MyDBA Privacy Policy

Effective date: 16 September 2026

1. Who we are

MyDBA is a PostgreSQL monitoring service operated by Elastic Data Solutions Ltd, company number 16576593, trading as MyDBA. Our registered office is 61 Bridget Gardens, Newcastle Upon Tyne, NE13 9DD, United Kingdom. For privacy questions or requests, contact support@mydba.dev.

We act as controller for personal information used to operate our website, administer accounts, manage billing, provide support and communicate with you. When we process personal information in monitoring data on a customer's instructions, the customer determines its purpose and we act as processor under the applicable service and data-processing terms. If your information appears in a customer's telemetry, contact that customer first; we can help route requests.

2. Information we collect

InformationExamples and sources
Account and organizationName, email, account identifier, organization membership, role and settings, provided by you, an inviting administrator or our authentication provider.
Sign-in and securityAuthentication events, session information, IP address, browser/device information and service logs generated when you access the service.
BillingBilling contact, address, subscription, payment status and invoices, from you and Stripe. Stripe processes payment-card details.
Support and communicationsContact details, messages, attachments, chat content and newsletter preferences you supply.
Service usagePages and features used, signup events, account identifiers and campaign/referral information, where analytics is configured.
Monitoring and configurationPerformance metrics, query statistics and text, activity samples, schema metadata, collected EXPLAIN plans, connection settings, reports and alerts. PostgreSQL logs are collected when enabled.
CredentialsMonitored-database credentials and supported AI-provider keys supplied by authorized users for their configured purpose.

Collectors gather monitoring information rather than routine application-table exports. SQL text, activity samples, logs, plans and object definitions can still contain personal information or sensitive values. Normalization does not remove every such value. Avoid sending passwords or unnecessary personal information in support requests.

3. Google and GitHub sign-in

You can choose email authentication or an available social sign-in provider. Clerk handles social authentication. The provider shares the identity information you authorize, which may include your provider identifier, name, email addresses, verification status, profile image and basic profile details. Clerk manages the linked identity and session; MyDBA uses account identity to provide access to your account and organizations.

Google sign-in requests only openid, email and basic profile scopes. It does not request Gmail messages, Drive files, Calendar or contacts. GitHub sign-in requests read:user and user:email, without repository access. You enter your Google or GitHub password with that provider, not MyDBA.

We use this provider information for account creation, authentication, account management and related security or support. We do not sell it or use it for advertising targeting. MyDBA's use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including applicable Limited Use requirements.

You can revoke MyDBA's access through your Google or GitHub account settings. Revocation does not itself delete your MyDBA account or previously stored records. Contact us for deletion or help arranging another sign-in method. Providers also apply their own privacy policies to their processing.

4. Purposes and lawful bases

Where UK or EU data-protection law applies, the following describes our own controller processing.

PurposeBasis
Provide an individual subscriber's account and servicePerformance of our contract with that person.
Administer a business customer's users, invitations and accessLegitimate interests in delivering and securing the customer's service.
Support and necessary service communicationsContract where applicable; otherwise legitimate interests in operating the service and resolving requests.
Prevent abuse, investigate failures and protect accountsLegitimate interests in security, reliability and fraud prevention; legal obligation where a specific requirement applies.
Payments, invoices and record keepingContract or legitimate interests in business-account administration; applicable accounting and tax obligations.
Usage measurement and product improvementLegitimate interests in understanding usage and improving reliability and usability; consent where required for the relevant tracking technology.
Optional newsletters and marketingConsent where required, with an unsubscribe option.
Legal requests and disputesApplicable legal obligations and legitimate interests in establishing or defending legal claims.

We need certain account and payment information to provide the corresponding service. Optional profile details, social sign-in and optional analysis are choices. Unsubscribing from marketing does not stop necessary service messages. We do not make decisions with legal or similarly significant effects about you solely through automated processing.

5. Cookies, analytics and support chat

Cookies and browser storage maintain sessions, remember settings and support account flows. Blocking necessary storage may prevent sign-in or interrupt the service. Where configured, PostHog measures usage and acquisition, including page visits and signup events, and can associate usage with your account identifier. Its implementation uses cookies and local storage. The tawk.to support widget loads when you request chat and receives browser/request information and messages.

We also use Vercel Web Analytics to understand visits and page usage. Analytics may include browser and device characteristics, interaction events and referral information. We do not describe all analytics as anonymous: authenticated usage can be associated with an account identifier.

You can control cookies and local storage through your browser settings, including blocking or clearing them. Clearing storage can sign you out or reset preferences. You can use email support instead of chat. Contact us about the analytics and storage applicable to your account or to object to usage analysis based on legitimate interests. Withdrawing consent, where it is the basis for processing, does not affect prior lawful processing.

