What data leaves my database?
MyDBA collects PostgreSQL query statistics, query text, schema metadata, performance metrics and EXPLAIN plans. Optional log collection also sends PostgreSQL logs. These can contain sensitive identifiers or literals even though the collector does not export application tables. A self-hosted collector still sends telemetry to the hosted service. Collector placement and permissions →
Who can see it?
Ordinary application access is scoped to your organization through validated authentication, database grants, row-level security and guarded RPC functions. Privileged operational roles are a separate trust boundary: PostgreSQL superusers and BYPASSRLS roles can bypass row-level security. How tenant isolation works →
How is it protected?
The hosted website, API and collector ingest use HTTPS. TLS for the collector-to-database connection depends on the connection settings you configure. Stored monitored-database credentials are column-encrypted with pgcrypto. Contact us for deployment-specific disk and backup requirements. Data handling details →
What about AI?
Core monitoring, health checks and insights use telemetry, rules and heuristics. AI analysis is optional and can be disabled by an organization admin. OpenRouter, OpenAI and Anthropic customer keys are supported on Free and Pro; requests pass through the MyDBA AI server to the configured provider. AI data handling and allowances →
Questions and reports
See the service-provider list or vulnerability disclosure policy. For security questionnaires, contractual data-processing requirements or account-data requests, contact security@mydba.dev.