DopeDB · Public policy

Privacy Policy

This policy explains what DopeDB processes across its public website, desktop app, workspace service, and optional managed database connections.

Effective: July 31, 2026

01

Who operates DopeDB

DopeDB is an open-source database client and workspace service operated by Jaesong Choi. Questions or privacy requests can be sent to cjs5241@gmail.com.

02

Information we process

  • Account data: your Google account identifier, verified email address, name, profile image, sign-in session, and the workspaces, memberships, roles, and invitations associated with your account.
  • Workspace data: shared connection templates, environment and safety settings, access grants, redacted provider selectors, revisions, backup metadata, and workspace audit events. Shared templates do not contain database passwords, tokens, certificates, embedded-credential URLs, or local secret references.
  • Google Cloud setup data: the Google account email, selected project and Cloud SQL instance metadata, requested OAuth scopes, and a short-lived access token used to configure the selected resource. DopeDB does not request or retain a Google refresh token or service-account key. The setup token is encrypted and expires within ten minutes.
  • Managed-access data: provider identity and resource metadata, encrypted provider authorization when a provider requires it, and short-lived member-specific database credentials. One-time database credentials are returned to the authenticated desktop app and are not stored in the workspace database.
  • Local desktop data: database credentials, certificates, advanced connection parameters, query history, and full execution audit data remain on the device or in its operating-system credential store unless you deliberately publish supported workspace metadata.
  • Website data: Vercel may process request, device, referral, and aggregate usage information needed to host, secure, and measure dopedb.dev. DopeDB does not use this website data to build advertising profiles.
03

How we use information

  • Authenticate users and devices, maintain sessions, and enforce workspace membership and role boundaries.
  • Create and synchronize shared connection templates, access policy, revisions, backups, invitations, and audit records.
  • Discover a cloud resource selected by an administrator and configure narrowly scoped, keyless managed database access.
  • Protect the service, investigate failures, prevent abuse, and comply with legal obligations.
  • Measure public website reliability and usage so the documentation and download flow can be improved.
04

Google user data

DopeDB requests Google identity scopes for sign-in and, only when a workspace administrator starts Google Cloud SQL setup, the Google Cloud platform scope needed to discover and configure resources that the administrator selects. Authorization is requested at that moment rather than during ordinary sign-in.

Google Cloud access is used only to list accessible projects and Cloud SQL instances, validate the selected instance, and perform the administrator-approved keyless setup. It is not used for advertising, credit decisions, or training general-purpose AI models.

DopeDB's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

05

When information is shared

We disclose information only to operate the service, follow your instructions, or meet legal requirements. Service providers can include Google for identity and Cloud APIs, Vercel for hosting, analytics, and workload identity, Neon for the workspace database, Resend for configured invitation email, and a database provider you deliberately connect. Each provider processes data under its own terms.

Workspace information is visible according to workspace roles and connection grants. We do not sell personal information or share it for cross-context behavioral advertising.

06

Retention and deletion

  • Google Cloud setup sessions and their encrypted access tokens expire within ten minutes. Managed database credentials normally expire within fifteen minutes.
  • Browser and desktop account sessions expire according to the product's session policy; current browser sessions are configured for up to thirty days unless revoked sooner.
  • Workspace records, connection metadata, revisions, backups, and audit events are retained while needed to provide and secure the workspace or until an authorized user deletes them, subject to legal and security retention requirements.
  • Local desktop data remains until you remove the connection, clear the related history, uninstall the app, or delete the operating-system credential item.
07

Security

DopeDB uses encrypted transport, server-side authorization checks, short-lived credentials, encrypted provider authorization, keyless Google Cloud federation, redacted logs and backups, and operating-system credential storage. No system is perfectly secure, so users should still grant the minimum cloud and database privileges required.

08

Your choices and rights

  • You can disconnect a provider integration, revoke DopeDB in your Google Account permissions, sign out devices, leave a workspace, or ask a workspace administrator to change or remove your membership.
  • You may request access, correction, deletion, restriction, or a copy of personal information where applicable by emailing cjs5241@gmail.com. We may verify your identity and authority before acting.
  • You can use the local desktop features without enabling an optional managed provider integration.
09

International processing, children, and changes

DopeDB and its service providers may process information in countries other than your own. We use the safeguards offered by the relevant provider and applicable law. DopeDB is a developer tool and is not directed to children under 16.

We may update this policy as the product or law changes. Material updates will be posted here with a revised effective date.