6. Collectors and optional AI

A self-hosted collector still sends telemetry to hosted MyDBA. This differs from hosting the full platform on your own infrastructure. Dashboard-managed database credentials are stored by MyDBA even for a self-hosted collector. Local YAML configuration can keep monitored-database credentials on the collector host. Full-platform deployments depend on their configuration and enabled integrations.

Optional AI requests pass through MyDBA's AI server to the configured provider. They can include query text, plans, schema metadata and diagnostic context. Built-in analysis uses OpenRouter and its downstream model provider. Customer keys support OpenRouter, OpenAI and Anthropic; bringing a key does not bypass MyDBA's server. Organization administrators can disable AI-provider requests while continuing to use monitoring features.

Provider retention and model-training practices depend on the provider, route, account settings and agreements. We do not promise universal zero retention or identical training restrictions. Review the applicable terms before sending sensitive context. See AI data handling.

7. Who receives information

We share information with service providers for the functions described here, with authorized organization members according to their access, and with notification recipients configured by you or your administrators. Emailed reports and attachments can contain monitoring information. Choosing to share a diagnostic plan creates a link accessible to its recipients.

Providers include Clerk (authentication), Stripe (payments), Vercel (hosting and web analytics) and Contabo (hosting), Fly.io (managed collectors), Cloudflare R2 (collector downloads), Resend (email), PostHog (configured analytics), tawk.to (requested chat), and configured AI gateways and model providers. See the current service-provider inventory for data categories and processing purposes. Payment and identity providers may also process some information under their own legal responsibilities.

We may disclose information when legally required, to protect legal rights and security, to advisers under appropriate confidentiality obligations, or in a business transfer subject to applicable protections. We do not sell personal information.

8. Locations and international transfers

Information may be processed where we and our providers operate. An infrastructure location does not determine where every authentication, support, email, analytics, payment or AI operation takes place.

Our providers operate internationally, including in the United Kingdom, the European Economic Area and the United States. Provider processing and onward transfers depend on the service and account configuration. This policy does not promise that every operation or copy remains within the UK or EEA.

Where an international transfer requires safeguards under applicable law, those safeguards may include an applicable adequacy decision or approved contractual transfer provisions, including UK provisions where required. Contact support@mydba.dev for the locations and transfer arrangements applicable to your service and information about relevant safeguards.

9. Retention and deletion

Free and Pro include 30 days of monitoring history. This is not a universal deletion deadline for accounts, saved reports, configuration, billing, support, provider records or backups.

We retain account information while needed to provide and administer the service, and afterwards where necessary for the stated legal, security and record-keeping purposes. Retention considers the purpose, applicable requirements, outstanding disputes and deletion requests. Organization deletion removes associated records through application deletion paths and database cascades; external provider records and backups can have separate lifecycles.

For records outside monitoring history, the following criteria apply:

  • Account and connection configuration is needed while the account or organization remains active, and while closure or deletion requests are being completed.
  • Billing and transaction records are retained for applicable accounting, tax, fraud-prevention and legal-claim requirements, including after account closure.
  • Support and message records are retained to resolve requests, maintain relevant correspondence and address related complaints or disputes.
  • Security and service logs are retained for diagnosing failures, protecting the service and investigating incidents; an active investigation can require longer retention of relevant evidence.
  • Analytics records are retained for the measurement purposes described above, subject to the configured provider lifecycle and applicable deletion requests.
  • Saved reports and notification configuration follow the relevant account or organization lifecycle unless a separate legal or operational need applies.
  • Backup copies remain until overwritten or expired under the backup lifecycle. A live-data deletion is not an immediate erasure of every historical backup.

Contact us for the retention and deletion scope applicable to a particular record or service-provider copy. We will explain any legal requirement that prevents fulfilling a deletion request.

10. Your rights and choices

Depending on the applicable law and circumstances, you may request access, correction, deletion, restriction or portability, or object to processing based on legitimate interests. You may withdraw consent where we rely on it without affecting processing before withdrawal. These rights have exceptions; we will explain any applicable limitation.

Contact support@mydba.dev. We may need to verify identity and identify the relevant account or organization. Where we act for a customer, we will refer the request to that customer and assist as appropriate.

You can complain to the UK Information Commissioner's Office or another relevant supervisory authority. Contacting us first is welcome but is not a condition of making a complaint.

11. Security and policy changes

Hosted endpoints and collector ingest use HTTPS. Stored monitored-database credentials and supported customer AI keys are column-encrypted; authorized services can decrypt them for their purpose. Application access is scoped by organization and role. Database-connection TLS depends on configuration. No system guarantees absolute security. See Data handling.

We will update the effective date when this policy changes and give appropriate notice of material changes through the service or email. Where fresh consent is required, we will request it before the relevant new processing.