Privacy Policy
Effective date: January 1, 2026 — Last updated: May 1, 2026
Introduction
DataRunner ("we", "us", "our") operates the DataRunner platform accessible at datarunner.io and associated subdomains (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using the Service, you consent to the practices described in this policy. If you do not agree with the terms of this policy, please do not access the Service.
Information we collect
Account information
When you create an account, we collect:
- Name and email address
- Password (stored as a bcrypt hash — we never store plaintext passwords)
- Workspace name and configuration
- Billing information (processed by Stripe; we do not store raw card data)
Database connection credentials
To connect to your databases, we collect and store the credentials you provide: host, port, database name, username, and password. These credentials are encrypted at rest using AES-256 and are used solely to execute queries and test connections on your behalf. Credentials are never shared with third parties and are not used for any other purpose.
Query and report data
We store the SQL queries, report configurations, schedules, and watch configurations you create. Query results are stored temporarily for delivery and history purposes and are retained for the duration specified by your plan (30 days for Free, 1 year for Pro).
Usage data
We automatically collect information about how you use the Service, including:
- Log data (IP address, browser type, pages visited, timestamps)
- Feature usage metrics (which features are used and how often)
- Error reports and performance data
This data is used to improve the Service, fix bugs, and understand usage patterns. It is not sold or shared with advertisers.
Communications
If you contact us via email or the contact form, we retain that communication to respond to your inquiry and improve our support.
How we use your information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process payments and manage subscriptions
- Send transactional emails (reports, alerts, delivery confirmations)
- Respond to support requests
- Analyze usage to improve features and performance
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not use your data for advertising. We do not sell your personal information or database contents to third parties.
Data retention
We retain your account data for as long as your account is active. Query results and run history are retained according to your plan limits. After account deletion, we permanently delete all associated data within 30 days, except where retention is required by law (e.g., billing records).
Data security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.2 or higher
- Database credentials are encrypted at rest using AES-256
- Passwords are hashed with bcrypt (never stored in plaintext)
- Access to production systems is restricted and audited
- Backups are encrypted and stored in geographically separate locations
No method of transmission over the internet is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
Third-party services
We use the following third-party services to operate the Service:
- Stripe— payment processing. Stripe's privacy policy governs their handling of payment data.
- SMTP providers — for sending transactional emails on your behalf (reports, alerts). You can configure your own SMTP server in Settings.
- Cloud infrastructure providers — for hosting and data storage. Data is stored in the EU and/or US depending on your workspace region.
We do not use third-party analytics services that track users across websites (e.g., Google Analytics).
Enterprise self-hosted
The DataRunner Enterprise edition is deployed entirely on your own infrastructure. In this case, DataRunner (the company) does not receive, process, or have access to any of your data, credentials, or query results. This Privacy Policy does not apply to self-hosted deployments.
Your rights
Depending on your location, you may have the following rights with respect to your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate data
- Deletion — request deletion of your personal data (subject to legal retention requirements)
- Portability — request export of your data in a machine-readable format
- Objection — object to certain types of processing
To exercise any of these rights, contact us at privacy@datarunner.io. We will respond within 30 days.
Cookies
We use strictly necessary cookies to operate the Service (session management, CSRF protection). We do not use advertising cookies or third-party tracking cookies.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service. Continued use after notification constitutes acceptance of the updated policy.
Contact
Questions about this Privacy Policy? Contact us at privacy@datarunner.io or via the contact form.