Privacy Policy for Exmergo Viz
Last modified: September 23, 2026
1. Scope
This annex describes how Exmergo, Inc. handles data in Exmergo Viz, our hosted analytics and dashboard service at viz.exmergo.com.
It forms part of the Exmergo Privacy Policy and should be read with it. The main policy covers who we are, your rights, international transfers, security, retention of account records, and how to contact us. This annex covers what is specific to Viz. Where the two differ on a Viz question, this annex governs.
Exmergo Dex is a different product with a different architecture and is covered by its own annex, the Privacy Policy for Exmergo Dex.
2. Our Role for Exmergo Viz
- We are a processor for the content you put into Viz: the files you upload, the metadata and query results we receive through your connected semantic layer, the prompts you write, and the dashboards you build. We process that content on your instructions, for your purposes. If it contains personal data about other people, you are the controller of it.
- We are a controller for your account information, your billing records, and the usage and analytics data we collect about how you use the service.
A Data Processing Agreement covering our role as processor is available on request at legal@exmergo.com.
3. What We Collect in Exmergo Viz
A. Information you provide
- Account information. When you create an account through Google or Microsoft, we receive your name, email address, and profile picture from that provider. We store this alongside your Viz settings, including your pricing tier.
- Account status. Viz has no free tier. A newly created account is inactive until you subscribe to a paid plan, including a trial of that plan. Pro and Ultra offer a 14-day trial requiring a valid payment method, as described in our Terms of Service.
- Uploaded data. The files you upload for analysis, in formats including CSV, XLSX, JSON, and Parquet. We do not inspect, restrict, or catalogue the contents of these files beyond what is needed to query them for you.
- Connected semantic layers. The credentials and connection settings for your dbt Semantic Layer, together with semantic metadata such as metrics and dimensions used to formulate queries. dbt Semantic Layer is our only data connector. See section 7.
- Prompts. The questions and instructions you type into the chat interface.
- Payment information. Collected directly by Stripe, Inc. We never receive or store your full card number.
B. Information generated as you work
- AI-generated content. The queries and visualization code our agents produce in response to your prompts.
- Query results. Results computed from uploaded files or returned through your semantic layer when the agent queries it. These results may be retained in sessions, dashboards, and published snapshots.
- Dashboard and session data. The configuration of your dashboards, including chart titles, sizes, and positions, and the history of your conversation with the AI for each session.
C. Information collected automatically
- Usage and analytics data, collected through Google Analytics: device and browser type, operating system, screen resolution, approximate location, how you arrived, which features you used, and session duration, with a randomly generated client identifier stored in a cookie.
- Server logs, recording IP address, request details, and timestamps for security and debugging.
4. How Your Data Is Stored and Queried
A. Uploaded files
Files you upload are converted to Apache Parquet and stored privately on Google Cloud Platform. Each file is written to a storage path unique to your user ID and session ID. Your uploaded files are not co-mingled with any other customer's, and no query path exists from one account to another's storage. Our data engine reads your files from that private location, computes results inside our infrastructure, and returns them to your browser.
B. Semantic-layer connections
Viz queries your dbt Semantic Layer on demand when the agent needs data to answer a question or create a visualization. The underlying source data remains in your environment. Connecting a semantic layer does not bulk-import your data, synchronize source tables into Viz, or create a copy of your raw dataset in our storage.
Viz receives semantic metadata and the results returned by those queries. Query results may be retained in sessions, dashboards, or published snapshots; the absence of a raw-data replica does not mean that query results are never stored.
C. Security
Data handled by Viz is encrypted in transit over HTTPS and at rest. Connection credentials are handled as described in section 7.
5. What the AI Models Receive
Our agents send Google's Gemini models your prompt and the conversation history for that session, along with context used to generate queries, visualizations, and insights:
- For uploaded files: the schema (column names and data types), a random sample of rows, and aggregated query results. We do not send the uploaded file itself to an AI provider; it stays in our storage and is queried by our own engine.
- For semantic-layer connections: semantic metadata, such as metric and dimension definitions, and results returned by queries through your dbt Semantic Layer. Viz does not import the underlying dataset or separately sample raw source tables for the model.
Samples from uploaded files and results from either data path can contain values from your data, including personal or sensitive information. Those values may reach Gemini for analysis and visualization. We do not send stored connection credentials to AI providers.
If your requirements restrict sending samples or query results to an AI provider, speak to us about Enterprise deployment options before uploading files or connecting a semantic layer. See section 12.
6. AI Model Training
Exmergo does not use your customer content to train its AI models. This includes uploaded data, prompts, schemas, semantic metadata, query results, and dashboard and session content. The commitment applies across all Viz plans, including trials. You do not need to opt out.
This commitment describes Exmergo’s own use of your content. AI providers process the information described in section 5 under the terms applicable to those services; this policy does not make a separate guarantee about their model-training practices.
