Skip to content
RowAttest
Methodology Verify a report API & MCP GitHub Log in Create account

Legal

RowAttest Privacy Policy

Effective date: October 10, 2026

RowAttest (rowattest.com and app.rowattest.com) is operated by RW Digital Ventures LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA ("we", "us"). This policy says what personal data we collect, why, who processes it for us, how long we keep it, and how you take it back. Questions: info@rowattest.com.

It has two parts. Part A is about the public website. Part B is about the app, your account, the projects you connect, the tests you run and the reports you buy. If you only read the website, Part A is all that applies to you.

Part A — The website (rowattest.com)

A1. Waitlist email. The website's waitlist form was removed when the alpha opened. If you joined the waitlist before that, we store the email address you gave us. We use it to tell you that RowAttest is open and how to create an account. Nothing else. Legal basis: your consent. You can withdraw it at any time; every waitlist email includes a way to unsubscribe.

A2. Analytics. The website uses Plausible Analytics, which is cookieless and collects aggregate information only: page views, referral source, browser and device type, and country. It does not use cookies, does not track you across sites, and does not build personal profiles. The app (app.rowattest.com) has no analytics at all — see B8.

A3. Technical and security logs. Our website host (Cloudflare) processes IP addresses and request metadata to deliver the site and block abuse. Legal basis: our legitimate interest in running a secure website.

Part B — The app, your account and your projects

B1. Your account. When you create an account we store your email address, a hashed form of your password (we never see or store the password itself), the time you accepted the Terms of Service, the time the account was created, whether your email address is confirmed, and the time of your last sign-in. If you sign in with GitHub, GitHub sends us your GitHub user id, your username, your name if you have set one, a link to your profile picture and the email addresses on your GitHub account. We store the id, the username, the name, the picture link and your primary email address, not your other addresses. Our authentication provider also keeps a record of your sign-in sessions, including the IP address and browser they came from (see B7). Signing in sets a login cookie in your browser; it is used only to keep you signed in and is not used for tracking. If you create RowAttest API keys, we store each key's name, its first 12 characters (so you can tell your keys apart), a hash of the key (we cannot recover the key itself), the time it was created and the time it was last used. Runs started with a key record the key's name and, if your tool sends one, a hash of its idempotency key. Legal basis: performing our contract with you.

B2. The projects you connect. To test a project we need access to it. Connecting by hand, you give us the project URL, two Supabase API keys and a database connection string. Connecting with Supabase, you approve RowAttest on Supabase's consent screen and give us the project's database password; from Supabase we receive an authorization for your organization and the list of its projects (reference, name, region, status), from which you choose one. We store the project reference, the name you give it (or, when connected with Supabase, the project's name in Supabase), how it was connected, and the credentials or authorization, encrypted. The project list we read at connect time is kept only while you are choosing a project and is cleared when the choice is saved or expires. How credentials are protected, used and deleted is described in full at rowattest.com/credentials; that page is part of this policy. Legal basis: performing our contract with you.

B3. Test runs. When you start a run we record when it ran, its status, which kind of Supabase API key the run used, and the results: the names of the tables, columns, policies and storage buckets in your project that were checked, the outcome of each check, and the engine's notes about what was and was not evaluated. For each check the report records which test identity was used, the operation and the table or bucket it targeted, the outcome on each test path and the verdict, a short note that can quote an error message from your project's API, and a fingerprint of the detailed record of that check. It does not store the contents of the rows it reads. The detailed records of each check and the run's other working files are deleted when the run finishes. The full report is kept in an encrypted archive for 30 days after the run so that you can buy a signed copy; after that it is deleted. If a payment dispute about that run is open, the archive is kept until the dispute is settled. When you connect a project, save its database password, ask for a fit check, confirm your access model or start a run, RowAttest also records a fit check: the names of the tables and storage buckets it found, for each table whether RowAttest can test it and, where it cannot, the reason, and the access model it read. Fit checks made before RowAttest read an access model record instead, for each table and bucket, the shape RowAttest recognized and the evidence for it. Fit checks are kept until you delete the project or your account is closed. The access model is RowAttest's reading of how each table in your project is owned: by an organization, by one user, through a parent row, open to everyone, open to all signed-in users, or not sure. For each table it records that answer, the columns, tables, keys and policy names the answer rests on, whether RowAttest detected it or you confirmed it, and when you confirmed it. Each run records the access model it used; the report embeds that model and a SHA-256 fingerprint of it. Access model versions you confirm are kept until you delete the project or your account is closed. RowAttest is for staging projects only (Terms §4). Legal basis: performing our contract with you.

B4. Payments. Signed reports are paid for through Stripe, which acts as the merchant of record; your card statement begins with LINK.COM*. Stripe collects your payment details and billing information directly on its own pages; we never receive your card number. To start a checkout we give Stripe your account email address and your account identifier, and we keep the customer identifier Stripe assigns to you. We also keep a record of the purchase: the payment identifiers, the amount and currency, its status (paid, refunded, disputed) and the time of each change, linked to your account and the run it covers. Stripe sends you the receipt. Legal basis: performing our contract with you, and our legal duty to keep financial records.

