Two different roles
For your account and usage data we are the controller. For the data inside your database, and for the contacts you upload, we are only a processor: you decide what goes in, what it is for, and how long it stays. We run what you configured and nothing beyond it.
What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Name, email, hashed password, workspace and role | Authentication and access control |
| Connection credentials | Host, port, database, user and password for your database | To run the queries you scheduled |
| Queries and results | The SQL you write, the report configuration, and the result of each run | To deliver the report and keep the history |
| Host metrics | CPU, memory, disk, network and similar, pushed by the agent | To monitor servers and open incidents |
| Usage | IP address, browser, access time and actions recorded in the audit log | Security, diagnostics and plan limits |
| Billing | Plan, subscription status and Stripe identifiers | To invoice. Card numbers never pass through us |
We do not collect data from your database on our own initiative. We read only what your query asks for, when your schedule says so, and keep the result for your plan’s retention period.
What we use it for
- Operating the service: running queries, delivering reports, running checks and opening incidents.
- Keeping accounts safe: detecting unauthorised access, enforcing limits, recording an audit trail.
- Billing paid plans and resolving payment problems.
- Answering you when you write to us.
- Meeting a legal obligation where one exists.
We do not sell personal data, do not share it with third parties for advertising, and do not use the content of your queries or results to train any model.
Legal basis
- Performance of a contract — everything needed for the service to work for you.
- Legitimate interest — security, abuse prevention and diagnostics, always at the minimum necessary.
- Legal obligation — tax records and responses to a competent authority.
- Consent — only where it is actually asked for, and revocable at any time.
Who we share it with
| Who | For what | What they receive |
|---|---|---|
| Stripe | Payment processing | Billing data. Card details are entered directly with them |
| Cloud infrastructure provider | Hosting the application, database and files | The data at rest and in processing |
| Email provider | Delivering service email and your reports, when you do not use your own SMTP | Recipient, subject and content of the send |
| Meta and Telegram | Delivering messages, when you configure those channels | Only the content you asked to be delivered there |
Each receives the minimum needed to do its part and is contractually barred from using the data for anything else. If a subprocessor changes materially, this list changes with it.
How long we keep it
- Run results and history: 30 days on the free plan, one year on Pro, three years on Business.
- Full-resolution host metrics: 7, 30 or 90 days depending on plan.
- Operational and audit records: 30, 180 or 365 days depending on plan.
- Account data: for as long as the account exists, plus any applicable legal period.
Deletion runs as an automatic routine rather than on manual request — which means it happens even when nobody is watching.
Security
- Connection credentials and channel configuration are encrypted at rest with AES-GCM.
- Passwords use bcrypt at work factor 12; they are not reversible and never appear in logs.
- Traffic uses TLS; the connection to your database uses TLS when the server offers it.
- A saved password is never returned by the API. On edit, the field comes back empty.
- Business workspaces can encrypt with their own key instead of ours.
- Sensitive actions are recorded in an audit log, with actor and timestamp.
No system is impenetrable and we are not going to claim otherwise. What we do commit to is reducing surface, recording what happens, and telling you plainly if something goes wrong.
Your rights
You may confirm processing, access, correct, port, object, and request deletion of your data. Two of those need no request at all: in the console you export your personal data in a machine-readable format, and you request account deletion, which enters a grace period before permanent removal and can be cancelled within it.
For the rest, write to privacy@datarunner.app. We answer within 15 days. If you believe we handled something improperly, you may complain to your country’s data protection authority — in Brazil, the ANPD.
International transfers
Our infrastructure and some subprocessors are outside Brazil. When your data leaves the country it travels under the contractual safeguards required by the LGPD and the GDPR, and stays limited to the purposes described here.
Minors
The service is for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors; if it happens, we delete it as soon as we know.
Changes to this policy
When there is a material change we notify you by email and update the date at the top of this page before it takes effect. The version history lives in the site’s public repository.
Contact
- Privacy and data protection officer: privacy@datarunner.app
- Security: security@datarunner.app
- Support: support@datarunner.app