← Home

Privacy Policy

Last updated: April 3, 2026

1. Introduction

Covenant Data Solutions ("we", "us", "our") operates Pipelingo. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.

2. Information We Collect

Account Information: When you sign up, we collect your name, email address, company name, and role/title. This is stored in our authentication provider (Supabase).

Data Source Credentials: When you connect a data source (e.g., Snowflake), we collect your account identifier, username, password, database, and warehouse name. These credentials are encrypted at rest using Fernet (AES-128) encryption before being stored.

Pipeline Metadata: We collect pipeline execution metadata from your data warehouse, including query text, execution status, timestamps, duration, and bytes scanned. We do not access or store your underlying business data (table contents, row data, etc.).

AI Analysis Data: When you request an AI analysis, the pipeline query text and error information are processed by our AI provider (Anthropic). Generated analyses are cached in our database to avoid redundant API calls.

Usage Data: We log API requests for security and debugging purposes, including timestamps, endpoints accessed, and IP addresses.

3. How We Use Your Information

  • To provide and operate the Service (monitoring pipelines, generating analyses, sending alerts)
  • To authenticate your identity and manage your account
  • To connect to your data sources on your behalf
  • To improve the Service and fix bugs
  • To send you alerts and notifications you have configured
  • To communicate important changes to the Service or these policies

4. Data Security

We take the security of your data seriously:

  • Credential Encryption: All data source credentials are encrypted at rest using Fernet symmetric encryption (AES-128-CBC) before being stored in our database. Plaintext credentials are never stored.
  • Transport Security: All data in transit is encrypted using TLS/HTTPS.
  • Access Control: API endpoints are protected with JWT-based authentication. Organization data is isolated — members can only access data within their organization.
  • Rate Limiting: API endpoints are rate-limited to prevent abuse.
  • Infrastructure: Our Service is hosted on Railway with managed infrastructure and automatic SSL certificates.

5. Third-Party Services

We use the following third-party services to operate Pipelingo:

  • Supabase — Authentication and database hosting (stores account info, pipeline metadata, encrypted credentials)
  • Anthropic (Claude AI) — AI-powered pipeline failure analysis and stakeholder summaries
  • Railway — Application hosting and deployment
  • Snowflake — Your data warehouse (we connect on your behalf using your credentials)

Each third-party service has its own privacy policy. We encourage you to review them.

6. Data Retention

We retain your data for as long as your account is active. Pipeline run metadata and AI analyses are retained to provide historical health scores and avoid redundant API calls. When you delete your account or disconnect a data source, associated credentials are permanently deleted. Cached pipeline data may be retained for up to 90 days after account deletion for backup purposes.

7. Data Sharing

We do not sell your data. We share data only in these cases:

  • With third-party services listed above, solely to operate the Service
  • When required by law, regulation, or legal process
  • To protect the rights, safety, or property of Covenant Data Solutions or our users

8. Your Rights

You have the right to:

  • Access your personal data stored in the Service
  • Correct inaccurate personal data
  • Delete your account and associated data
  • Disconnect data sources at any time, immediately deleting stored credentials
  • Export your pipeline data

To exercise these rights, contact us at privacy@pipelingo.com.

9. Cookies

We use essential cookies for authentication session management (Supabase auth tokens). We do not use tracking cookies, analytics cookies, or third-party advertising cookies. We store your theme preference (light/dark mode) in browser localStorage.

10. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via the email associated with your account. The "Last updated" date at the top indicates when the policy was last revised.

12. Contact

For questions or concerns about this Privacy Policy or your data, contact us at:
Covenant Data Solutions
Email: privacy@pipelingo.com