SubGrade
Home Explore Data API Docs Connect AI

Privacy Policy

SubGrade — operated by Keystone Digital Labs LLC
Effective Date: March 2026  |  Last Updated: March 2026

1. Who We Are

SubGrade (“we,” “us,” “our”) is a satellite intelligence platform operated by Keystone Digital Labs LLC, a Pennsylvania limited liability company. We operate the website and API at subgrade.io.

This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

2. What SubGrade Does

SubGrade processes Sentinel-2 satellite imagery to detect land clearing, construction, and ground disturbance. We deliver this intelligence through a public and authenticated REST API, an interactive web Explorer, CSV exports, and AI assistant integrations via Model Context Protocol (MCP).

SubGrade is a data infrastructure product. We serve data to you. We do not aggregate or sell your personal data to third parties. Your relationship with SubGrade is straightforward: you query our API and we return detection data and satellite imagery.

3. What Data We Collect

3.1 Account Information

When you create an account, we collect:

  • Email address — required for account creation and account-related communications

We do not collect your name, company name, phone number, password, or physical address at signup.

3.2 API and MCP Usage Data

When you use the SubGrade API (public or authenticated) or access SubGrade through an AI assistant via MCP, we log:

  • API endpoint called and request parameters (e.g., search coordinates, radius)
  • Timestamp of each request
  • IP address from which the request originated
  • API key identifier (for authenticated requests)
  • Response status (success, error, rate limited)

MCP queries log the same data as API queries (coordinates, timestamp, IP address). API and MCP usage logs are used for metering (tracking your usage against your tier limits), rate limiting, abuse prevention, debugging, and platform improvement.

3.3 Public Endpoint Usage

When you access public endpoints or browse the Explorer without an account, we collect only standard server-level data: IP address, request parameters, and timestamp. This data is not linked to any identity because no account exists.

3.4 Payment Information

When you subscribe to the Pro tier, payment is processed by Stripe. We do not store your credit card number, CVV, or full payment details on our servers. Stripe handles all payment data in accordance with PCI-DSS standards. We receive from Stripe: a confirmation of payment, subscription status, and transaction metadata.

3.5 Local Storage

SubGrade uses browser local storage solely for:

  • Session authentication — storing your Supabase authentication token and account tier locally so you remain authenticated when using the Explorer or account page (essential; cannot be disabled without losing authenticated access)

We do not use cookies of any kind. We do not use analytics cookies, advertising cookies, or tracking cookies. We do not use PostHog, Google Analytics, or any third-party analytics service.

3.6 What We Do Not Collect

To be explicit about what we do not collect:

  • We do not track your browsing behavior across pages
  • We do not use analytics or tracking scripts
  • We do not collect device fingerprints
  • We do not collect your name, company, or phone number
  • We do not collect location data from your device (search coordinates are data you provide to query our API, not geolocation we capture from you)
  • We do not use advertising cookies or share any data with ad networks
  • We do not use cookies at all

4. How We Use Your Data

4.1 To Operate the Platform

  • Authenticate your API requests
  • Meter your usage against tier limits
  • Process your subscription payments
  • Enforce rate limits to maintain platform stability

4.2 To Maintain and Improve the Service

  • Monitor API performance and diagnose errors
  • Identify and prevent abusive usage patterns
  • Understand aggregate usage patterns to inform product development (e.g., which geographic areas are most queried, which endpoints are most used)

4.3 To Communicate With You

  • Account-related emails (subscription confirmations, billing issues)
  • Service notices (planned downtime, breaking API changes, security issues)

We may send periodic product updates, construction activity reports, and service-related communications to users who have signed up for an account or downloaded a report. You may unsubscribe from non-essential communications at any time by following the unsubscribe link in the email or contacting us at contact@subgrade.io.

