Privacy Policy
Last updated: September 14, 2026
dbOrbit connects your phone straight to your database. For the engines it connects to directly, your credentials, queries and results travel between your device and your database and nowhere else. This policy explains what we do collect, the few features that use our servers, and the rights you have over your information.
1. What Stays on Your Device
Your connections (including passwords and SSH keys), saved queries, query history, PIN hash and recovery email address are stored on your device in the iOS Keychain or Android Keystore. The schema cache — the table and column names used for browsing and autocomplete — is written to files inside the app’s private storage, and app settings are kept in the app’s local storage.
A second encryption layer for the local store (SQLCipher) is in development. Until it ships, data on the device is protected by the platform keystore and the operating system’s own storage encryption.
Data leaves your device only in the cases described in Sections 2 and 3.
2. Data We Collect
We collect usage analytics and crash reports to find bugs and understand which features are used. Before an analytics event is sent, an on-device scrubber removes fields that could hold sensitive values, reduces SQL to its leading keyword (for example, SELECT), and masks email addresses, IPv4 addresses and database connection URLs.
Product analytics (Mixpanel)
- App events: app opened, backgrounded and foregrounded; app locked and unlocked; connections created, edited, tested, activated and deleted; GitHub backup connected, disconnected, run and restored
- Event details such as the database engine type, whether SSH is enabled, connection latency, and error messages
- Platform, operating-system version, app version, and device brand or model
- A randomly generated install identifier, which we do not link to your name, email address or any account
- Your IP address, which Mixpanel uses to estimate an approximate location (country and city)
Crash and performance reporting (Sentry)
- Stack traces, error messages, device model and operating-system version
- Performance traces for a sample of sessions, and whether a session ended in a crash
- Breadcrumbs leading up to an error: the screens you visited and the web addresses of requests the app made, for example to our servers or to GitHub
Error messages can contain a database hostname or an object name such as a table name, because the scrubber masks IP addresses and connection URLs but not bare hostnames or identifiers.
The app does not currently have a setting to turn analytics or crash reporting off. If you object to this processing, contact us (Section 13).
Support requests
When you use Settings → Contact support, we receive the email address you enter, your message, and your app version, platform and build number. The message is delivered to our support inbox by ZeptoMail.
Subscriptions
Purchases are handled by the App Store or Google Play and synced by RevenueCat. RevenueCat identifies you with an anonymous ID, or with your recovery email address if you have set one.
3. Features That Use Our Servers
A few features cannot work from the device alone. When you use them, the data below passes through servers operated by Metronio Technologies.
- Recovery email and one-time codes — to email you a verification code or temporary PIN, the app sends your recovery email address and the message to our email service, which delivers it through ZeptoMail. Codes are generated and checked on your device. Our email service keeps a delivery log of the recipient address and message subject.
- MongoDB Atlas (coming soon) — Atlas connections are relayed through our proxy because they need DNS SRV lookups the device cannot perform. The connection string, including credentials, and the commands and documents you send and receive pass through the proxy.
- dbOrbit-hosted SQLite (coming soon) — hosted databases are stored on our servers. Your hosted-database email address and PIN, the SQL you run and its results are processed there.
- GitHub backup — the backup itself goes to your own GitHub repository (Section 6). Signing in to GitHub exchanges an authorisation code for an access token through our server, and after each backup the app sends your GitHub username, email address, repository name and commit identifier to our server.
4. Data We Don’t Collect
For databases the app connects to directly — every engine except MongoDB Atlas and dbOrbit-hosted SQLite — the following never pass through our servers:
- Database passwords, SSH private keys or other connection credentials
- SQL query text, query results, execution plans or query parameters
- Data stored in or retrieved from your databases
Whichever engine you use, we never collect:
- Your app PIN or biometric data — Face ID and fingerprint checks happen inside the operating system
- Keystroke logs, clipboard contents, screen recordings or screenshots
5. Third-Party Services
The following processors are involved in delivering the service:
- Mixpanel — product analytics, including IP-based approximate location (privacy policy)
- Sentry — crash and performance reporting (privacy policy)
- RevenueCat — subscription state and entitlement sync (privacy policy)
- ZeptoMail (Zoho) — delivery of verification codes and support messages (privacy policy)
- GitHub — when you enable encrypted backup, your encrypted backup is stored in your own GitHub repository (privacy policy)
- Apple App Store / Google Play — app distribution and in-app purchase processing (subject to platform privacy policies)
We do not sell, rent, or trade personal information to any third party for marketing purposes.
