Privacy Policy

1. What Stays on Your Device

Your connections (including passwords and SSH keys), saved queries, query history, PIN hash and recovery email address are stored on your device in the iOS Keychain or Android Keystore. The schema cache — the table and column names used for browsing and autocomplete — is written to files inside the app’s private storage, and app settings are kept in the app’s local storage.

A second encryption layer for the local store (SQLCipher) is in development. Until it ships, data on the device is protected by the platform keystore and the operating system’s own storage encryption.

Data leaves your device only in the cases described in Sections 2 and 3.

2. Data We Collect

We collect usage analytics and crash reports to find bugs and understand which features are used. Before an analytics event is sent, an on-device scrubber removes fields that could hold sensitive values, reduces SQL to its leading keyword (for example, SELECT), and masks email addresses, IPv4 addresses and database connection URLs.

Product analytics (Mixpanel)

Crash and performance reporting (Sentry)

Error messages can contain a database hostname or an object name such as a table name, because the scrubber masks IP addresses and connection URLs but not bare hostnames or identifiers.

The app does not currently have a setting to turn analytics or crash reporting off. If you object to this processing, contact us (Section 13).

Support requests

When you use Settings → Contact support, we receive the email address you enter, your message, and your app version, platform and build number. The message is delivered to our support inbox by ZeptoMail.

Subscriptions

Purchases are handled by the App Store or Google Play and synced by RevenueCat. RevenueCat identifies you with an anonymous ID, or with your recovery email address if you have set one.

3. Features That Use Our Servers

A few features cannot work from the device alone. When you use them, the data below passes through servers operated by Metronio Technologies.

4. Data We Don’t Collect

For databases the app connects to directly — every engine except MongoDB Atlas and dbOrbit-hosted SQLite — the following never pass through our servers:

Whichever engine you use, we never collect:

5. Third-Party Services

The following processors are involved in delivering the service:

We do not sell, rent, or trade personal information to any third party for marketing purposes.

6. Encryption & Security

Credentials, SSH keys, saved queries, query history and your PIN hash are stored in the iOS Keychain or Android Keystore. Your PIN is stored as a PBKDF2-SHA256 hash. Connections to your databases use TLS when it is enabled for the connection, and SSH tunnelling uses SSHv2 with password or key authentication.

Optional GitHub backups contain your connections (including credentials), settings and, if you choose, saved queries and history. They are encrypted on the device with AES-256-GCM, using a key derived from your PIN, before they are uploaded. Commit messages in the backup repository include your GitHub username and email address and the number of items backed up.

SQLCipher encryption of the local store is in development and not yet active. For a deeper technical overview, see our Security page.

7. Data Retention

8. Your Rights — GDPR (European Economic Area, UK, Switzerland)

If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation and equivalent laws:

The legal bases on which we rely are: performance of a contract (delivering the app, any subscription you have purchased, and features you ask for such as recovery email, hosted databases and backups) and legitimate interests (analytics and crash reporting to improve and secure the app, and preventing abuse). To exercise any right, email support@dborbit.io. We respond within 30 days. Step-by-step deletion instructions are on Delete your data.

9. Your Rights — CCPA / CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:

To exercise these rights, email support@dborbit.io. dbOrbit has no user accounts, so we will verify your request using the email address you contact us from, and respond within 45 days, with one 45-day extension permitted under the CCPA.

10. International Data Transfers

dbOrbit operates from the United States. Analytics may be processed by Mixpanel (United States) and Sentry (United States, with a European data-region option). Where personal data is transferred from the EEA, UK, or Switzerland to the United States or another third country, we rely on:

11. Children’s Privacy

dbOrbit is a developer tool and is not directed to children under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us at support@dborbit.io and we will delete it. This policy is consistent with the Children’s Online Privacy Protection Act (COPPA) and the GDPR’s Article 8 protections for children.

Classroom features for schools are not yet available. We will update this section before they launch.

12. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of the page reflects the latest revision. Material changes — those that meaningfully expand the scope of data collection or change the legal basis for processing — will be communicated via in-app notification at least 14 days before they take effect. Continued use of the app after the effective date constitutes acceptance of the revised policy.

For privacy questions, data subject requests, or any other matter related to this policy, please contact:

For users in the EEA / UK, you may also lodge a complaint with your local supervisory authority.