Sia Makerlab
홈회사소개서비스포트폴리오공지사항문의하기

© since 2025 Sia Makerlab. All rights reserved.

사업자등록번호: 649-11-03282 | 대표: 이장욱

통신판매업신고번호: 제2025-충북제천-0264호

Sia Manager for Supabase

개인정보처리방침

Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.

개인정보처리방침v1.0

Privacy Policy

Last Updated: July 11, 2026

Effective Date: July 11, 2026

Revision: 1.0

Revision History

VersionDateChanges
1.0July 11, 2026Initial release

1. Introduction

This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the Sia Manager for Supabase mobile application (the "App").

The App is an Android ops and management console for the Supabase projects that you specify. It connects directly from your device to your Supabase projects. It does not require you to create an account, and we do not operate a server that stores your project details or your data. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.

2. Information We Collect

2.1 Information You Provide

The App is designed to function without an account or personal information. We do not collect your name, email address, phone number, or physical address.

To connect to a Supabase project, you provide its details — a project URL and one or more API keys (an anon key and/or a secret/service_role key) and, for Management API features on Supabase Cloud, a Personal Access Token. Keys and tokens are treated as opaque strings, and the project ref is derived from the URL. This configuration is stored locally on your device and is not collected by us.

2.2 Projects You Configure (Outbound Requests)

When you use the App, it communicates directly from your device to the Supabase endpoints you configure, across two API planes:

  • Data plane — requests to your project at <project>.supabase.co (REST, Auth, Storage, Realtime), authenticated with your API key. Available for both cloud and self-hosted projects.
  • Management API plane — requests to api.supabase.com, authenticated with your Personal Access Token. Available for Supabase Cloud projects only.

Your rows, users, files, SQL, logs, and their results travel between your device and your Supabase project — not through us. We operate no server and do not see, receive, or store your project URLs, keys, tokens, or data. You are responsible for ensuring you are authorized to access any project you connect to.

2.3 Information Stored on Your Device

The App stores the following data only on your device, in app-private storage (DataStore):

DataCollectedStoredSharedPurpose
Project connectionsYesDevice onlyNoProject URLs and options for the projects you configure
API keys & Management tokenYesDevice onlyNoAnon / secret keys and the Personal Access Token used to authenticate to your projects
Workspace dataYesDevice onlyNoSaved SQL workspace and similar in-app working data
App settingsYesDevice onlyNoTheme, read-only mode, screen-capture blocking, biometric app lock, and other preferences
Purchase stateYesDevice onlyNoCached "remove ads" entitlement (reconciled with Google Play)

This data is stored exclusively on your device, in the App's private storage. We do not have access to it, and it is never transmitted to our servers. Secret keys and the Management token in particular are stored only in this device's app-private DataStore; use the App only on trusted devices.

2.4 Screen-Capture Protection

To help keep sensitive information private, the App enables screen-capture blocking (Android FLAG_SECURE) by default, so project data is hidden in screenshots and in the recent-apps (recents) list. This is a device-side protection; no capture data is collected or transmitted.

2.5 Biometric App Lock

If you enable the biometric app lock, authentication is performed by the Android operating system on your device. The App never receives, stores, or transmits your fingerprint or other biometric data.

2.6 Clipboard

When you copy values within the App, the App may automatically clear the clipboard after a short interval to reduce the risk of sensitive data lingering. Clipboard contents are not collected or transmitted.

2.7 Local Notifications

On app launch, the App can detect projects that are paused or in a failed state and show a local status notification. This detection runs entirely on your device using the project data you configured — there is no Firebase Cloud Messaging (FCM), push server, or backend of ours involved.

2.8 Permissions

  • Internet (INTERNET): required to connect to the Supabase projects you configure and to serve ads.
  • Network state (ACCESS_NETWORK_STATE): used to detect network availability.
  • Notifications (POST_NOTIFICATIONS): used only to display the local project-status notifications described above. You may decline it.
  • Advertising ID (AD_ID): automatically merged from the Google AdMob SDK and used to serve ads (see Section 2.9).

The App does not request location, camera, microphone, or contacts permissions.

