Privacy Policy
Last updated 30 August 2026
This document describes how Interva is actually built and what it actually does, but it has not been reviewed by a lawyer. Have counsel review it, and fill in the bracketed placeholders, before relying on it or launching publicly.
In short
- Browsing the catalog requires no account and no sign-in.
- If you sign in, we receive your email address and a user identifier from Google. Nothing else.
- We run no analytics, no advertising, and no third-party trackers. There is no tracking cookie on this site.
- We do not sell, rent, or share personal data with third parties for their own purposes.
- You can delete your account and associated data at any time — see Your choices.
Who we are
Interva (“we”, “us”) provides harmonized global time-series data through a web application, a REST API, and an MCP server for AI agents. This policy covers all three.
Data controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Contact: [PRIVACY CONTACT EMAIL].
What we collect
If you sign in. We use Google as an identity provider, through Supabase. From that flow we receive:
- your email address;
- a stable user identifier issued by the identity provider;
- the timestamps of account creation and most recent sign-in.
We never receive your Google password, and we do not request access to your Gmail, Drive, contacts, or any other Google service.
If you use the service at all. Our servers keep ordinary request logs — IP address, timestamp, requested path, response status, and user agent — which we use to operate the service, diagnose faults, and detect abuse.
What you create. Saved items in your workspace and any API keys you generate are stored against your user identifier.
What we do not collect. No behavioural analytics, no advertising identifiers, no cross-site tracking, no fingerprinting, no session recording, and no marketing profile.
Why we process it
- To provide the service — authenticate you, keep your workspace, and honour your API keys. (Performance of a contract.)
- To keep it running and secure — request logs, rate limiting, and abuse detection. (Legitimate interests.)
- To meet legal obligations where they apply.
Where it is stored, and who processes it
We use a small number of infrastructure providers. Each processes data only on our instructions:
- Supabase — authentication and account records.
- Cloudflare R2 — object storage for the published dataset files. It holds no personal data.
- [HOSTING PROVIDER] — application hosting and request logs.
These providers may store data outside your country. Where personal data is transferred out of the UK or EEA, the transfer relies on [TRANSFER MECHANISM — e.g. standard contractual clauses].
How long we keep it
- Account data — for as long as your account exists, and deleted within [30] days of you deleting it.
- Request logs — [90] days, then deleted.
- Published dataset files — retained indefinitely. They contain no personal data; they are public statistics.
Your choices
You can, at any time:
- Use Interva without an account. The catalog, search, and the public API surface do not require signing in.
- Sign out, which clears the session cookie.
- Request a copy of the personal data we hold about you.
- Request correction or deletion of it.
- Object to or restrict processing based on legitimate interests.
- Complain to your data protection authority.
Write to [PRIVACY CONTACT EMAIL]. We respond within [30] days.
A note on the statistical data
The datasets Interva publishes are aggregate national and regional statistics from the World Bank, the World Health Organization, and Eurostat. They describe populations, not individuals, and contain no personal data about you.
Children
Interva is not directed at children under [16], and we do not knowingly create accounts for them. If you believe a child has an account, contact us and we will remove it.
Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect how we handle personal data, we will notify signed-in users by email before the change takes effect.