Privacy Policy
Last updated: July 22, 2026
What we collect
- Account info — email address and hashed password for authentication.
- Google Login — when you sign in with Google, we collect your email address and basic profile information (name, profile picture). We use this data solely to authenticate you, create your account, and display your profile.
- Database connections — connection strings are encrypted at rest and used only to run your queries.
- Queries and results — your questions, generated SQL, and result sets are stored to power the trust flywheel and history.
- Analytics — anonymous product analytics via PostHog. Respects
Do Not Track. No personal data is sent.
What we send externally
- Schema + your question — sent to OpenRouter to generate SQL. Your row data never leaves your machine.
- Email — verification and password-reset emails are sent through MyEmailVerifier and Resend.
What we never do
- We never sell or share your data with third parties for advertising.
- We never read or transmit your actual database rows.
- We never track you across sites.
Data storage
User accounts, Google authentication data, and query history are stored in PostgreSQL (Supabase). The local knowledge base is stored in SQLite on your machine. Database connection strings are encrypted using Fernet symmetric encryption.
Data deletion
You have the right to request the deletion of your account and all associated data. Upon request, we will permanently delete your profile, email, authentication records, database connections, and query history from our servers. To request data deletion, please contact us or open an issue on GitHub.
Changes
We may update this policy from time to time. The "Last updated" date at the top will always reflect the most recent revision.
Contact
Questions? Open an issue on GitHub.