Privacy

Draft. Have this reviewed by a lawyer before launch.

What we collect

The database connection string you submit (used for one scan and not stored), the scan findings (see Retention), the account details you give us if you sign up (email, optional name, and a hashed password or your GitHub or Google account id), your email if you join the waitlist and standard server logs (IP address, timestamps). Payments are processed by Paystack; we receive confirmation of payment, not card details.

If you file a support ticket or feature request, we keep what you write, your email and name (if given), and any report link you attach. These are sent to us by email so we can reply and work on them.

Product analytics

We measure how far people get through the product: landing page, sample report, scan started, scan finished or failed, checkout started, payment succeeded, and report downloaded or shared. This is how we find out where the product is broken, for example whether people are abandoning at the connection screen.

These events are processed by PostHog. They carry an anonymous random id from a first-party cookie, counts of findings by severity, your database provider and version, and your country when our hosting provider supplies it, and nothing else. Your IP address is not sent. They never carry your connection string, your query text, your table or index names, your findings, or the link to your report: a report link is the secret that opens it, so only a one-way hash of it is sent, which is enough to group one report's events together and cannot be turned back into the link.

We do not use these events for advertising, and we do not sell them.

How we use it

To run your scan, show you the report, process payment, and operate and secure the service. We do not sell data or use your findings for advertising.

Retention

Without an account, scan results are deleted automatically 7 days after the scan. With a free account they are kept 30 days, and a report you unlock is kept until you delete it or your account. Deleting your account removes your saved reports and sign-in details. Payment records (amount, date, payment reference) are kept for bookkeeping. Waitlist emails are kept until you ask us to remove them.

Your data in your database

Checkups read database statistics and catalog metadata only, never table contents. See Security & database access.

Related

Security & database access sets out the exact permissions a checkup needs. Refunds & re-runs covers failed scans and unusable reports.

Contact

Add a contact address here before launch.