5. Third-Party Services

We use the following third-party services that may process data in connection with your use of SubGrade:

Service Purpose Data Involved
Railway Application hosting and PostgreSQL database All platform data (server-side, encrypted in transit)
Supabase User authentication Email address, authentication tokens
Stripe Payment processing for Pro subscriptions Email, payment details, subscription status
Amazon Web Services (AWS) Cloud-Optimized GeoTIFF (COG) imagery hosting Before/after satellite imagery fetched server-side; no user data sent
CartoDB/CARTO Map tile basemaps for the Explorer Your IP address and browser metadata (standard tile server requests from your browser)
Leaflet.js (via unpkg CDN) Map library loaded in your browser Your IP address (standard CDN request)
Google Fonts Inter font family for the website Your IP address (standard CDN request)
Nominatim/OpenStreetMap Reverse geocoding on the construction-suppliers page Coordinates you search (no personal data)
Copernicus Data Space Sentinel-2 satellite imagery source Detection coordinates (server-side, no user data sent)

Each of these services has its own privacy policy. CartoDB, Google Fonts, and the unpkg CDN are loaded client-side, which means your browser makes direct requests to these services when you use the Explorer. These requests expose your IP address to those services, as is standard for any website that loads external resources.

6. Data Sharing

We do not sell your personal information. Unlike some of our other products, SubGrade does not aggregate user data into a product sold to others. You are the customer, not the product.

We share data only as follows:

  • With service providers listed in Section 5, solely for them to perform their function
  • When required by law — in response to a valid subpoena, court order, or law enforcement request. We will attempt to notify you when legally permitted to do so.

7. Data Retention

  • Account data (email) is retained as long as your account is active. If you delete your account, we delete your personal information within 30 days.
  • API usage logs are retained for 90 days for metering, debugging, and abuse prevention, then deleted.
  • Payment records are retained as required by tax and financial regulations (typically 7 years).
  • Server logs (IP addresses, request metadata) are retained for 90 days, then deleted.

8. Your Rights

8.1 All Users

You have the right to:

  • Access your data — your account page shows your email, tier, and usage. Contact us for a full export.
  • Correct your data — contact us to update your email address.
  • Delete your account — contact us at contact@subgrade.io and we will delete your account and personal data within 30 days.
  • Export your data — contact us at contact@subgrade.io to request a copy of your data in a portable format.

8.2 California Residents (CCPA Rights)

If you are a California resident, you have rights under the California Consumer Privacy Act:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Opt Out of Sale: We do not sell your personal information. There is nothing to opt out of.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise any of these rights, contact us at contact@subgrade.io. We will verify your identity and respond within 45 days as required by law.

8.3 EU/EEA Residents (GDPR Rights)

If you are a resident of the European Union or European Economic Area:

  • Legal Basis for Processing: We process your data based on contractual necessity (providing the service you signed up for) and our legitimate interest in maintaining platform security and stability.
  • Rights: You have the right to access, rectification, erasure, restriction of processing, data portability, objection, and to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at contact@subgrade.io.

8.4 Other State Privacy Laws

Residents of Colorado, Connecticut, Virginia, and other states with consumer privacy laws may have additional rights similar to those described above. Contact us at contact@subgrade.io to exercise any applicable rights.

9. Children’s Privacy

SubGrade is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, contact us and we will delete it promptly.

10. Security

We implement reasonable security measures to protect your data:

  • All data is transmitted over HTTPS/TLS encryption
  • Database access is restricted and encrypted in transit
  • API endpoints are authenticated via bearer token and rate-limited
  • Payment data is handled entirely by Stripe (PCI-DSS compliant)

No system is perfectly secure. If we become aware of a data breach affecting your personal information, we will notify affected users within 60 days of discovery and comply with applicable breach notification laws, including Pennsylvania’s Breach of Personal Information Notification Act.

11. Do Not Track

We do not track users across websites. We do not use analytics or advertising tracking. Because we perform no tracking, Do Not Track browser signals do not change our behavior — there is no tracking to disable.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if you have an account) or by posting a notice on the platform at least 14 days before the changes take effect. Your continued use of the platform after the effective date constitutes acceptance.

13. Contact Us

For privacy-related questions or requests:

Email: contact@subgrade.io

Mail:
Keystone Digital Labs LLC
4069 Green Park Drive
Mount Joy, PA 17552

SubGrade

Satellite-powered land change detection.

Explore Data API Documentation Pricing Privacy Policy Terms of Service
Powered by Sentinel-2 satellite data from the Copernicus Programme. © 2026 Keystone Digital Labs LLC. All rights reserved.