Legal · Privacy
Privacy Policy
Effective September 5, 2026
This policy explains what information SwitchLens processes, why it is used, and the choices available to people who use the service. SwitchLens is operated by SwitchCase Studios LLC. Because it is a collaborative reporting product, an organization that gives you access may also control workspace content and membership.
1. Scope and roles
This policy applies to the SwitchLens website, application, APIs, and hosted visualization pages. It does not govern a customer database, website containing an embedded visualization, or third-party service except for information SwitchLens receives from it.
SwitchCase Studios LLC is the controller or business for account, website, billing, and service-operation information it determines how to use. For Customer Content submitted through a business or team account, the customer generally acts as the controller or business and SwitchCase Studios LLC acts as its processor or service provider. The customer decides what to connect, upload, model, and share and is responsible for its notices, legal basis, and instructions. The parties may document more specific privacy roles in a separate data-processing agreement.
2. Information we process
- Account and identity information. User identifiers, names, email addresses, verified-email status, authentication events, and workspace roles supplied through Clerk or an account administrator.
- Workspace and report information. Workspace names, memberships, source metadata, model relationships, calculated fields, report definitions, filters, layouts, refresh settings, and embed audience rules.
- Customer Content. Uploaded CSV, TXT, XLS, and XLSX files; data returned from connected databases or approved read-only custom queries; SFTP replacement files; and cached report or visualization results.
- Connection information. Database and SFTP configuration, selected schemas or tables, and encrypted credentials needed to reach sources. Credentials are not returned in normal browser workspace data.
- Billing information. Plan, subscription, customer, billing status, and transaction references received from Stripe. Payment-card details are entered on Stripe-hosted pages rather than into SwitchLens.
- Usage and technical information. Request and correlation identifiers, timestamps, IP and device/network information ordinarily present in service logs, feature activity, refresh outcomes, errors, and security signals.
- Embed access information. Public embed tokens and, for private embeds, designated user IDs, verified-email allowlists, domain patterns, or workspace membership rules selected by an author.
3. Where information comes from
Information comes from you, workspace administrators, connected data sources, uploaded or fetched files, Google or GitHub when you choose those sign-in methods through Clerk, Stripe, and ordinary interaction with the service. A customer is responsible for having authority to provide data and connection access to SwitchLens.
4. How information is used
- authenticate users and enforce account, workspace, source, report, and embed permissions;
- connect to selected sources, inspect schemas, execute approved queries, refresh results, and render reports;
- operate collaboration, billing, support, security, and troubleshooting workflows and measure feature reliability;
- protect users, customer data, and the service from abuse, fraud, unsafe destinations, and unauthorized access; and
- meet legal obligations and enforce applicable agreements.
SwitchLens is not designed to sell personal information, use Customer Content for third-party targeted advertising, or train a generative artificial-intelligence model on Customer Content.
Where applicable law requires a legal basis, processing is performed as needed to provide the service and fulfill a contract, comply with law, protect the legitimate interests of operating and securing the service, or based on consent when specifically requested. A customer determines the legal basis for Customer Content it directs SwitchLens to process.
5. Service providers and disclosures
SwitchLens uses service providers to operate the product: Clerk for identity and authentication; Microsoft Azure for the public web application, DNS, object storage, and optional communication services; Fly.io for application and worker compute; Railway for PostgreSQL; and Stripe for billing and hosted payment flows. Those providers process information under their own contracts and privacy terms.
Information may also be disclosed to a customer's authorized administrators and members, to recipients selected through embed controls, during a business transaction subject to appropriate safeguards, or when reasonably necessary to comply with law, protect rights and safety, or investigate abuse. A public embed is accessible to anyone who has its bearer URL until it is made private or replaced; access controls cannot recall information already viewed, copied, exported, or captured.
6. Cookies and local storage
SwitchLens and Clerk use cookies or comparable browser storage needed for sign-in, session security, routing, and saved interface preferences such as theme and text size. Stripe may use its own technologies on hosted checkout and billing pages. SwitchLens does not currently include an advertising-cookie feature.
7. Retention and deletion
We use the following retention criteria rather than keeping information indefinitely:
- account, workspace, and Customer Content is retained while the applicable account or workspace is active and until it is deleted or the service relationship ends;
- billing, transaction, membership, consent, and administrative records may be retained for the period reasonably needed for accounting, fraud prevention, disputes, and legal obligations;
- request, security, refresh, and error records are retained for a limited operational period appropriate to troubleshooting, abuse prevention, and incident response; and
- information subject to deletion may remain temporarily in protected backups, provider recovery systems, retained usage records, or a legal hold until the applicable lifecycle or obligation ends.
Deleting a source removes its active control-plane record and initiates deletion of its managed uploaded object. SwitchLens cannot delete copies already exported or captured by a customer, embed recipient, or connected third party.
SwitchLens does not yet offer a complete self-service account export or deletion workflow. Users should ask their workspace or account administrator to remove access or content. Administrators should use the contact method in their invitation, order, or account communication for broader privacy requests.
8. Security
SwitchLens uses authentication, role-based authorization, tenant-scoped records, encrypted transport, encrypted stored connector credentials, bounded file and query processing, and protected provider configuration. No system is perfectly secure, and these controls are not a certification or a guarantee against loss or unauthorized access.
9. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, or a portable copy; restrict or object to certain processing; withdraw consent without affecting earlier lawful processing; or appeal a denied request. You may also have the right to complain to your local data-protection authority. Start with the organization that provided your account when it controls the workspace data.
For operator-controlled information, email jschroeder@switchcasestudios.com. A request does not require a new account. We may verify your identity or authority, ask an authorized agent for proof, retain a request record, and apply legal exceptions. We will not discriminate against you for exercising a privacy right.
10. U.S. state privacy notice
During the preceding 12 months, the categories collected and disclosed for the business purposes described above may include identifiers; customer-record and subscription information; internet, device, and service-activity information; professional or employment-related information a customer places in the service; and sensitive personal information such as account credentials or the contents of Customer Content. The exact Customer Content categories are determined by the customer.
These categories may be disclosed to the service-provider categories in Section 5 and to recipients a customer authorizes. SwitchLens has not sold personal information or shared it for cross-context behavioral advertising, and it does not use sensitive personal information to infer characteristics about a person. Consequently, the service does not currently provide a sale/sharing or sensitive-information limitation opt-out. If those practices change, this notice and the required choices will be updated before the change.
Residents of states with applicable privacy laws may request the categories or specific pieces collected, sources, purposes, recipients, correction, deletion, or portability using the email or mailing address in Section 13. California residents may use an authorized agent; proof of authorization and direct identity confirmation may be required.
11. Children
SwitchLens is a business reporting service intended for people who are at least 18. We do not knowingly offer accounts to children. If you believe a person under 18 provided account information, email the privacy contact below so the account can be reviewed.
12. International processing
SwitchLens and its providers may process information in the United States and other countries where they operate. Privacy protections can differ by location. Where required, international transfers must use a recognized legal mechanism or another lawful basis. Business customers that require specific transfer terms or a data-processing agreement should arrange them before submitting regulated data.
13. Changes and contact
This policy may change as the service, providers, or legal requirements change. The effective date will be updated, and material changes will be communicated through the service or the account relationship when reasonably practical.
Privacy questions and requests may be sent to jschroeder@switchcasestudios.com or mailed to:
SwitchCase Studios LLCPO Box 8378
Eastpointe, MI 48021
United States