Skip to content

Legal

Privacy Policy

This policy explains what data DataRunner collects, why, for how long, and what you can do about it. It covers the datarunner.app site, the console at console.datarunner.app, the desktop app and the monitoring agent.

Last updated2 September 2026

Two different roles

For your account and usage data we are the controller. For the data inside your database, and for the contacts you upload, we are only a processor: you decide what goes in, what it is for, and how long it stays. We run what you configured and nothing beyond it.

What we collect

CategoryWhat it isWhy
AccountName, email, hashed password, workspace and roleAuthentication and access control
Connection credentialsHost, port, database, user and password for your databaseTo run the queries you scheduled
Queries and resultsThe SQL you write, the report configuration, and the result of each runTo deliver the report and keep the history
Host metricsCPU, memory, disk, network and similar, pushed by the agentTo monitor servers and open incidents
UsageIP address, browser, access time and actions recorded in the audit logSecurity, diagnostics and plan limits
BillingPlan, subscription status and Stripe identifiersTo invoice. Card numbers never pass through us

We do not collect data from your database on our own initiative. We read only what your query asks for, when your schedule says so, and keep the result for your plan’s retention period.

What we use it for

  • Operating the service: running queries, delivering reports, running checks and opening incidents.
  • Keeping accounts safe: detecting unauthorised access, enforcing limits, recording an audit trail.
  • Billing paid plans and resolving payment problems.
  • Answering you when you write to us.
  • Meeting a legal obligation where one exists.

We do not sell personal data, do not share it with third parties for advertising, and do not use the content of your queries or results to train any model.

Who we share it with

WhoFor whatWhat they receive
StripePayment processingBilling data. Card details are entered directly with them
Cloud infrastructure providerHosting the application, database and filesThe data at rest and in processing
Email providerDelivering service email and your reports, when you do not use your own SMTPRecipient, subject and content of the send
Meta and TelegramDelivering messages, when you configure those channelsOnly the content you asked to be delivered there

Each receives the minimum needed to do its part and is contractually barred from using the data for anything else. If a subprocessor changes materially, this list changes with it.

How long we keep it

  • Run results and history: 30 days on the free plan, one year on Pro, three years on Business.
  • Full-resolution host metrics: 7, 30 or 90 days depending on plan.
  • Operational and audit records: 30, 180 or 365 days depending on plan.
  • Account data: for as long as the account exists, plus any applicable legal period.

Deletion runs as an automatic routine rather than on manual request — which means it happens even when nobody is watching.

Security

  • Connection credentials and channel configuration are encrypted at rest with AES-GCM.
  • Passwords use bcrypt at work factor 12; they are not reversible and never appear in logs.
  • Traffic uses TLS; the connection to your database uses TLS when the server offers it.
  • A saved password is never returned by the API. On edit, the field comes back empty.
  • Business workspaces can encrypt with their own key instead of ours.
  • Sensitive actions are recorded in an audit log, with actor and timestamp.

No system is impenetrable and we are not going to claim otherwise. What we do commit to is reducing surface, recording what happens, and telling you plainly if something goes wrong.

Your rights

You may confirm processing, access, correct, port, object, and request deletion of your data. Two of those need no request at all: in the console you export your personal data in a machine-readable format, and you request account deletion, which enters a grace period before permanent removal and can be cancelled within it.

For the rest, write to privacy@datarunner.app. We answer within 15 days. If you believe we handled something improperly, you may complain to your country’s data protection authority — in Brazil, the ANPD.

Cookies

This site uses only what is strictly necessary — in practice, it stores just your theme preference in the browser. There is no advertising cookie, no cross-site tracking, and no third-party analytics tool loaded on this page. The console uses session cookies to keep you signed in; without them there is no way to log in.

International transfers

Our infrastructure and some subprocessors are outside Brazil. When your data leaves the country it travels under the contractual safeguards required by the LGPD and the GDPR, and stays limited to the purposes described here.

Minors

The service is for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors; if it happens, we delete it as soon as we know.

Changes to this policy

When there is a material change we notify you by email and update the date at the top of this page before it takes effect. The version history lives in the site’s public repository.

Contact

  • Privacy and data protection officer: privacy@datarunner.app
  • Security: security@datarunner.app
  • Support: support@datarunner.app