Encryption in transit
The hosted website, public API and collector ingest use HTTPS. Collector-to-database TLS is controlled by your connection’s SSL settings and database configuration; not every possible database connection is encrypted automatically. Use a mode that validates the server certificate where your environment supports it.
Stored credentials
Monitored-database credentials and supported customer AI keys are encrypted at the column level with pgcrypto. Authorized services can decrypt them for their configured purpose. Contact us for deployment-specific key-management, disk and backup requirements.
What we store
- Query statistics, normalized query text and activity samples.
- Schema metadata, collected EXPLAIN plans and performance time series.
- PostgreSQL logs when you enable log collection.
- Account, organization, connection and notification configuration needed to provide the service.
Query samples, logs, plans and definitions can contain sensitive literals or identifiers. Review the collection options and database permissions for your requirements.
Retention and sampling
Free uses full collection for the first seven days, then reduced sampling. Both plans keep 30 days of history; short-lived events can fall between samples. This 30-day window describes monitoring history; it is not a blanket retention period for account, billing, support or backup records.
Deletion and privacy enquiries
Organization deletion removes associated records through the application’s deletion paths and database cascades. External provider records, legally required billing records and backup copies can have separate lifecycles. For an account-data request or a written explanation of the applicable deletion scope, contact security@mydba.dev.
See AI data handling and service providers for onward processing.