B5. Signed reports and verify pages. A signed report is a PDF that only you receive; the API also gives you a JSON copy of the same report. Its public verify page at rowattest.com/verify shows a separately signed summary: the report ID, the date, the result totals, the coverage statement, a SHA-256 fingerprint of the full report and, for reports that embed an access model, that model's SHA-256 fingerprint, how many of its entries RowAttest detected and how many you confirmed or declared, and how many tables the report covered. The verify page shows no name, email address, project reference or credential. Verify pages stay online after the 30-day archive is deleted and after you close your account, because the people you gave a report to must still be able to check it (Terms §7). Anyone with the link can see the summary; you acknowledge this when you buy the report.

B6. Emails we send you. The app sends three kinds of automatic email, all delivered through our authentication provider by Resend: the confirmation of your email address when you sign up, a password-reset link when you ask for one, and a notice when your password has been changed. Anything else comes from a person. If something goes wrong with your account or stored credentials (for example, if we ever have reason to believe stored credentials were exposed — see rowattest.com/credentials), or when our terms or this policy change materially, we email you from info@rowattest.com. Purchase receipts come from Stripe. We do not send marketing email to app accounts.

B7. Logs and security. Our app host (Vercel) keeps request logs — IP address, browser type, the page or endpoint requested and the time — to run the service and investigate abuse. Our authentication provider (Supabase) keeps records of sign-ins and sign-up attempts, including IP address and browser type. We rate-limit sign-in, sign-up and other sensitive actions; to do so we record each attempt that goes through — for sign-in, sign-up, password-reset requests and API or MCP requests that need a key but carry no valid one, the IP address it came from — and delete those records automatically once the limit's time window has passed, normally within about two hours. Our worker, which executes runs, writes an operational log for our own use. It never contains credentials or the contents of your data; it can contain your project's reference, the names of tables, columns and buckets in your project, the run's marker and counts from a run, and run errors are recorded as fixed, pre-written messages. Legal basis: our legitimate interest in running a secure service and preventing abuse.

B8. What we do not do. We do not sell personal data and do not share it for advertising. The app contains no analytics script, no advertising tracker and no third-party error-reporting tool. We do not use your project's data, your results or your reports to train AI models, and we do not pass your credentials to anyone; the only services that touch your data are the processors in B9, each only to provide its service to us.

B9. Who processes data for us.

  • Supabase — database and authentication hosting for the app (United States, us-east-1), and database hosting for the website waitlist. When you connect with Supabase, Supabase also acts on its own account: it shows you the consent screen and may email your organization's owner that RowAttest was authorized.
  • Vercel — hosting for the app (United States), with edge locations worldwide that handle your login cookie (see B10).
  • Stripe — payments, as merchant of record (see B4).
  • Resend — delivery of the emails described in B6.
  • Cloudflare — hosting, content delivery, DNS and security for the website.
  • Plausible Analytics — aggregate, cookieless analytics for the website only.

Our worker runs on hardware we control in the United Arab Emirates (see B10). We have no analytics, advertising or data partners.

B10. Where your data is. Your account, projects, runs and reports are stored in the United States (Supabase, us-east-1; Vercel, Washington, D.C. region). Two things happen elsewhere. Vercel runs the small piece of code that reads and refreshes your login cookie at edge locations around the world, close to wherever you are. Our worker — the machine that decrypts your stored credentials for the duration of a run or a fit check and executes the tests — runs on hardware we control in the United Arab Emirates. If you are in the EEA, the UK or Switzerland, your data is therefore transferred to the United States and the United Arab Emirates. Our processors rely on standard contractual clauses or an equivalent lawful mechanism; the transfer to our own worker is necessary to perform the contract you asked for.

B11. How long we keep it.

  • Account data: until you close your account.
  • Project credentials and authorizations: until you delete the project, or your account is closed — then hard-deleted at once.
  • RowAttest API keys: until you revoke them (the record is deleted at once) or your account is closed.
  • Run results (B3): until you delete the project or your account is closed.
  • Fit checks and access model versions (B3): until you delete the project or your account is closed.
  • Signed reports you bought (the full report and its PDF): kept indefinitely with their public summaries; you can download the PDF again while your account is open.
  • Full report archive: 30 days after the run, or until an open payment dispute is settled.
  • Purchase records and your Stripe customer identifier: as long as tax and accounting law requires.
  • Rate-limit records: deleted automatically once the limit's time window has passed, normally within about two hours.
  • Signed public summaries and verify pages: kept indefinitely by design; they contain no personal data.
  • Website waitlist emails: until launch communications are complete or you ask us to delete yours.
  • Logs: our providers' standard retention periods.

B12. Your rights and how to close your account. Email info@rowattest.com to access, correct, export or delete your data, or to object to a use of it. To close your account, email us from the account's address; we then hard-delete your stored credentials, your connected projects and your run results; signed reports you bought are kept (B11). Purchase records are kept as the law requires, and signed public summaries stay online (B5). If you are in the EEA or UK you have the rights set out in the GDPR, including the right to complain to your supervisory authority. If you are a California resident: we do not sell or share personal information as those terms are defined in the CCPA/CPRA, and you may exercise your rights by email.

B13. Children. RowAttest is for adults. The website is not directed to children under 16; the app requires you to be at least 18 (Terms §2). We do not knowingly collect children's information.

B14. Changes. If this policy changes, the new version is posted at rowattest.com/privacy and app.rowattest.com/privacy with a new effective date. Material changes that affect app accounts are announced by email at least 14 days before they take effect, the same way as changes to our Terms.

← Back to RowAttest
Privacy Policy Terms of Use Cookie Policy Credential handling Methodology App API description GitHub

© 2026 RW Digital Ventures LLC · info@rowattest.com