Legal

Privacy Policy

Effective date: January 1, 2026 — Last updated: May 1, 2026

Introduction

DataRunner ("we", "us", "our") operates the DataRunner platform accessible at datarunner.io and associated subdomains (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using the Service, you consent to the practices described in this policy. If you do not agree with the terms of this policy, please do not access the Service.

Information we collect

Account information

When you create an account, we collect:

  • Name and email address
  • Password (stored as a bcrypt hash — we never store plaintext passwords)
  • Workspace name and configuration
  • Billing information (processed by Stripe; we do not store raw card data)

Database connection credentials

To connect to your databases, we collect and store the credentials you provide: host, port, database name, username, and password. These credentials are encrypted at rest using AES-256 and are used solely to execute queries and test connections on your behalf. Credentials are never shared with third parties and are not used for any other purpose.

Query and report data

We store the SQL queries, report configurations, schedules, and watch configurations you create. Query results are stored temporarily for delivery and history purposes and are retained for the duration specified by your plan (30 days for Free, 1 year for Pro).

Usage data

We automatically collect information about how you use the Service, including:

  • Log data (IP address, browser type, pages visited, timestamps)
  • Feature usage metrics (which features are used and how often)
  • Error reports and performance data

This data is used to improve the Service, fix bugs, and understand usage patterns. It is not sold or shared with advertisers.

Communications

If you contact us via email or the contact form, we retain that communication to respond to your inquiry and improve our support.

How we use your information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process payments and manage subscriptions
  • Send transactional emails (reports, alerts, delivery confirmations)
  • Respond to support requests
  • Analyze usage to improve features and performance
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not use your data for advertising. We do not sell your personal information or database contents to third parties.

Data retention

We retain your account data for as long as your account is active. Query results and run history are retained according to your plan limits. After account deletion, we permanently delete all associated data within 30 days, except where retention is required by law (e.g., billing records).

Data security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Database credentials are encrypted at rest using AES-256
  • Passwords are hashed with bcrypt (never stored in plaintext)
  • Access to production systems is restricted and audited
  • Backups are encrypted and stored in geographically separate locations

No method of transmission over the internet is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.

Third-party services

We use the following third-party services to operate the Service:

  • Stripe— payment processing. Stripe's privacy policy governs their handling of payment data.
  • SMTP providers — for sending transactional emails on your behalf (reports, alerts). You can configure your own SMTP server in Settings.
  • Cloud infrastructure providers — for hosting and data storage. Data is stored in the EU and/or US depending on your workspace region.

We do not use third-party analytics services that track users across websites (e.g., Google Analytics).

Enterprise self-hosted

The DataRunner Enterprise edition is deployed entirely on your own infrastructure. In this case, DataRunner (the company) does not receive, process, or have access to any of your data, credentials, or query results. This Privacy Policy does not apply to self-hosted deployments.

Your rights

Depending on your location, you may have the following rights with respect to your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your personal data (subject to legal retention requirements)
  • Portability — request export of your data in a machine-readable format
  • Objection — object to certain types of processing

To exercise any of these rights, contact us at privacy@datarunner.io. We will respond within 30 days.

Cookies

We use strictly necessary cookies to operate the Service (session management, CSRF protection). We do not use advertising cookies or third-party tracking cookies.

Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service. Continued use after notification constitutes acceptance of the updated policy.

Contact

Questions about this Privacy Policy? Contact us at privacy@datarunner.io or via the contact form.