2.9 Advertising Data (Third-Party)

Unless you purchase the ad-removal option, the App displays advertising through Google AdMob. Our advertising partner may collect:

  • Advertising ID (Android Advertising ID)
  • Device information (device type, operating system version)
  • IP address
  • General location data (country/region level)
  • Ad interaction data

Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy

2.10 Information We Do NOT Collect

We explicitly do not collect:

  • Personal or contact information
  • Your project URLs, keys, tokens, or database, auth, or storage contents
  • Analytics or usage tracking data by us directly
  • Precise location data
  • Payment or card information (handled by Google Play)

3. How We Use Information

3.1 Local Data Usage

Data stored on your device is used locally to:

  • Establish the connections you configure and run your requests across the data and Management API planes
  • Remember your project connections and workspace data
  • Apply your settings, screen-capture blocking, biometric app lock, and preferences
  • Apply your ad-removal entitlement

3.2 Third-Party Data Usage

Data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase.

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We do not sell, trade, or rent your personal information to third parties.

4.2 Third-Party Service Providers

The App integrates the following third-party services, which handle data according to their own privacy policies:

ServicePurposePrivacy Policy
Google AdMobAdvertisinghttps://policies.google.com/privacy
Google User Messaging Platform (UMP)Ad consent managementhttps://policies.google.com/privacy
Google Play BillingProcess the one-time ad-removal purchasehttps://policies.google.com/privacy

Separately, the App communicates directly with the Supabase projects you specify (both <project>.supabase.co and api.supabase.com). Those projects and services are operated by you, by Supabase, or by parties you choose, and their handling of your connections and data is outside our control.

4.3 Legal Requirements

We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.

5. Data Retention

5.1 Local Data

Data stored on your device remains until you delete it within the App, clear app data in device settings, or uninstall the App.

5.2 Third-Party Data

Data collected by Google's advertising, consent, and billing services is retained according to their respective policies.

6. Your Rights and Choices

6.1 For All Users

You have the right to:

  • Access: View your data within the App
  • Delete: Remove project connections in the App, or clear app data or uninstall the App to remove all local data
  • Opt out of personalized ads: Manage ad personalization through your device's advertising settings or the UMP consent options

6.2 For Users in the EEA, United Kingdom, and Switzerland

Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service, contact that service directly.

6.3 Managing Consent

Manage advertising consent through:

  • In-App: privacy/consent options provided via Google UMP
  • Device Settings: Android Settings > Google > Ads

7. Data Security

We implement reasonable technical measures to protect data on your device:

  • API keys and the Management token are stored only in this device's app-private DataStore
  • Screen-capture blocking (FLAG_SECURE) is enabled by default, hiding sensitive information in screenshots and the recents list
  • An optional biometric app lock and automatic clipboard clearing provide additional protection
  • Data is stored only on your device; we operate no server and keep no copies
  • No cloud synchronization and no user accounts
  • Network access is used only to reach the Supabase projects you configure and to serve third-party advertising

8. Children's Privacy

The App is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.

9. International Data Transfers

Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.

11. Disclaimer of Liability

11.1 Third-Party Services

We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, and Google Play Billing, nor for the Supabase projects and services you choose to connect to.

11.2 Data Loss

We are not responsible for any loss of data stored locally on your device, including your project connections and workspace data.

11.3 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.

12. Governing Law

This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.

13. Contact Us

Sia Makerlab

  • Email: sia@siamakerlab.com
  • Website: https://siamakerlab.com

For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.


Summary of Data Practices

Data TypeCollectedStoredSharedPurpose
Project connections & settingsYesDevice onlyNoConnecting to your projects and preferences
API keys & Management tokenYesDevice only (app-private DataStore)NoAuthenticating to your projects
Project data (rows, users, files, SQL, logs)No (sent device → your Supabase projects)Not retainedOnly with the projects you specifyRunning your operations
Purchase stateYesDevice onlyNoAd-removal entitlement
Advertising IDYes*By GoogleWith GoogleAdvertising
Personal infoNoN/ANoN/A

*Collected by third-party services (Google), not by us directly.


This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.

Sia Manager for Supabase 제품 페이지로 돌아가기