Security & Subprocessors
Last updated: July 19, 2026
This page states, plainly, what RefreshRadar's app registration can do inside your Power BI tenant, which outside companies (subprocessors) touch your data and why, and how long anything is kept.
What our app can do in your tenant
RefreshRadar's app registration holds the Contributor role on the workspaces you grant, with read-only behavior on your refresh metadata — every Power BI request we build is a GET. An audited, account-scoped call log records every request we make (with tokens redacted), viewable from your dashboard.
Subprocessors
The following companies handle data on our behalf in order to run RefreshRadar:
| Subprocessor | What it processes | Retention |
|---|---|---|
| Supabase | US-hosted Postgres database (your account, tenant, workspace, dataset, and refresh-event data) plus encrypted daily backups. | Backups age out within Supabase's 7-day backup-retention window; no PITR add-on is purchased. |
| Vercel | Application hosting and cookieless Web Analytics (no cross-site tracking). | Retained for the life of the deployment, under Vercel's standard hosting/analytics data handling. |
| Anthropic | AI failure-narrative generation — the classification input is the Power BI error code plus a small amount of surrounding context. | Handled under Anthropic's standard API terms. We have not verified a special data-retention or training-exclusion agreement, so none is claimed here. |
| Resend | Transactional email delivery for alert notifications. | Retained per Resend's standard operational delivery-log retention. |
| Stripe | Billing and payment processing (subscriptions, invoices, the hosted Customer Portal). | Stripe retains transaction and tax records per its own legal and regulatory obligations, independent of your RefreshRadar account status. |
| Sentry | Error monitoring for application exceptions (expected 429 / transient-retry events are excluded and are never sent to Sentry). | Retained per Sentry's standard error-event retention window. |
| cron-job.org | External uptime/heartbeat monitoring of RefreshRadar's own polling service. | Retained per cron-job.org's standard monitoring-log retention. |
| Azure Key Vault | Secure storage of RefreshRadar's single multi-tenant application credential (the signing certificate). | Retained for the operational life of the credential; holds no customer data. |
Retention & deletion
Durable refresh history is retained while you are a customer (a paid feature; the free tier keeps 7 days of history). When you disconnect a tenant or close your account, your primary data is purged on offboard within days, with an audit entry recorded for the deletion. Residual copies in Supabase's encrypted daily backups age out within the 7-day backup-retention window, so every copy — primary and backup — is eliminated within 30 days.
Data Processing Addendum
Data Processing Addendum (DPA): a formal DPA isn't published yet — request one and we'll provide it.
Questions
Email hello@refreshradar.com with any security or data-handling question.