Privacy Policy
Last updated: March 7, 2026
1. Introduction
SchemaStack ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
2. Data We Collect
Account Information
When you create an account, we collect:
- Name and email address
- Password (stored hashed, never in plain text)
- Organization name and settings
Metadata
To provide the Service, we store metadata about your workspaces:
- Schema definitions (entity names, column types, relationships, constraints)
- View configurations (column order, filters, presets)
- Permissions and role assignments
- Workspace and database connection settings
Your Business Data
We do not store your business data. When you connect your own database, your data remains entirely in your infrastructure. SchemaStack reads and writes to your database on your behalf but does not copy, cache, or retain your business data.
When using our Managed Hosting services, your data is stored in a database dedicated to your organization. This data is not shared with other customers, is not used by SchemaStack for any purpose other than providing the Service, and can be migrated out at any time.
Usage Data
We automatically collect limited technical data:
- IP address and approximate location (country level)
- Browser type and operating system
- Pages visited and features used within the Service
- API request counts and error rates (aggregate, not request content)
3. How We Use Your Data
We use collected information to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Enforce usage limits and prevent abuse
- Send service-related communications (account verification, security alerts, billing)
- Respond to support requests
- Comply with legal obligations
We do not sell your personal data. We do not use your data for advertising. We do not use your business data to train AI models or for any purpose other than providing the Service to you.
4. Data Sharing
We may share information only in these limited circumstances:
- Service providers: Trusted third parties that help us operate the Service (hosting, payment processing, email delivery). These providers are contractually bound to use your data only for providing their services to us.
- Legal requirements: When required by law, regulation, legal process, or governmental request.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.
- With your consent: When you explicitly authorize us to share information.
5. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data Retention
We retain your account information and metadata for as long as your account is active. When you delete your account, we will delete your personal data and metadata within 30 days, except where retention is required by law or for legitimate business purposes (such as resolving disputes or enforcing agreements).
Your business data in your own databases is not affected by account deletion — it remains in your infrastructure.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your personal data
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
8. Cookies
We use essential cookies required for the Service to function (authentication, session management). We do not use third-party advertising or tracking cookies. You can configure your browser to block cookies, but some features of the Service may not work properly.
9. International Transfers
Our infrastructure is hosted in the European Union. If you access the Service from outside the EU, your account information may be transferred to and processed in the EU. We ensure appropriate safeguards are in place for any international data transfers.
Your business data stays wherever your database is hosted — SchemaStack does not transfer your business data across borders.
10. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and updating the "Last updated" date. We encourage you to review this policy periodically.
12. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at [email protected].