Who we are
Alwaystudios Ltd is the controller for your Supervela account — the sign-in identity and which workspaces you belong to. Your organisation is the controller for workspace knowledge: Jira issues, Confluence pages, meeting uploads, and the rest of the project store. We process that content as a processor on their behalf.
What we collect
- Account email and sign-in through Amazon Cognito, including Google if you use it.
- Workspace membership and role.
- Content the team chooses to sync or upload.
- Integration secrets the team pastes (Jira, Confluence, GitHub, cloud-agent tokens), stored encrypted.
- If you pay: billing email and payment status from Stripe. Quota and billing notices we send from noreply@supervela.com. We do not store the full card.
- AWS operational logs (CloudFront, CloudWatch, Cognito) so we can run and secure the service.
Tracking
We use PostHog (European Union cloud) for product usage analytics. Marketing pages and the signed-in app send page and section views (path only — not query strings). Supervela MCP sends tool name, duration, and whether the call succeeded — not tool arguments or knowledge content. When you are signed in, we attach events to a person identified by your Cognito user id — not your email. Events may include workspace id, project, plan, and role. We do not send your email. We do not use advertising cookies. These marketing pages stay anonymous and store no analytics cookies (in-memory only). When you are signed in on app.supervela.com, the app may set one first-party functional cookie (supervela_has_session=1) on .supervela.com so this site can show Open app instead of Sign in. That cookie is a session hint only — no email, no Cognito user id, and no workspace id. Delete my account erases that PostHog person.
Your rights (UK GDPR)
You can access and erase personal data we hold about you. Use the product paths below — we do not claim a certification badge. Counsel reviews these pages; this is not legal advice.
- Download my data and Delete my account live under Account in the signed-in app. Delete my account removes your sign-in, memberships, and the PostHog person tied to your Cognito user id. It does not delete the workspace's knowledge.
- Delete workspace (Settings → Account) is how a workspace admin erases that tenant: knowledge, projects, integrations, and team access. Sign-in identities stay, so people can join another workspace later.
If you are the last admin of a workspace, delete that workspace first. On Teams, you can invite another admin instead.
How long we keep data
Account data lasts until you delete your account. Workspace content lasts until an admin deletes the workspace, or we are instructed to erase it.
Sharing
We use AWS to host Supervela. Workspace content is sent to AWS Bedrock to embed and to run Chat, Review, planning, and the other product models. When you send a work order, a brief from that store goes to the Cursor or Claude cloud agent the workspace has connected. On Teams, Enterprise, and Dedicated, MCP lets that client retrieve store content. If you pay, Stripe processes the card and billing email. Quota and billing notices are sent from noreply@supervela.com through Amazon SES.
Product analytics are processed by PostHog in the EU (eu.posthog.com). Mail to hello@supervela.com is forwarded by ImprovMX (https://improvmx.com) to our inbox. We do not sell personal data. Google sees the sign-in if you choose Google.
Changes
We will update this page when our practices change.