DopeDB · Public policy

Privacy Policy

This policy explains how DopeDB processes information across its public website, local desktop app, hosted workspace, and optional provider integrations.

Effective: September 11, 2026

01

Controller and privacy contact

The data controller and privacy officer for DopeDB's hosted service is Jaesong Choi, an individual operator in the Republic of Korea. Privacy questions, rights requests, and complaints can be sent to cjs5241@gmail.com.

02

Scope and responsibility

This policy covers dopedb.dev, the hosted service at app.dopedb.dev, the DopeDB desktop app, and optional managed provider integrations. Information that remains only on your device is controlled by you and is not received by the hosted service, except for the separately described sanitized Sentry diagnostics and Desktop product analytics you explicitly opt into.

A workspace organization may separately determine why and how it uses member or database-related information. In that case, the organization is responsible for its own notices, authority, and instructions, while DopeDB processes hosted workspace data to provide and secure the service.

03

Information we process

  • Account and invitation data: Google account identifier, verified email address, name, profile image, account timestamps, workspace memberships and roles, invitation address and status, inviter identity, and workspace name.
  • Session and security data: session and device-authorization identifiers, expiration and activity timestamps, IP address, user agent, rate-limit key and count, request identifier, authentication status, and redacted audit events.
  • Workspace data: workspace profile, members and roles, secretless connection templates, environment and safety settings, access grants, revisions and conflicts, provider/resource selectors, encrypted metadata backups and deletion markers, and audit records. Shared templates reject database passwords, tokens, certificates, embedded-credential URLs, local paths, and local secret references.
  • Provider setup and managed-access data: provider identity and resource metadata, selected Google Cloud project and Cloud SQL instance, requested OAuth scopes, short-lived setup authorization, encrypted reusable provider authorization when required, setup receipts, and credential-lease metadata. One-time database credentials are returned only to the authenticated desktop app and are not stored in the workspace database.
  • Local desktop and Agent data: other than the separately described diagnostics and optional product analytics, database credentials, certificates, advanced connection parameters, query history, full execution records, and provider CLI authentication remain on the device or in its operating-system credential store unless you deliberately publish supported metadata or send selected context to an Agent provider.
  • Desktop error diagnostics: production builds send Sentry a sanitized exception type and stack structure or code location, app release and runtime, a bounded React component-name chain, and closed Agent-plugin provider, operation, and failure outcome tags. User, request, breadcrumb, free-form message, extra context, logs, replay, tracing, and default PII are disabled or removed before sending.
  • Optional Desktop product analytics: only after explicit opt-in, the app sends random installation and session identifiers, a one-way event identifier, app version, operating-system family, language, an installation-scoped sign-in key, workspace-scoped team member and workspace keys when applicable, workspace kind, and closed event outcomes such as database engine, local or managed access, statement class, provider, approval flag, role, and bucketed duration or row count.
  • Website data: hosting and security requests, plus closed page/language and download or workspace-button event categories stored in Cloudflare Analytics Engine for three months. Website metrics contain no visitor identifier, full URL, query string, referrer, device, or location field and are not used for advertising profiles.
04

Desktop diagnostics and analytics choices

Sentry error diagnostics and optional product analytics are separate. Sentry receives only the sanitized production error projection described above and is not used to build product funnels. Optional product analytics remains off while your choice is pending or denied and is sent through app.dopedb.dev to DopeDB's dedicated Cloudflare analytics service only after you choose to allow it.

The first-party relay validates a closed event schema and does not store raw analytics in the workspace database. The dedicated Cloudflare Worker sends the normalized event to Google BigQuery in the EU without the original client IP, person profiles, autocapture, cookies, replay, heatmaps, surveys, or free-form properties. Cloudflare may separately process request metadata and IP addresses as hosting and security data.

Neither diagnostics nor product analytics is allowed to contain SQL or query text, parameters, database results, database, host, connection, schema, table, column or project names, credentials, tokens, certificates, Agent prompts or transcripts, repository names or source, local paths, email, display name, raw account or workspace identifiers, request or response bodies, or raw product errors. DopeDB does not use these systems for advertising or general-purpose AI training.

Withdrawing Desktop product-analytics consent stops future collection and deletes the pending local queue and random installation identifier immediately. If you opt in again, the app creates new installation, session, and sign-in keys. Workspace-scoped team member and workspace keys may still group separately consented events inside that team. Installation-only, Personal Workspace, and sign-in events already accepted by the relay cannot be individually located because DopeDB keeps no account-to-installation map; they expire under the raw-event retention limit. This choice does not change Sentry diagnostics or the public website's separate website metrics.

