Privacy Policy

Your learning data should work for you.

This policy explains what SupaSQL collects, why we use it, who processes it, and the choices available to you.

Effective: August 19, 2026 · Last updated: August 19, 2026

1. Scope and operator

This Privacy Policy applies to the SupaSQL iOS application, its API, and the SupaSQL support and legal pages (together, the “Service”). SupaSQL is operated by Utivilla (“SupaSQL,” “we,” “us,” or “our”).

Questions or privacy requests can be sent to utivillainc@gmail.com.

2. Information we collect

Account and profile information

  • An automatically generated account identifier and authentication token when you first use the app.
  • If you use Sign in with Apple, the stable account identifier supplied by Apple and any display name you choose to provide. SupaSQL does not currently save the email address contained in Apple’s identity response.
  • Your selected learning goal, experience level, onboarding state, and profile display name.

Learning content and activity

  • SQL queries you run or submit, challenge identifiers, results such as verdicts and row counts, execution timing, errors, hints used, and timestamps.
  • Learning progress, skill estimates, completions, streaks, XP, achievements, daily challenges, and usage-limit counters.
  • Interview-mode answers, session activity, and generated reports.
  • AI tutor requests and related context, which may include your SQL, error messages, challenge details, and skill profile. We also record limited AI operational metadata such as feature, model, token counts, latency, and success status.

Purchases

Apple processes payment details. We receive and store purchase-related identifiers and status information needed to verify and provide your subscription, such as the product identifier, original transaction identifier, purchase and expiration dates, environment, and revocation status. We do not receive your full card number.

Usage and technical information

We collect a limited set of product events—for example, when onboarding is completed, a challenge is opened or completed, a hint is requested, or a subscription is restored. Event properties are allowlisted and are designed not to contain raw SQL or directly identifying contact information. Server and security logs may also contain IP address, request path, user agent, timestamps, response status, and diagnostic details.

Notifications and device storage

Practice reminders are local notifications scheduled on your device. SupaSQL does not currently operate a remote push-notification service or store an Apple push token. Your session token and selected local preferences are stored on your device, including in the iOS Keychain where appropriate.

3. How we use information

  • Provide accounts, execute SQL safely against synthetic training databases, grade answers, and preserve progress.
  • Personalize challenges, learning paths, hints, interview practice, and skill feedback.
  • Verify purchases, provide Pro features, enforce usage limits, and prevent fraud or abuse.
  • Operate, secure, troubleshoot, and improve the Service.
  • Respond to support, privacy, and legal requests.
  • Comply with law and protect users, SupaSQL, and others.
We do not sell your personal information. We do not use your learning activity for third-party targeted advertising.

4. Service providers and disclosures

We disclose information only as needed to operate the Service or meet legal obligations:

  • Apple: Sign in with Apple, App Store purchases, TestFlight, crash diagnostics you choose to share, and distribution of the app.
  • Amazon Web Services: cloud hosting, networking, storage, database infrastructure, backups, and operational logs.
  • Anthropic: AI tutor and challenge-generation processing. Prompts sent for these features may contain challenge context, your SQL, error text, or learning context. Do not enter secrets or real personal information in SQL or interview responses.
  • Professional and legal recipients: advisers, authorities, or counterparties when reasonably necessary for legal compliance, safety, fraud prevention, or a business transaction.

Service providers process information under their own terms and privacy commitments. We do not authorize them to use SupaSQL data for unrelated advertising.

5. Retention and account deletion

We keep account and learning information while your account remains active and as reasonably needed to provide and secure the Service. Retention can vary based on the type of record, operational needs, fraud prevention, legal requirements, and backup rotation.

You can delete your account inside the app at Settings → Danger Zone → Delete Account. Deletion removes your profile and account-linked learning records from the active application database. Certain security, AI-operation, and analytics records may remain without your account identifier, and deleted information may persist temporarily in encrypted or access-controlled backups until those backups rotate. Apple subscription records and purchase history remain subject to Apple’s policies; deleting SupaSQL does not itself cancel a subscription.

You may also request assistance by emailing utivillainc@gmail.com.

6. Security

We use safeguards designed to protect information, including encrypted network connections, restricted database roles, query controls, authentication tokens, access controls, and server-side purchase verification. No system is completely secure, and we cannot guarantee absolute security.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain processing. You may update supported profile fields or delete your account in the app. You can disable local notifications in SupaSQL or iOS Settings and manage subscriptions through your Apple ID settings.

To make another request, email us from an address or account we can reasonably verify. We may request information necessary to confirm your identity and authority.

8. Children and international processing

SupaSQL is a general-audience learning service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided such information, contact us so we can investigate and delete it where appropriate.

Our providers may process information in the United States and other countries. Those locations may have data-protection rules different from those where you live. We use reasonable measures intended to protect information as described in this policy.

9. Changes and contact

We may update this policy as SupaSQL changes. We will revise the “Last updated” date and provide additional notice when legally required. Continued use after an update means the revised policy applies to future use, subject to applicable law.

Email: utivillainc@gmail.com
Support: supasql.utivilla.com/support