Privacy Policy.
This Privacy Policy describes how Data Alias, operated by Changseok Lim (“Data Alias,” “we,” “us,” or “our”), handles information in connection with the Data Alias website and browser application at https://dataalias.app (the “Service”). The Service is built around one design decision: files you process are parsed and transformed inside your own browser tab. File contents, detected values, and generated safe copies are not uploaded to a Data Alias server or shared with any third party.
Table of contents
- What this Privacy Policy covers
- What we never collect
- Personal data we collect
- Sources of personal data
- Why we collect it
- How we disclose personal data
- Data stored on your device
- Tracking signals and opt-out
- Data security
- Data retention
- Your rights and choices
- Personal data of children
- Changes to this Privacy Policy
- Contact information
What this Privacy Policy covers
This Privacy Policy applies to personal data handled through the Service — the marketing website and the browser application. “Personal data” means information that identifies or relates to a particular individual. It does not cover the practices of companies we don't control, such as the AI services you choose to use with your safe copies; their own policies apply there.
What we never collect
Because file processing runs locally in your browser, the following never reach our servers, by design:
- Your files and their contents.
- File names, column names, and detected cell values.
- Alias mappings and custom detection patterns.
- Generated safe copies, reports, and restore results.
We also do not use:
- Third-party analytics or advertising trackers.
- Session-replay recordings.
Sensitive personal information: we do not collect sensitive personal data (such as government ID numbers, precise geolocation, or information revealing race, religion, health, or sexual orientation) through the Service. Files you process may contain sensitive values — but they are processed in your browser and are never transmitted to us.
Personal data we collect
This chart details the limited categories of personal data the Service can collect, with examples and the categories of parties they are shared with:
| Category of personal data | Examples of what we collect | Categories of parties it is shared with |
|---|---|---|
| Account data (optional — only if you sign in) |
|
|
| Billing data (only if you purchase) |
|
|
| Product usage events (anonymous) |
|
|
| Technical logs |
|
|
Data Alias currently works without accounts; account and billing data exist only once you choose to sign in or purchase. Even with an account, signing in changes what the server knows about your plan — not what it knows about your data, which remains nothing.
Sources of personal data
- You — when you sign in with your email or contact support.
- Automatically — anonymous product usage events from the app and standard access logs at the hosting layer.
- Our payment provider — subscription lifecycle events (signed webhooks from Lemon Squeezy) containing the checkout email and subscription status.
Why we collect it
- Providing and operating the Service, including signing you in.
- Processing subscriptions: granting the plan you paid for, based on events from our merchant of record.
- Responding to correspondence you send us.
- Understanding which product features are used, through first-party events that cannot carry file data.
- Meeting legal obligations and protecting the Service against abuse.
We will not use the personal data we collect for materially different or incompatible purposes without providing you notice.
How we disclose personal data
We do not sell or rent personal data, and we do not share it for advertising. Personal data is disclosed only to:
- Service providers that operate our infrastructure — hosting/CDN, authentication and database hosting, and Lemon Squeezy as merchant of record — each receiving only what its function requires.
- Authorities, where disclosure is required by applicable law, regulation, or valid legal process.
Data stored on your device
Some features keep data in your own browser's local storage. It stays on your device, we cannot access it, and clearing your browser storage removes it:
- Rule presets and project folders — configuration only: column types, transform choices, and names you typed. Never data values from your files.
- Project activity history — generic labels only (for example “Safe copy (CSV)”) with timestamps. Never real file names.
- The optional alias vault — your original-to-alias mappings, encrypted on your device with a key derived from your passphrase before anything touches storage.
- A monthly usage counter (a number and the month, nothing else).
- The random identifier used for anonymous product usage events.
Tracking signals and opt-out
We use no third-party analytics or advertising cookies. To understand which features are used, the app sends a small number of usage events to our own endpoint (/api/event) — never to a third-party analytics service. Each event carries only an allow-listed event name (for example "file_parse_succeeded") and coarse metadata such as file format, size and row-count buckets, processing time, and detection counts. Events can never contain file contents, filenames, column names, cell values, alias mappings, or custom patterns — the allow-list is enforced in the client and again on the server, and anything outside it is dropped. Events are keyed to a random per-browser identifier that is not joined to your account, and nothing is sent at all when your browser signals Do Not Track or Global Privacy Control.
Data security
Connections to the Service use TLS encryption in transit. Card data is handled entirely by our merchant of record and never reaches our systems. The alias vault is encrypted on your device before storage, with a key derived from a passphrase only you know. The most effective security control in the Service is architectural: the data that matters most — your files — is never transmitted to us in the first place. No online service can promise absolute security, so we deliberately minimize what exists on our side to an email address and a plan flag.
Data retention
- Account data (email, plan) is kept while your account exists and deleted on request.
- Anonymous usage events are kept for product analysis and are not linked back to accounts.
- Data on your device (presets, projects, vault, counters) remains until you delete it — it is under your direct control.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal data we hold about you. Because the personal data we hold is minimal — an email address and a plan flag — the practical way to exercise any of these rights is to email hello@dataalias.app from the address in question. We respond to verified requests within a reasonable time, and we do not discriminate against you for exercising your rights. Everything else the Service touches lives in your browser, where you can inspect and delete it directly.
Personal data of children
The Service is not directed to children under 14, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this Privacy Policy
We may update this Privacy Policy as the Service evolves. When we do, we will update the “Last updated” date on this page, and for material changes we will post a notice on the website.
Contact information
Privacy questions: hello@dataalias.app.