Last updated: August 15, 2026
This agreement is part of the Terms of Service and governs the billing data you import into Kometrics. For that data you are the controller and Fields Apps LTDA is the processor: we process it only to provide the service you configured, never for our own purposes.
Customers, subscriptions and invoices read from the billing providers you connect, and the metrics computed from them. Access to your providers is read-only. If your workspace enables privacy mode, customer names are pseudonymized and emails dropped at ingest, before storage.
Data is encrypted in transit, workspaces are isolated at the database layer, and source credentials are stored server-side and never exposed to the browser. Privacy mode uses a per-workspace secret; deleting the secret makes the pseudonyms permanently unlinkable. Imported data is deleted within 30 days of disconnecting a source or closing the account.
These are the providers that can touch personal data while running the service, and what each one receives:
| Provider | Role | What it receives | Location |
|---|---|---|---|
| Cloudflare | Hosting, CDN and background job queues | All traffic to the service, including the data rendered on your pages | Global edge, primarily US |
| Supabase | Database and authentication | Your account, your workspaces and the imported billing data at rest | United States |
| Stripe | Billing for the Kometrics subscription | The paying account’s name, email and payment details (card data stays with Stripe) | United States |
| SendKit | Transactional email | Recipient name and email, workspace names, aggregate MRR figures in recap emails | United States |
| OpenRouter | AI model gateway behind Kometrics AI | Your questions and the figures needed to answer them, only when you use Kometrics AI | United States |
| Optional sign-in with Google | The OAuth handshake: email, name and profile id, only if you choose it | United States | |
| Plausible Analytics | Cookieless analytics on the public site only | Page views, referrer, coarse location. Never sees the app or your imported data | European Union |
Kometrics AI runs through OpenRouter, which routes to the configured model provider; the underlying model can change, OpenRouter as the gateway does not. Currency reference rates come from the Brazilian Central Bank and the Frankfurter API, which receive dates and currency codes only, never personal data.
Most processing happens in the United States. Transfers rely on the safeguards in each provider's own data processing terms, including standard contractual clauses where they apply under GDPR and LGPD.
We update this page before a new subprocessor starts handling personal data, and announce material changes by email. If you object to an addition, you can export your data and close the account before it takes effect.
Questions about data processing: privacy@kometrics.com.