Privacy policy
Last updated: 19 July 2026
What this service is
datavisual.studio is a free data-visualisation and research tool. You upload or connect data, build dashboards, and run research with AI models using your own provider keys.
What we store
Everything you create lives on the platform's own server — there is no external database and your content is never sold or shared with third parties:
- Your account record: name, email and an internal user id.
- Datasets you upload or import from a database/API connection.
- Dashboards, research reports and their chat/edit history.
- Your AI provider keys (OpenRouter, Gemini), stored with your account and shown back to you only in masked form.
- Basic usage events (e.g. "research run", "dashboard created") used for operating the service.
Authentication
Sign-in is handled by Clerk. Clerk processes your login credentials and session; we receive only your identity (id, email, name). See Clerk's own privacy policy for how they handle authentication data.
Where your data goes when you use AI features
AI features run on the keys you provide. When you run research or edit a dashboard by chat, the relevant question, data excerpts and context are sent to the AI providers you configured (OpenRouter and/or Google Gemini) to produce the result. If you connect a database, imports are read-only and the results are stored as files on our server.
Your control
You can delete your dashboards and research from the app at any time, and replace or remove your AI keys from the "AI keys" panel. To have your account and all associated data removed entirely, contact the maintainer via GitHub.
Cookies & product analytics
Two kinds of first-party cookies, and nothing more — no advertising, and no cross-site or third-party trackers:
- Authentication — the session cookies Clerk needs to keep you signed in.
- Product analytics — a first-party
dv_anon_idcookie (a random visitor id, kept ~12 months) plus a per-session id, so we can understand how the product is used and improve it.
Each analytics event records the event name(e.g. "landing_view", "dashboard_created"), those ids, the page path (never the query string), the referrer, and any UTM campaign parameters from your first visit. Events post to our own server — not to any third party.
What is never in an analytics event: your data. Dataset contents, cell values, questions, dashboard specifics and API keys are excluded by design — event metadata is the only thing sent. Analytics records are retained on our server and are not sold or shared.
You can turn product analytics off in this browser — we also honour Global Privacy Control:
Changes
If this policy changes, the date above is updated. Substantial changes will be noted on the landing page.