05

Purposes and legal grounds

  • Provide the service and follow your request: authenticate accounts and devices, maintain sessions, create workspaces, synchronize supported metadata, send invitations, and issue managed credentials.
  • Apply workspace access rules, preserve revision and audit history, prevent abuse, investigate failures, protect users and the service, and maintain reliability.
  • Complete an optional Google Cloud or other provider setup that an authorized administrator starts and approves.
  • Measure public website reliability and navigation so documentation and download flows can be improved; diagnose sanitized Desktop failures; and, with explicit consent, measure closed Desktop activation, reliability, and shared-access outcomes.
  • Depending on the processing, we rely on performance of the service you request, explicit consent for optional Desktop product analytics and optional provider access, legitimate security and operational interests balanced against your rights for strictly bounded diagnostics, or another basis permitted or required by applicable law.
06

Google user data

Ordinary sign-in requests Google identity scopes for your account identifier, verified email, name, and profile image. DopeDB clears Google access, refresh, and ID token values before account data is stored.

Only when an authorized workspace administrator starts Google Cloud SQL setup does DopeDB request the Google Cloud platform scope. The resulting access token is encrypted, used to list accessible projects and instances, validate the selected resource, and perform the explicitly approved keyless setup, and expires within ten minutes. DopeDB does not request or retain a Google refresh token or service-account key.

Google data is not used for advertising, credit decisions, or training general-purpose AI models. DopeDB's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access from your Google Account permissions.

07

Agents and user-directed services

DopeDB launches official Agent adapters and relies on the user's local Codex or Claude CLI login. DopeDB does not read, refresh, or persist that provider login token. Prompts and any schema, query, result, file, or error context you include may be transmitted by the official CLI to the selected provider and processed under that provider's account settings, terms, and privacy policy.

A cloud project, database, GitHub repository, or other service that you deliberately connect likewise receives the requests and data needed to perform your instruction. Those providers are independent recipients, and their processing locations and retention depend on the provider, account, and resource you select. DopeDB does not independently use Agent conversations or database contents to train a general-purpose AI model.

08

Service providers and sharing

  • Cloudflare hosts and secures the public website, Workspace application, background coordinator, and workload identity service. Its D1 database stores account and workspace records, including encrypted integration and backup records. It stores closed public website events in Analytics Engine and may process request and security metadata. Policy: https://www.cloudflare.com/privacypolicy/.
  • Sentry provides production Desktop error diagnostics through its United States ingest service. It receives only the sanitized error projection described above. Policy: https://sentry.io/privacy/.
  • Cloudflare hosts the dedicated product-analytics Worker; Google Cloud stores the resulting opt-in events in BigQuery (EU). Google policy: https://cloud.google.com/terms/cloud-privacy-notice. DopeDB's first-party relay sends the closed event projection without the original client IP. Policy: https://www.cloudflare.com/privacypolicy/.
  • Neon, LLC (Neon) previously stored account and workspace records in PostgreSQL. Restricted recovery copies remain during migration cleanup; the active Workspace database is Cloudflare D1. Contact: privacy@neon.tech; policy: https://neon.com/privacy-policy.
  • Plus Five Five, Inc. (Resend) sends workspace invitations only when email delivery is configured. It receives recipient and inviter name/email, workspace name, and the invitation link. Contact: privacy@resend.com; policy: https://resend.com/legal/privacy-policy.
  • Google receives sign-in and optional Cloud API requests; a user-selected Agent, cloud, or database provider receives only the requests the user initiates. Each independent provider applies its own terms and privacy policy.
  • Workspace data is visible to members according to their current roles and connection grants. Information may also be disclosed when required by applicable law, a valid legal order, or an urgent need to protect rights and safety. DopeDB does not sell personal information or share it for cross-context behavioral advertising.
09

International processing and transfer

DopeDB is operated in the Republic of Korea. Public website and Workspace requests run on Cloudflare’s distributed network, which is not restricted to one country. The Workspace D1 database requests placement in Eastern North America; this placement preference does not guarantee a country or legal jurisdiction. Restricted legacy recovery copies remain in the United States during migration cleanup. Authenticated requests and records are transferred over encrypted connections. These providers may use subprocessors in the locations identified in their legal notices.

Sanitized production Desktop errors are sent directly to Sentry’s United States ingest service. Optional Desktop product analytics reaches the Cloudflare-hosted Workspace relay and then the dedicated Cloudflare analytics Worker. Google BigQuery stores normalized Desktop events in its EU multi-region. Worker processing and hosting-security metadata may occur outside that storage jurisdiction.

If invitation email is enabled, the invitation data listed above is sent by encrypted API request to Resend in the United States when an administrator sends or resends an invitation. Google and user-selected Agent, cloud, and database providers may process data in the countries shown in their own policies or the region selected for the connected resource.

