Privacy Policy

Draft — pending legal review

This document is a working draft published so the structure and scope are visible. It has not yet been reviewed by counsel and is not a binding legal commitment. If you need a reviewed policy or a data processing agreement before you can proceed, contact us at hello@cognodb.com and we will tell you where we are.

What this covers

This policy describes how CognoDB handles information in connection with the CognoDB Cloud service and this website. It does not describe how our customers handle the data they choose to store in their own database instances.

Two different kinds of data

It matters which is which, because our role differs between them.

  • Account information — the details you give us to create and operate an account: name, email address, organization, billing details, and records of actions taken in the console. We decide how this is used, and this policy governs it.
  • Database contents — whatever you store in your instances. We process it on your instruction in order to run the service. We do not read it, mine it, or use it to train anything. You decide what goes in and what comes out.

What we collect

  • Account and contact details you provide at signup, or that your identity provider supplies if your organization uses single sign-on.
  • Billing information necessary to charge for paid instances. Card details are handled by our payment processor; we do not store them.
  • Operational telemetry about your instances — resource usage, error rates, connection counts — used to run, bill and support the service.
  • An audit record of state-changing actions in the console and API, including who performed them and the originating address.
  • Standard web logs for this site and the console.

What we do with it

Operate and secure the service, calculate and collect payment, respond to support requests, investigate abuse or security incidents, and meet legal obligations. We do not sell personal information, and we do not use customer database contents for any purpose other than running the service you asked for.

Where it lives

Instances run in the region you choose at creation — currently us-east4 (Northern Virginia), us-central1 (Iowa) or europe-west1 (Belgium) — and instance data stays in that region. Account and billing records are held in our systems, which may be located elsewhere.

Retention

Deleted instances are retained for 30 days with a final snapshot before permanent removal, so an accidental deletion is recoverable. Account records are kept while your account is active and for as long afterwards as we need for legal, tax and accounting purposes.

Sharing

We use third-party infrastructure and service providers to run CognoDB Cloud — cloud hosting, payment processing, email delivery and error monitoring. They receive only what they need to perform their function. A complete sub-processor list will accompany the reviewed version of this policy.

Your rights

Depending on where you are, you may have rights to access, correct, export or delete personal information we hold about you, and to object to or restrict certain processing. You can export your database contents yourself at any time. For anything else, contact us at hello@cognodb.com.

Security

Connections are encrypted in transit, instance storage and backups are encrypted at rest, credentials are stored only as hashes, and organizations are isolated from one another at the network level. The security page describes the controls in more detail.

Changes

When this policy changes materially we will tell account holders before the change takes effect.

Contact

Questions about this policy go to hello@cognodb.com.