Security & Subprocessors

Last updated: July 19, 2026

This page states, plainly, what RefreshRadar's app registration can do inside your Power BI tenant, which outside companies (subprocessors) touch your data and why, and how long anything is kept.

What our app can do in your tenant

RefreshRadar's app registration holds the Contributor role on the workspaces you grant, with read-only behavior on your refresh metadata — every Power BI request we build is a GET. An audited, account-scoped call log records every request we make (with tokens redacted), viewable from your dashboard.

Subprocessors

The following companies handle data on our behalf in order to run RefreshRadar:

SubprocessorWhat it processesRetention
SupabaseUS-hosted Postgres database (your account, tenant, workspace, dataset, and refresh-event data) plus encrypted daily backups.Backups age out within Supabase's 7-day backup-retention window; no PITR add-on is purchased.
VercelApplication hosting and cookieless Web Analytics (no cross-site tracking).Retained for the life of the deployment, under Vercel's standard hosting/analytics data handling.
AnthropicAI failure-narrative generation — the classification input is the Power BI error code plus a small amount of surrounding context.Handled under Anthropic's standard API terms. We have not verified a special data-retention or training-exclusion agreement, so none is claimed here.
ResendTransactional email delivery for alert notifications.Retained per Resend's standard operational delivery-log retention.
StripeBilling and payment processing (subscriptions, invoices, the hosted Customer Portal).Stripe retains transaction and tax records per its own legal and regulatory obligations, independent of your RefreshRadar account status.
SentryError monitoring for application exceptions (expected 429 / transient-retry events are excluded and are never sent to Sentry).Retained per Sentry's standard error-event retention window.
cron-job.orgExternal uptime/heartbeat monitoring of RefreshRadar's own polling service.Retained per cron-job.org's standard monitoring-log retention.
Azure Key VaultSecure storage of RefreshRadar's single multi-tenant application credential (the signing certificate).Retained for the operational life of the credential; holds no customer data.

Retention & deletion

Durable refresh history is retained while you are a customer (a paid feature; the free tier keeps 7 days of history). When you disconnect a tenant or close your account, your primary data is purged on offboard within days, with an audit entry recorded for the deletion. Residual copies in Supabase's encrypted daily backups age out within the 7-day backup-retention window, so every copy — primary and backup — is eliminated within 30 days.

Data Processing Addendum

Data Processing Addendum (DPA): a formal DPA isn't published yet — request one and we'll provide it.

Questions

Email hello@refreshradar.com with any security or data-handling question.