6. Encryption & Security
Credentials, SSH keys, saved queries, query history and your PIN hash are stored in the iOS Keychain or Android Keystore. Your PIN is stored as a PBKDF2-SHA256 hash. Connections to your databases use TLS when it is enabled for the connection, and SSH tunnelling uses SSHv2 with password or key authentication.
Optional GitHub backups contain your connections (including credentials), settings and, if you choose, saved queries and history. They are encrypted on the device with AES-256-GCM, using a key derived from your PIN, before they are uploaded. Commit messages in the backup repository include your GitHub username and email address and the number of items backed up.
SQLCipher encryption of the local store is in development and not yet active. For a deeper technical overview, see our Security page.
7. Data Retention
- Local data — retained on your device until you uninstall the app or use Settings → Biometric & PIN → Clear All Data. Clear All Data removes what is held in the Keychain or Keystore; some app settings remain until you uninstall
- Analytics events — retained for up to 12 months, then aggregated and deleted
- Crash and performance reports — retained for 90 days
- Hosted database data — retained for 30 days after subscription cancellation
- Customer support correspondence — retained for 24 months from the date of last contact
- Subscription / billing records — retained as required by tax and accounting laws (typically 7 years)
8. Your Rights — GDPR (European Economic Area, UK, Switzerland)
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation and equivalent laws:
- Right of access — request a copy of personal data we process about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion of your personal data, subject to legal retention obligations
- Right to restriction of processing — request that we limit processing in certain circumstances
- Right to data portability — receive your data in a structured, commonly used, machine-readable format
- Right to object — object to processing based on legitimate interests, including analytics
- Right to withdraw consent — withdraw any consent previously given, without affecting the lawfulness of processing prior to withdrawal
- Right to lodge a complaint — with your local data protection authority
The legal bases on which we rely are: performance of a contract (delivering the app, any subscription you have purchased, and features you ask for such as recovery email, hosted databases and backups) and legitimate interests (analytics and crash reporting to improve and secure the app, and preventing abuse). To exercise any right, email support@dborbit.io. We respond within 30 days. Step-by-step deletion instructions are on Delete your data.
9. Your Rights — CCPA / CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know — what personal information we collect, the sources, purposes, and any third parties with whom it is shared
- Right to delete — request deletion of personal information we have collected
- Right to correct — request correction of inaccurate personal information
- Right to opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising
- Right to limit use of sensitive personal information — we do not collect sensitive personal information beyond what is described in this policy
- Right of non-discrimination — you will not receive degraded service for exercising any of these rights
We do not sell or share your personal information. We have not done so in the prior 12 months and have no plans to do so.
To exercise these rights, email support@dborbit.io. dbOrbit has no user accounts, so we will verify your request using the email address you contact us from, and respond within 45 days, with one 45-day extension permitted under the CCPA.
10. International Data Transfers
dbOrbit operates from the United States. Analytics may be processed by Mixpanel (United States) and Sentry (United States, with a European data-region option). Where personal data is transferred from the EEA, UK, or Switzerland to the United States or another third country, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, as supplemented by the UK International Data Transfer Addendum where applicable
- The EU-U.S. Data Privacy Framework (or its successor mechanism) where the recipient is certified
- Additional safeguards such as encryption in transit (TLS)
11. Children’s Privacy
dbOrbit is a developer tool and is not directed to children under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us at support@dborbit.io and we will delete it. This policy is consistent with the Children’s Online Privacy Protection Act (COPPA) and the GDPR’s Article 8 protections for children.
Classroom features for schools are not yet available. We will update this section before they launch.
12. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of the page reflects the latest revision. Material changes — those that meaningfully expand the scope of data collection or change the legal basis for processing — will be communicated via in-app notification at least 14 days before they take effect. Continued use of the app after the effective date constitutes acceptance of the revised policy.
13. Contact
For privacy questions, data subject requests, or any other matter related to this policy, please contact:
- Email: support@dborbit.io
- Subject line: "Privacy request" — for fastest routing
- Postal: Metronio Technologies (postal address available on request)
For users in the EEA / UK, you may also lodge a complaint with your local supervisory authority.