Recipients process information for the purposes described above for the service relationship, account or workspace lifecycle, provider backup cycle, and any period required by law. You can refuse core overseas processing by not signing in to or creating a hosted workspace; this prevents hosted sharing and managed access but does not prevent local-only desktop use. You can separately refuse an optional integration by not connecting it or by disconnecting and revoking it with the provider.

10

Retention, deletion, and destruction

  • Device authorization and Google Cloud setup sessions are valid for no more than ten minutes, managed database credentials normally for no more than fifteen minutes, invitation links for 48 hours, and current account sessions for up to 30 days unless revoked sooner. Related security and audit records can be retained for the longer periods described below.
  • Account, membership, workspace, connection, revision, integration, and audit records are retained while needed to provide and secure an active workspace and to meet legal obligations. Self-service workspace deletion is currently disabled; an owner or other authorized person can email a verified deletion request, and we will explain any record that must be retained.
  • Deleting a metadata backup makes it unavailable through the product and records a deletion marker. Its encrypted ciphertext may remain until a verified workspace deletion or an operational purge is completed. Disconnecting an integration removes or invalidates DopeDB's stored authorization where supported, but you should also revoke provider-side access.
  • The optional Desktop analytics retry queue contains at most 100 closed events, discards events older than seven days, and is deleted with its random installation identifier when consent is withdrawn. Raw product events in Google BigQuery (EU) expire from active storage within 30 days. Restricted recovery storage can remain for two days of time travel followed by seven days of fail-safe retention. Sanitized Sentry events are retained only for the configured incident-investigation period and are deleted or anonymized when no longer needed.
  • When destruction is due, electronic records are deleted or irreversibly anonymized through the applicable database, storage, and provider lifecycle. Isolated provider backups may remain until their protected backup cycle expires and are not used for ordinary service operations.
  • Local desktop data remains until you remove the connection or history, delete the operating-system credential item, or uninstall the app. Agent or connected-provider copies must be deleted through that provider's controls.
11

Cookies and automatic collection

The hosted workspace uses secure, essential authentication cookies to maintain the selected session, including a short cookie cache. Current sessions can last up to 30 days. Blocking or deleting these cookies prevents or ends hosted sign-in but does not prevent local-only desktop use.

The public website uses same-origin Cloudflare Analytics Engine collection for bounded page and click counts. It creates no website visitor identifier and uses no advertising cookies or cross-site behavioral tracking. Do Not Track and Global Privacy Control disable collection. Hosting security metadata may still be processed when a request reaches the service.

Optional Desktop product analytics does not use a website cookie and is not linked to website event counts. It starts only after the in-app consent action. Sentry diagnostics is a separate error-monitoring path and is not used for funnel measurement.

12

Security

DopeDB uses encrypted transport, server-side authorization checks, short-lived credentials, encrypted provider authorization and metadata backups, keyless Google Cloud federation, redacted logs, secretless shared templates, and operating-system credential storage. Access is restricted by workspace role and connection grant. No system is perfectly secure, so users should grant the minimum cloud and database privileges required and report suspected compromise promptly.

13

Your rights and complaints

  • You or an authorized representative may request access, correction, deletion, suspension or restriction of processing, withdrawal of consent, or a copy of applicable personal information by emailing cjs5241@gmail.com. You may also object or appeal when a request is denied. We may verify identity and authority and will explain a refusal required or permitted by law.
  • You can withdraw optional Desktop product-analytics consent in the app. This immediately clears its local queue and installation identifier. DopeDB keeps no account mapping for that random identifier, so already relayed installation-only, Personal Workspace, and sign-in events cannot be individually located and expire within the stated 30-day raw-event limit. For applicable team events, an authorized request may let us recompute that team's scoped member and workspace pseudonyms and delete matching rows from the dedicated BigQuery dataset. Sentry and Cloudflare requests are handled separately because their identifiers are not joined to the Desktop analytics identifier.
  • You can disconnect an integration, revoke DopeDB in Google Account permissions, sign out a session, or ask a workspace administrator to change or remove membership. Optional provider integration is not required for local-only desktop use.
  • You may seek additional help from Korea's Personal Information Infringement Report Center at https://privacy.kisa.or.kr or the Personal Information Dispute Mediation Committee at https://www.kopico.go.kr.
14

Children, changes, and language

DopeDB is a developer tool and is not directed to children under 16. We do not knowingly collect their personal information through the hosted service; if we learn that we have done so, we will take appropriate deletion steps.

We may update this policy as the product or law changes. Material updates will be posted here with a revised effective date, and additional notice will be provided when required by law. A prior version can be requested at the privacy contact.

The Korean and English versions are intended to have the same meaning. If they conflict, the Korean version controls to the extent permitted by applicable law.