Privacy Policy
Draft — pending legal review
What this covers
This policy describes how CognoDB handles information in connection with the CognoDB Cloud service and this website. It does not describe how our customers handle the data they choose to store in their own database instances.
Two different kinds of data
It matters which is which, because our role differs between them.
- Account information — the details you give us to create and operate an account: name, email address, organization, billing details, and records of actions taken in the console. We decide how this is used, and this policy governs it.
- Database contents — whatever you store in your instances. We process it on your instruction in order to run the service. We do not read it, mine it, or use it to train anything. You decide what goes in and what comes out.
What we collect
- Account and contact details you provide at signup, or that your identity provider supplies if your organization uses single sign-on.
- Billing information necessary to charge for paid instances. Card details are handled by our payment processor; we do not store them.
- Operational telemetry about your instances — resource usage, error rates, connection counts — used to run, bill and support the service.
- An audit record of state-changing actions in the console and API, including who performed them and the originating address.
- Standard web logs for this site and the console.
What we do with it
Operate and secure the service, calculate and collect payment, respond to support requests, investigate abuse or security incidents, and meet legal obligations. We do not sell personal information, and we do not use customer database contents for any purpose other than running the service you asked for.
Where it lives
Instances run in the region you choose at creation — currently us-east4 (Northern Virginia), us-central1 (Iowa) or europe-west1 (Belgium) — and instance data stays in that region. Account and billing records are held in our systems, which may be located elsewhere.
Retention
Deleted instances are retained for 30 days with a final snapshot before permanent removal, so an accidental deletion is recoverable. Account records are kept while your account is active and for as long afterwards as we need for legal, tax and accounting purposes.
Sharing
We use third-party infrastructure and service providers to run CognoDB Cloud — cloud hosting, payment processing, email delivery and error monitoring. They receive only what they need to perform their function. A complete sub-processor list will accompany the reviewed version of this policy.
Your rights
Depending on where you are, you may have rights to access, correct, export or delete personal information we hold about you, and to object to or restrict certain processing. You can export your database contents yourself at any time. For anything else, contact us at hello@cognodb.com.
Security
Connections are encrypted in transit, instance storage and backups are encrypted at rest, credentials are stored only as hashes, and organizations are isolated from one another at the network level. The security page describes the controls in more detail.
Changes
When this policy changes materially we will tell account holders before the change takes effect.
Contact
Questions about this policy go to hello@cognodb.com.