Privacy Policy
Last updated: 20 July 2026
Who we are
StatSage (statsage.app) is a statistical analysis and reporting service operated from Singapore. This policy explains what personal data we collect, why, and the choices you have. It is written to comply with Singapore's Personal Data Protection Act (PDPA). Contact for anything privacy-related: hello@statsage.app.
What we collect
- Account data — your email address and a password (stored only as a secure hash; we cannot read it). Managed through Supabase, our authentication provider.
- Datasets you upload — the files you choose to analyse, plus the variable profiles, analysis settings and results derived from them.
- Analysis history — a log of which tests were run, with which software versions, for reproducibility.
- Payment data — handled entirely by Lemon Squeezy, our merchant of record. We never see or store your card details; we receive only your email, the product purchased, and the plan status needed to unlock your access.
- Technical data — standard server logs (IP address, timestamps) kept by our hosting providers for security and reliability.
We use no advertising trackers and no analytics cookies. The only thing stored in your browser is your sign-in session.
How AI is used with your data
StatSage uses AI (Anthropic's Claude models) for two narrow tasks: understanding your question and writing prose around verified results. By design, the rows of your dataset are never sent to any AI model. The AI receives only variable names, measurement levels, summary metadata, and the already-computed statistical results. All statistics are calculated by conventional statistical software on our own server. Anthropic does not train its models on data sent through its API.
Why we process your data
- To provide the service you asked for — profiling datasets, recommending and running analyses, generating reports.
- To operate your account — sign-in, email verification, password reset.
- To activate purchases and manage plan entitlements.
- To keep the service secure and diagnose faults.
We do not sell personal data, and we do not use your data or your datasets to train AI models.
Your responsibilities for uploaded data
You must have the authority to upload any dataset you analyse with StatSage — for example, ethics approval or consent covering research participants, or your organisation's permission for business data. Where possible, de-identify data before uploading; StatSage does not need names, identity numbers or contact details to do its job, and its profiler flags likely identifier columns so you can exclude them.
Retention and deletion
- Every dataset has a retention period you control (7, 30, 90 or 365 days; default 90). When it lapses, the dataset, its profile and its analysis history are deleted automatically.
- You can delete any dataset immediately from My Projects. Deletion is permanent and covers the data file, derived profiles and analysis logs.
- To delete your entire account and all associated data, email hello@statsage.app from your account address — we action such requests within 30 days.
Where your data lives (our processors)
StatSage runs on established cloud providers, each processing data only on our instructions: Railway (application hosting and dataset storage), Supabase (authentication), Vercel (website delivery), Anthropic (AI processing of metadata and results only), Lemon Squeezy (payments), and Resend (transactional email). Some of these providers process data outside Singapore; we rely on their contractual and security safeguards, consistent with the PDPA's transfer requirements.
Security
All traffic is encrypted in transit (HTTPS). Passwords are stored as salted hashes. Datasets are private to the account that uploaded them and are not accessible to other users. No system is perfectly secure; if we become aware of a data breach that is likely to result in significant harm, we will notify affected users and the PDPC as required by the PDPA.
Your rights
Under the PDPA you may request access to, or correction of, the personal data we hold about you, and you may withdraw consent for processing (which may mean closing your account). Email hello@statsage.app and we will respond within 30 days.
Changes
If we materially change this policy, we will update this page and note the new date above. Continued use of StatSage after a change means you accept the updated policy.
Questions? Contact hello@statsage.app · Terms of Service · Privacy Policy