a Stripe customer/subscription reference so we can bill you and show your plan. We never see or store your card number.

Diagnostics and usage. To keep the service reliable we collect application error events (with sensitive strings redacted before they leave our systems), an audited log of the Power BI API calls we make on your behalf (with access tokens redacted), and privacy-friendly, cookieless web analytics that do not track you across other sites. We use a strictly-necessary cookie to keep you signed in; we don't use advertising or cross-site tracking cookies.

AI-generated failure explanations

When a refresh fails with an error code that isn't in our built-in catalog, we send the error code plus a small amount of surrounding context to our AI subprocessor (Anthropic) to generate a plain-English root cause and suggested fix. Source identifiers are redacted before egress, and a catalog-only mode that turns the AI path off entirely is available. We don't claim any special training-exclusion or data-retention arrangement with our AI subprocessor; see our Security page at /security for exactly what is and isn't guaranteed.

Legal bases (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the monitoring service you signed up for); our legitimate interests (to secure, operate, and improve the service and prevent abuse), balanced against your rights; and consent where the law requires it, including the Microsoft administrator consent you grant when you connect a tenant, which you can withdraw at any time by disconnecting.

Who we share it with (subprocessors)

We do not sell your personal data and we do not share it for anyone else's marketing. We use the following subprocessors to run RefreshRadar: Supabase, Vercel, Anthropic, Resend, Stripe, Sentry, cron-job.org, Azure Key Vault. Each one, what it processes, and how long it keeps data is listed on our Security page at /security. We may also disclose data if required by law or to protect our rights, users, or the public.

Where it is stored, and international transfers

Your primary data is stored in our Postgres database (Supabase), hosted in the United States. If you access RefreshRadar from the EEA, the UK, or elsewhere, your data is processed in the United States; where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses for that transfer. Ask us at hello@refreshradar.com for details of the safeguards in place.

How long we keep it

Durable refresh history is retained while you're a customer (a paid feature; the free tier keeps 7 days of history). When you disconnect a tenant or close your account, your primary data is purged on offboard within days, with an audit entry recorded for the deletion, and access is revoked immediately. Residual copies in Supabase's encrypted daily backups age out within the 7-day backup-retention window, so every copy, primary and backup, is eliminated within 30 days. Billing and tax records held by Stripe are kept as long as the law requires.

How we protect it

Our app registration holds the Contributor role on the workspaces you grant, with read-only behavior on your refresh metadata: every Power BI request we build is a GET. Accounts are isolated at the database level so one customer can never read another's data, access tokens and secrets are redacted from our logs, and our single application credential is held in Azure Key Vault. Our Security page at /security covers our security practices and subprocessors. No online service can promise perfect security. Rather than make sweeping "we store nothing about you" promises, we tell you plainly what we hold (the items listed above) and protect it.

If we ever discover a security breach affecting your personal data, we'll notify you without undue delay (and, where you are the controller, in time for you to meet your own obligations) with what happened, what's affected, and what we're doing about it.

Your rights and choices

Depending on where you live, you have rights to access, correct, delete, export, or restrict your personal data, to object to certain processing, and to withdraw consent. You can delete most data yourself at any time: disconnect a tenant to remove its metadata, or close your account to delete it all (subject to the deletion timeline above). To exercise any right, email hello@refreshradar.com and we'll respond within the time the law allows. You also have the right to complain to your local data protection authority.

If you are a California resident (CCPA/CPRA): we do not sell or "share" your personal information, and we will not discriminate against you for exercising your rights. You may request to know, delete, or correct your personal information using the same contact address.

Children

RefreshRadar is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email hello@refreshradar.com and we'll delete it.

Changes to this policy

We may update this policy as the product evolves. When we do, we'll change the "last updated" date above, and for material changes we'll give you reasonable notice (for example, by email or an in-app notice) before they take effect.

Contact us

RefreshRadar. Email hello@refreshradar.com with any privacy question or to exercise a right below.