Last updated June 12, 2026
Privacy Policy
Your databases are yours. This policy explains exactly what Datagent AI stores, what it never stores, and how your data is used and protected.
1. What we collect
- Account data: name, email, password hash, and optional two-factor secrets.
- Workspace data: workspace names, member roles, and invitations.
- Connection metadata: connection names, engines, hosts, and ports. Credentials are stored encrypted with AES-256-GCM and are never readable by our staff, returned to the browser, or written to logs.
- Usage data: queries you run through the Service (statement text, status, and timing) for the audit log, and AI token usage for credit accounting.
- Billing data: plan, subscription status, and payment references. Card details are handled entirely by Razorpay and never touch our servers.
2. What we do not collect
We do not copy or warehouse the contents of your connected databases. Query results are streamed to your browser and are not retained server-side beyond transient processing.
3. How we use your data
- To operate the Service: authentication, workspaces, connections, and query execution.
- To provide AI features: relevant schema metadata and your prompt are sent to the AI provider configured for the platform (Anthropic, OpenAI, or Google) solely to generate the response. We do not use your data to train models.
- To bill you and account for AI credit usage.
- To send transactional email (verification, password reset, invitations).
4. AI processing
When you use Copilot, docs, health advice, or agents, we transmit the minimum context needed — schema structure, aggregate statistics, and your question — to the active AI provider. Connection credentials are never included. Providers process this data under their API terms, which exclude training on API inputs.
5. Cookies
We use strictly necessary cookies for authentication sessions and a small set of functional preferences (theme, cookie-consent choice). We do not use advertising or cross-site tracking cookies. See the Cookie Policy for the full list.
6. Data retention
- Account and workspace data: kept while your account is active; deleted within 30 days of account deletion.
- Audit log entries: kept for 12 months, or per your Enterprise agreement.
- AI usage and credit ledger: kept for accounting purposes for up to 7 years where required.
7. Sharing
We share data only with the processors needed to run the Service — database hosting (Neon), email delivery, payment processing (Razorpay), and the configured AI provider — each bound by data-processing terms. We never sell personal data.
8. Security
Credentials are encrypted at rest with AES-256-GCM; transport is TLS everywhere; connections default to read-only with statement timeouts and row caps; access is role-scoped per workspace; and every query is audited.
9. Your rights
Depending on your jurisdiction (including GDPR and similar laws), you may request access, correction, export, or deletion of your personal data, and object to or restrict certain processing. Email privacy@datagent.ai and we will respond within 30 days.
10. Changes
We will notify you of material changes to this policy by email or in-app before they take effect.
Questions about this policy? Contact us at legal@datagent.ai.