Legal

Privacy Policy

Last updated: 27 June 2025

1. Who we are

Superpositional is operated by State Vector Co. Pty Ltd (ABN 72 698 005 024), a company registered in Victoria, Australia. In this policy, “we”, “us”, and “our” refer to State Vector Co.

We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we process data of individuals in the European Economic Area (EEA) or United Kingdom, we also comply with applicable provisions of the GDPR.

2. What information we collect

We collect the following categories of personal information:

  • Account information — name, email address, and authentication credentials when you create an account.
  • Organisation information — workspace name, billing contact, and payment details (processed by Stripe; we do not store full card numbers).
  • Usage data — interactions with the service, feature usage, API calls, and performance metrics.
  • Source code metadata — repository names, file paths, entity names, and structural relationships extracted during indexing. We process source code to build the system graph but do not retain raw source code beyond the indexing pipeline.
  • Communications — messages sent via support channels, contact forms, or in-app chat.
  • Technical data — IP address, browser type, device information, and cookies (see Section 7).

3. How we use your information

We use personal information for the following purposes:

  • Providing, maintaining, and improving the Superpositional service.
  • Processing payments and managing billing.
  • Responding to support requests and communicating service updates.
  • Analysing usage patterns to improve product quality and performance.
  • Detecting and preventing fraud, abuse, or security incidents.
  • Complying with legal obligations.

We do not sell your personal information. We do not use your source code or system graph data to train machine learning models outside of your organisation's own workspace.

4. Data storage and security

Your data is stored in the European Union (Ireland). We chose EU residency to provide strong data protection guarantees regardless of where you are located.

We protect your data with:

  • Strict per-organisation data isolation — your data is never co-mingled with other customers.
  • AES-256 encryption at rest and TLS 1.2+ in transit.
  • Application-level access controls and audit logging.

5. Data retention

  • Account data — retained while your account is active, then deleted within 90 days of account closure.
  • Source code metadata — retained while the repository is connected. Deleted within 30 days of disconnection.
  • Usage and analytics data — retained for up to 24 months in aggregated form.
  • Support communications — retained for up to 36 months for quality and training purposes.
  • Billing records — retained as required by Australian tax law (generally 5 years).

6. Disclosure and third parties

We share personal information only with:

  • Service providers — AWS (infrastructure), Stripe (payments), PostHog (analytics), Zendesk (support), Resend (email). These providers process data on our behalf under data processing agreements.
  • Legal obligations — where required by law, court order, or to protect our rights.
  • Business transfers — in connection with a merger, acquisition, or asset sale (with prior notice).

We do not share your data with advertisers or data brokers.

7. Cookies and analytics

We use the following cookies and tracking technologies:

  • Essential cookies — authentication session, CSRF protection.
  • Analytics (PostHog) — self-hosted product analytics to understand feature usage. PostHog is configured with EU data residency.
  • Support (Zendesk) — session cookies for the live chat widget.

We do not use third-party advertising cookies. You can disable non-essential cookies in your browser settings without affecting core functionality.

8. Your rights

Under the Australian Privacy Act and (where applicable) the GDPR, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — request correction of inaccurate or incomplete information.
  • Deletion — request deletion of your personal information (subject to legal retention requirements).
  • Data portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interests.
  • Complaint — lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or your local supervisory authority.

To exercise any of these rights, contact us at privacy@superpositional.io.

9. International transfers

Our primary data storage is in the EU. Where data is transferred outside the EEA (for example, to Australia for business operations), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where applicable.

Australia is recognised by the European Commission as providing an adequate level of data protection for certain categories of data.

10. Children's privacy

Superpositional is not directed at individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notification at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.

12. Contact us

If you have questions about this privacy policy or how we handle your data: