SupahID Privacy Policy

This policy explains what SupahID handles when you join, verify, sign in, shape your Persona, and use your account.

Information SupahID processes

SupahID processes invitation state, the bounded Stripe verification outcome, alias and account setup, browser authentication ceremonies, owner-authorized Persona changes, and support requests. Canonical identity, authentication metadata, sessions, and the Persona projection remain separate from the public presentation layer.

Identity verification

Stripe receives the government-ID and live-selfie submission. Supah stores only provider, external session reference, status, and verification time. Supah does not request or store the submitted images, expanded report, document fields, selfie details, or biometrics.

Authentication

Supah stores password verifiers and public WebAuthn credential metadata. Passkey private keys stay with the authenticator. SupahID's account cookie contains short-lived onboarding state and an opaque customer session.

Personas

Personas begin private. If you publish, the selected Persona fields, connections, Verified Human mark, and bounded JSON projection become publicly available. Search engines and other people may copy information after publication.

Website analytics

With your permission, the public supah.id site uses its own Google Analytics measurement tag to understand aggregate page visits, traffic sources, approximate location, and browser or device information. Google Analytics may set first-party cookies after you allow analytics. The tag is separate from the tag used on developer.supahcomputer.com, is not loaded on account pages, and is configured without advertising personalization or Google Signals. Public Persona aliases, names, and query strings are replaced or omitted from analytics page and referrer fields. You can decline analytics or change your choice at any time using the Privacy choices control. Learn more about how Google uses information from sites that use its services.

Personal intelligence on iPhone

When you use Chat, messages you send and conversation context selected on your iPhone are processed by the configured OpenAI service to provide answers. You review this processing before first use. Supah's execution services do not store prompts, answers, or calendar payloads. The model provider may apply its own retention and abuse-monitoring policies; this is not a promise of zero retention by every provider. Supah retains content-free authorization, usage, outcome, and timing records.

Your continuous conversation and source labels are encrypted on your iPhone and excluded from backup. Messages expire 30 days after they are sent; sending new messages does not extend older messages. Expired messages are excluded from display and outgoing context. Their encrypted storage is cleaned up while Supah is active or the next time it can unlock that account's protected history. Signing out locks the remaining history until the same account signs back in. You can delete all messages in the app at any time. Losing the device or its encryption key may make history unrecoverable. Private conversations are never added automatically to public Persona.

Where Calendar is enabled, you choose calendars on this iPhone and separately approve sharing their next-seven-days busy times with OpenAI. While Calendar is on, each message uses a fresh device reading. Event details and calendar account names remain on the iPhone; Supah never changes events. Device read time does not establish upstream synchronization freshness. Turning Calendar off excludes earlier conversation context from future requests; removing Calendar access also withdraws Supah permission. Offline withdrawal remains pending until acknowledged. iOS Calendar permission is managed separately in Settings. Raw availability snapshots are not retained; dated source summaries expire with their messages. Learned memory and cloud provider connections remain disabled. The conversation uses the newest complete exchanges within the request limit; it does not give the agent permanent memory of all past messages.

Retention and deletion

Supah retains identity and authentication records according to its operating and legal obligations. Account deletion revokes sessions and removes customer-visible profile and authentication material under the deletion policy. Some security or legal audit records may be retained where required.

Your choices and contact

You control Persona publication and may request access, correction, or deletion by contacting privacy@supah.dev. Account and Persona controls are available in the owner portal.