Draft, pending legal review
This page describes how the product actually works and is written by the people who built it. It has not been reviewed by a lawyer and is not yet a binding agreement.
Privacy
The short version: we hold your backups as ciphertext we cannot read, the minimum account data needed to run the service, and analytics you can decline. We do not sell anything to anyone.
What we hold
| Data | Why | Can we read it? |
|---|---|---|
| Backup artifacts | The product | No. Encrypted on your machine with a key we never receive |
| Artifact metadata: size, checksum, timestamps, retention | Listing, retention, billing | Yes |
| Account: name, email, workspace membership | Sign-in and access control | Yes |
| Source credentials, cloud backups only | To connect to the database you asked us to | Held in a secrets vault, read at run time. Local backups never send them |
| Audit trail: who changed what, and when | Your record, and ours | Yes. Never contains a secret |
| Usage counters | Billing | Yes. Quantities only, never content |
What we cannot do
Backup data is encrypted before it leaves the machine that produced it, with a public key you supply. We store the result and never receive the private half.
We cannot decrypt your backups. We cannot recover them if you lose your key, and we cannot produce their contents in response to a request from anyone, including a legal one. We can only produce the ciphertext and the metadata listed above.
Who else processes it
We use a small number of providers. Each is listed with what it actually receives.
| Provider | Purpose | What it receives |
|---|---|---|
| WorkOS | Sign-in and organisations | Name, email, workspace membership |
| Stripe | Payments and invoicing | Billing details, usage quantities. We never see your card |
| Amazon S3 | Artifact storage | Encrypted artifacts |
| Oracle Cloud | Compute for the service | Runs the application; holds no plaintext backup data |
| Google Analytics | Traffic on this marketing site | Page views and referrers, only if you accept. Nothing from the product itself |
| Grafana Cloud | Infrastructure metrics | Machine metrics. No customer data |
Analytics and cookies
This marketing site uses Google Analytics to count visits, and only if you accept it. Decline and it is never initialised. There is no advertising network, no cross-site tracking pixel, and no analytics of any kind inside the product dashboard today.
We also use Google Search Console to see which searches lead here. It reports from Google’s own index and receives nothing from us.
How long we keep things
- Artifacts are kept for as long as the retention policy you set says, then deleted. If you set a protection lock, they cannot be deleted before it expires, including by us.
- Run history is available for 30 days.
- Audit entries are kept for the life of the workspace.
- A closed or unpaid account keeps its data for a year before anything is deleted, and downloads keep working throughout.
Your data, on the way out
You can download every artifact you hold, at any time, in every account state. Artifacts are self-describing and open with standard tools, so leaving does not require our cooperation or our continued existence.
Requests
To see, correct or delete the account data we hold, email us from the address on the account. We will tell you what we hold and what we cannot produce, which for backup contents is everything.