Separately, we analyze usage data in aggregated and anonymized form to understand which features are used and to improve the product. That analysis cannot be traced back to an individual user or dataset.
7. Connected Data Sources and Their Credentials
File upload remains available on every plan. Viz’s only data connector is dbt Semantic Layer; Viz does not offer direct database or business-application connectors. The number of semantic layers you can connect depends on your plan:
| Connector type | Sources | Available on |
|---|---|---|
| File upload | CSV, XLSX, JSON, Parquet | All plans |
| Semantic layer | dbt Semantic Layer | Pro: 1 per account; Ultra and Enterprise: unlimited per account |
When you connect a source, we store the connection settings and the credentials or access tokens needed to reach it. Those are encrypted at rest, are scoped to your account, and are never sent to an AI provider, never written into a dashboard, and never exposed to anyone you share a dashboard with. Connections are encrypted in transit. You can revoke a connection at any time from within Viz, which deletes the stored credential and stops further queries through that connection. Disconnecting does not delete results already saved in sessions, dashboards, or published snapshots; their retention is described in section 9.
Enterprise deployments can additionally place these connections behind VPN or VPC access controls.
8. Published and Shared Dashboards
Publishing a dashboard creates a read-only public snapshot of its visualizations and query results. It does not grant viewers access to your uploaded files, connected semantic layer, or source systems.
When you publish, our engine re-runs the specific queries behind each visualization on your dashboard and saves only the final results to a separate public location. Anyone with the link can view the resulting charts and the results included in the snapshot. Published results may themselves disclose sensitive information or allow viewers to infer facts about the underlying data, even though the link does not grant access to the source.
Treat a published link as public. Anyone who has it can open it, so publish only results you are comfortable making public, and unpublish from within Viz when you no longer want the link to work.
9. Retention and Deletion
- Uploaded files. Retained while your account is active. Deleting a file inside Viz permanently deletes it from our systems.
- Dashboards and session history, including saved query results. Retained while your account is active, and deletable individually from within Viz.
- Semantic-layer connections. Stored settings and credentials support access to your semantic layer; revoking a connection deletes its stored credential. We do not retain a replica of the underlying source dataset.
- Published snapshots. Retained until you unpublish the dashboard or delete it.
- Account, billing, and correspondence records. Retained as described in section 10 of the main policy.
When subscription cancellation takes effect, or a trial is cancelled, your account becomes inactive. Existing uploaded files, dashboards, session history, and their saved results are retained and become accessible again if you reactivate a paid plan, as described in our Terms of Service. Cancellation is not an account-deletion request.
Deleting your account removes your uploaded files, stored connections, dashboards, session history, and associated saved results and published snapshots. Deletion in Viz does not delete data in your connected source systems. We may retain billing records where accounting or tax law requires it.
10. Where Your Data Is Stored
- Pro and Ultra plans. The information Viz receives and handles, including uploaded files, semantic metadata, query results, and account information, is processed and stored in the United States. If you are outside the United States, using these plans means your information is transferred there.
- Enterprise plans. You may select a geography, for example within the European Union, for storage and processing. Your enterprise agreement sets the specifics.
These locations describe Viz’s processing and storage. Connecting your semantic layer does not relocate the underlying warehouse or its raw dataset to Exmergo.
Transfers out of the EEA, the UK, or Switzerland rely on the Standard Contractual Clauses, as described in section 12 of the main policy.
11. Sub-processors for Exmergo Viz
- Google Cloud Platform and Firebase. Hosting, file storage, the application database, and analytics.
- Google (Gemini). The AI models, receiving only what section 5 describes.
- Google and Microsoft. Authentication, when you sign in through them.
- Stripe, Inc. Payment processing on paid plans.
We do not sell your personal data and we do not share it for advertising.
12. Enterprise Deployment Options
Enterprise customers can change where Viz runs, which changes the answer to several of the questions above:
- Standard Cloud. Shared infrastructure with logical isolation, the same architecture described throughout this annex.
- Private Managed Cloud. Dedicated infrastructure with physical isolation and a geography of your choosing.
- On-Premise. Viz runs inside your own environment. Your data does not reach Exmergo infrastructure at all, and our role narrows to the account and licensing information you provide us directly.
Your enterprise agreement, and any Data Processing Agreement executed with it, governs where these differ from this annex.
13. Prohibited Data
As set out in our Terms of Service, you may not upload, submit, or make available through a connected semantic layer data subject to specific regulatory regimes, including Protected Health Information under HIPAA or cardholder data under PCI-DSS, unless you have a separate written agreement with us covering it. Viz is not configured for those regimes by default, and providing such data without that agreement puts it outside the protections either of us has committed to.
14. Contact
Questions about this annex, or requests to exercise your rights, go to support@exmergo.com. Data Processing Agreements and contractual questions go to legal@exmergo.com. The full contact details are in section 16 of the main policy.