Data Processing Agreement

Last updated: August 15, 2026

1. What this is

This agreement is part of the Terms of Service and governs the billing data you import into Kometrics. For that data you are the controller and Fields Apps LTDA is the processor: we process it only to provide the service you configured, never for our own purposes.

2. What we process on your behalf

Customers, subscriptions and invoices read from the billing providers you connect, and the metrics computed from them. Access to your providers is read-only. If your workspace enables privacy mode, customer names are pseudonymized and emails dropped at ingest, before storage.

3. Security

Data is encrypted in transit, workspaces are isolated at the database layer, and source credentials are stored server-side and never exposed to the browser. Privacy mode uses a per-workspace secret; deleting the secret makes the pseudonyms permanently unlinkable. Imported data is deleted within 30 days of disconnecting a source or closing the account.

4. Subprocessors

These are the providers that can touch personal data while running the service, and what each one receives:

ProviderRoleWhat it receivesLocation
CloudflareHosting, CDN and background job queuesAll traffic to the service, including the data rendered on your pagesGlobal edge, primarily US
SupabaseDatabase and authenticationYour account, your workspaces and the imported billing data at restUnited States
StripeBilling for the Kometrics subscriptionThe paying account’s name, email and payment details (card data stays with Stripe)United States
SendKitTransactional emailRecipient name and email, workspace names, aggregate MRR figures in recap emailsUnited States
OpenRouterAI model gateway behind Kometrics AIYour questions and the figures needed to answer them, only when you use Kometrics AIUnited States
GoogleOptional sign-in with GoogleThe OAuth handshake: email, name and profile id, only if you choose itUnited States
Plausible AnalyticsCookieless analytics on the public site onlyPage views, referrer, coarse location. Never sees the app or your imported dataEuropean Union

Kometrics AI runs through OpenRouter, which routes to the configured model provider; the underlying model can change, OpenRouter as the gateway does not. Currency reference rates come from the Brazilian Central Bank and the Frankfurter API, which receive dates and currency codes only, never personal data.

5. International transfers

Most processing happens in the United States. Transfers rely on the safeguards in each provider's own data processing terms, including standard contractual clauses where they apply under GDPR and LGPD.

6. Changes to this list

We update this page before a new subprocessor starts handling personal data, and announce material changes by email. If you object to an addition, you can export your data and close the account before it takes effect.

7. Contact

Questions about data processing: privacy@kometrics.com.