Privacy Policy

Version 2026-08-27 · effective 27 August 2026 · draft, pending legal review

This document is a working draft published so the structure and scope are visible. It has not yet been reviewed by counsel and is not a binding legal commitment. If you need a reviewed policy or a data processing agreement before you can proceed, contact us at hello@cognodb.com and we will tell you where we are.

What this covers

This policy describes how CognoDB handles information in connection with the CognoDB service and this website. It does not describe how our customers handle the data they choose to store in their own database instances.

Two different kinds of data

It matters which is which, because our role differs between them.

  • Account information, the details you give us to create and operate an account: name, email address, organization, billing details, and records of actions taken in the console. We decide how this is used, and this policy governs it.
  • Database contents, whatever you store in your instances. We process it on your instruction in order to run the service. We do not read it, mine it, or use it to train anything. You decide what goes in and what comes out.

What we collect

  • Account and contact details you provide at signup, or that your identity provider supplies if your organization uses single sign-on.
  • Billing information necessary to charge for paid instances. Card details are handled by our payment processor; we do not store them.
  • Operational telemetry about your instances (resource usage, error rates, connection counts) used to run, bill and support the service.
  • An audit record of state-changing actions in the console and API, including who performed them and the originating address.
  • Standard web logs for this site and the console.

What we do with it

Operate and secure the service, calculate and collect payment, respond to support requests, investigate abuse or security incidents, and meet legal obligations. We do not sell personal information, and we do not use customer database contents for any purpose other than running the service you asked for.

Cookies and tracking

This site can load four third-party services. None of them runs until you choose, and you can change or withdraw that choice at any time from “Cookie settings” in the footer of every page. Your choice is recorded against the version of this policy shown above, so if this text changes materially you will be asked again.

Two things are always on and need no consent, because the site cannot do what you asked without them: your light/dark theme preference, and your cookie choice itself — we cannot honour “reject” without remembering that you rejected.

WhatProviderPurposeCategory
Google Analytics 4 (G-H3E84QT30H)GoogleCounting visits and which pages are used.Analytics
PostHogPostHog, Inc. (US)Product analytics: page views and named events. Anonymous visitors are recorded as events only, without a person profile.Analytics
Google Ads (AW-18393289240)GoogleMeasuring whether an advert led to a signup.Advertising
CrispCrisp IM SAS (France)The live-chat widget, so you can start a conversation with us.Support

Each of these sets its own cookies or browser storage once you allow its category. We record your choice, the policy version it was given against, a truncated form of your IP address (the first three octets for IPv4, the first 48 bits for IPv6 — never the full address) and your browser’s user-agent string, so we can show what was agreed and when.

Where it lives

Instances run in the region you choose at creation, currently us-east4 (Northern Virginia), us-central1 (Iowa) or europe-west1 (Belgium), and instance data stays in that region. Account and billing records are held in us-east4 (Northern Virginia), in the United States, regardless of where your instances run.

Retention

Deleted instances are retained for 30 days with a final snapshot before permanent removal, so an accidental deletion is recoverable. Account records are kept while your account is active and for as long afterwards as we need for legal, tax and accounting purposes.

Sharing

We use third-party infrastructure and service providers to run CognoDB: cloud hosting, payment processing, email delivery and error monitoring, plus the analytics, advertising and support services named under “Cookies and tracking” above. They receive only what they need to perform their function. A complete sub-processor list, with each provider’s location and purpose, accompanies the reviewed version of this policy; the four browser-side services are named in full above in the meantime.

Your rights

Depending on where you are, you may have rights to access, correct, export or delete personal information we hold about you, and to object to or restrict certain processing. You can export your database contents yourself at any time. For anything else, contact us at hello@cognodb.com.

Security

Connections are encrypted in transit, instance storage and backups are encrypted at rest, credentials are stored only as hashes, and organizations are isolated from one another at the network level. The security page describes the controls in more detail.

Changes

Every version of this policy carries an identifier, shown at the top of the page. Your recorded cookie choice stores that identifier, so a material change means your stored answer stops counting and you are asked again rather than being carried over silently.

VersionDateWhat changed
2026-08-2727 August 2026First version to carry a version identifier. Added the cookies and tracking section naming Google Analytics, Google Ads, PostHog and Crisp, and introduced the consent banner that gates all four.

When this policy changes materially we will tell account holders before the change takes effect.

Contact

Questions about this policy go to hello@cognodb.com.