Last updated: January 23, 2025
Effective Date: January 23, 2025
SQL Studio (“Company”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SQL database management platform (the “Service”).
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use the Service. By accessing or using SQL Studio, you acknowledge that you have read and understood this Privacy Policy.
We collect information that you voluntarily provide to us, including:
We automatically collect certain information when you use the Service:
We may receive information from third-party sources:
We use the information we collect for various purposes:
Your information is stored on secure servers located in [Data Center Location - typically US or multi-region]. We use a combination of PostgreSQL (for user accounts) and MongoDB (for application data, queries, connections, and audit logs).
Database credentials and connection strings are encrypted at rest using industry-standard encryption algorithms. API keys and sensitive tokens are not logged or stored in plaintext.
Your authentication tokens are stored in browser localStorage for session persistence. Access tokens are valid for 15 minutes with automatic refresh starting 60 seconds before expiry. Refresh tokens are valid for 30 days. You can clear this data anytime by logging out or clearing your browser cache.
We do not sell your personal information to third parties. We may share information in the following circumstances:
We share information with trusted service providers who assist us in operating our Service:
We may disclose your information when required by law or when we believe in good faith that disclosure is necessary to:
If SQL Studio undergoes a merger, acquisition, bankruptcy, or other business reorganization, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you. This may be used for research, marketing, analytics, and other purposes without restriction.
When you connect external databases to SQL Studio, we store only the connection credentials. We do not access or store data from your databases beyond what you explicitly query and display in the Service. You remain responsible for the security of your database credentials and access control policies.
When you send prompts to our AI assistant, the following occurs:
SQL Studio integrates with multiple AI model providers. When you use AI features, your data is transmitted to and processed by:
Each provider has their own privacy policies and data handling practices. We recommend reviewing their privacy policies before using our Service.
By default, AI providers may use interaction data to improve their models unless you opt out. You can:
To provide effective AI suggestions, we may share your database schema information (table names, column names, data types) with AI providers. We do not share actual data values unless they are part of your explicit query or configuration.
If your database contains sensitive information (HIPAA-regulated health data, GDPR-protected personal data, PCI-DSS payment card data, etc.), you should:
We implement comprehensive security measures to protect your information:
We maintain an incident response plan to address security breaches promptly. In the event of unauthorized access or data breach:
While we implement strong security, you are responsible for:
If you are a resident of the European Union, you have the following rights under the General Data Protection Regulation (GDPR):
If you are a resident of California, you have rights under the California Consumer Privacy Act (CCPA):
Depending on your jurisdiction, you may have additional privacy rights. These may include rights similar to GDPR or CCPA in other regions (Canada’s PIPEDA, Australia’s Privacy Act, etc.). Please contact us to learn about your specific rights.
To exercise any of these rights, please submit a request through our privacy portal or by contacting us at privacy@sqlstudio.io. We will verify your identity and respond within the timeframe required by applicable law (typically 30-45 days).
You can control cookie preferences through your browser settings. Most browsers allow you to refuse cookies or alert you when cookies are being sent. However, disabling essential cookies may impact Service functionality.
We may use other tracking technologies including:
Some browsers include a “Do Not Track” feature. Our Service does not currently respond to Do Not Track signals, but you can disable tracking through browser settings and privacy extensions.
The Service is not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided information to us, we will delete such information immediately.
If you believe we have collected information from a child under 13, please contact us immediately at privacy@sqlstudio.io.
The Service may contain links to third-party websites and services. This Privacy Policy applies only to SQL Studio. We are not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party services before providing your information.
When you sign in via Google OAuth, you are subject to Google’s privacy policies in addition to ours. Google processes your authentication information according to their policies.
When you connect to external databases (PostgreSQL, MySQL, MSSQL, etc.), those providers may collect logs and metadata as specified in their terms. We are not responsible for their data practices.
If you are subject to HIPAA and process health information through the Service, we can execute a Business Associate Agreement (BAA) to ensure compliance.
If you are subject to GDPR or similar regulations, we can execute a Data Processing Agreement (DPA) that outlines our obligations as a data processor.
Organizations with specific data protection requirements can contact us to negotiate custom data handling agreements.
You can view your account’s audit log through the Settings > Audit Logs page. This log includes:
Audit logs capture:
We retain audit logs for a minimum of 1 year for security, compliance, and investigation purposes. Certain audit logs may be retained longer if required by applicable law.
Your information may be transferred to and stored in countries other than your country of residence. These countries may have different data protection laws than your country of origin.
When we transfer data internationally, we implement appropriate safeguards including:
For EU users, we comply with applicable data protection frameworks for transferring data to the United States. Please contact us if you have questions about international data transfer mechanisms.
In the event of a confirmed data breach involving your personal information, we will:
If you suspect a security breach, please contact us immediately at security@sqlstudio.io.
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. The date of the most recent update appears at the top of this page.
If we make material changes to how we handle your information, we will notify you by email or through the Service. Your continued use of the Service after such notification constitutes your acceptance of the revised Privacy Policy.
Previous versions of this Privacy Policy are available upon request.
If you have questions about this Privacy Policy, your information, or your privacy rights, please contact us:
Email: privacy@sqlstudio.io
Data Protection Officer: dpo@sqlstudio.io
Website: https://sqlstudio.io
Support Portal: https://sqlstudio.io/support
This Privacy Policy and our data practices comply with applicable privacy and data protection laws, including:
SQL Studio maintains industry certifications and complies with security standards including ISO 27001 and SOC 2 Type II (where applicable).
We undergo regular third-party audits to verify our compliance with privacy and security standards. Audit reports are available to enterprise customers under NDA.
You can delete your account through Settings > Account > Delete Account. Upon deletion:
After account deletion, we retain:
To request permanent deletion of all data including backup data, please contact privacy@sqlstudio.io with your account details and reason for deletion.
By accessing and using SQL Studio, you acknowledge that you have read this Privacy Policy, understand our privacy practices, and consent to the collection, use, and disclosure of your information as described herein.
If you do not agree with our privacy practices, please do not use the Service.
SQL Studio Privacy Policy © 2025. All rights reserved. This Privacy Policy is provided for informational purposes and should be reviewed by legal counsel before deployment in production. Customize with your specific data practices, compliance certifications, and contact information.