PolyDB / Privacy Policy

Privacy Policy

Effective Date: 2026-03-24

We wrote this for developers. No dark patterns, no "by using this service you waive all rights" language. Just what we collect, why, and what you can do about it.


1. What We Collect

Account Data

Billing Data

Usage Data

Infrastructure Data

Cookies


2. What We Do Not Collect


3. How We Use Your Data

DataPurpose
EmailAccount access, billing receipts, service announcements, support
Password hashAuthentication
Usage metricsBilling calculation, quota enforcement, capacity planning
IP addressesSecurity, rate limiting, abuse detection
LogsDebugging, incident response, performance monitoring

We do not sell your data. We do not share your data with advertisers. We do not train AI models on your data.


4. Subprocessors

We use the following third-party services to operate PolyDB Cloud. Each subprocessor has agreed to handle data in compliance with applicable privacy laws.

SubprocessorPurposeData SharedLocation
AWSInfrastructure (Fargate, ALB, SES, Secrets Manager)All service traffic, email deliveryus-east-1
NeonPostgreSQL hosting (tenant databases)Your database contentus-east-1
StripePayment processing, subscription managementEmail, billing detailsUnited States

If we add new subprocessors, we'll update this list and notify you by email before the subprocessor begins processing your data.


5. Data Location

All data is stored and processed in AWS us-east-1 (Northern Virginia). We do not currently offer data residency in other regions. If this matters to you for compliance reasons, contact us.


6. Data Retention

Data TypeRetention
Account dataUntil account deletion + 30 days
Database contentUntil account deletion + 30 days
Access logs30 days
Billing records7 years (legal requirement)
Support emails2 years

When you delete your account, we initiate deletion within 7 days and complete it within 30 days. Billing records are retained for legal compliance.


7. Your Rights (GDPR and Beyond)

If you're in the EU/EEA, UK, or California, you have specific rights over your data. We honor these for everyone, not just residents of regulated jurisdictions.

RightWhat it meansEndpoint
AccessGet a copy of all data we hold about youGET /api/gdpr/export
RectificationCorrect inaccurate account dataPATCH /api/auth/profile
ErasureDelete your account and all associated dataDELETE /api/gdpr/account
PortabilityExport your database content in a portable formatGET /api/gdpr/export
RestrictionPause processing while a dispute is resolvedEmail support@polydb.dev
ObjectOpt out of non-essential processingEmail support@polydb.dev

To exercise any right, you can use the API endpoints above (authenticated) or email support@polydb.dev. We'll respond within 30 days. For GDPR requests, we'll respond within 72 hours for urgent erasure requests.


8. Security


9. Children's Privacy

PolyDB Cloud is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has created an account, email support@polydb.dev and we'll delete it.


10. Changes to This Policy

When we make material changes to this policy:


11. Contact

Privacy questions: support@polydb.dev Security disclosures: security@polydb.dev GDPR requests: support@polydb.dev (subject: "GDPR Request")

We're a small team. We read everything and respond within 2 business days.