Privacy Policy
Last updated: March 19, 2026
1. Introduction
CheckMyData.ai (“we,” “us,” “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, what we explicitly do not collect, how we use the information we have, and your rights regarding that information.
CheckMyData.ai is an open-source project. Our entire codebase is publicly available for review. This means you can verify every claim in this policy by inspecting the source code yourself — there are no hidden data-collection mechanisms.
2. Information We Collect
We collect only the minimum information necessary to operate the Service:
2.1 Account Information
- Email address — used for authentication and account recovery;
- Display name (optional) — shown in the interface and to project collaborators;
- Password hash — your password is hashed using industry-standard algorithms (bcrypt) before storage. We never store plaintext passwords.
2.2 Connection Metadata
- Database connection details — host, port, database name, database type (PostgreSQL, MySQL, MongoDB, ClickHouse). These are required to establish connections on your behalf.
- Database credentials — usernames and passwords for your databases are encrypted at rest and decrypted only at the moment a connection is established.
2.3 SSH Keys
- If you provide SSH keys for tunneled connections, they are stored encrypted and used exclusively for establishing SSH tunnels to hosts you specify.
2.4 Chat History
- Your natural-language questions and the AI-generated responses (including generated SQL) are stored to provide conversation continuity across sessions.
- Chat history does include the result table an answer was built from, up to 500 rows per message, so a conversation you return to still shows what it was based on. It is stored with the message and deleted with it — see Data Retention and Deletion.
2.5 Repository Metadata
- When you connect a Git repository, the Service indexes structural metadata (file names, entity names, function signatures) and generates enriched documentation for RAG retrieval. This metadata is stored in a local vector database (ChromaDB).
2.6 Saved Queries (Notes)
- Queries you explicitly save as “notes” are stored so you can reference them later. These contain the SQL and your annotation, not the result data.
3. Information We Do NOT Collect
We do not collect, store, copy, or retain access to:
- A copy of your database — we do not replicate, mirror, or bulk-export your data, and we hold no standing copy of it. What we do keep is narrower and worth stating plainly: the result table behind an answer is stored with that chat message, capped at 500 rows, and column indexing stores a small sample of distinct values per column so the agent can write correct queries. Both are deleted when you delete the chat, the connection, or the project they belong to.
- Raw source code — repository indexing extracts structural metadata (names, signatures, relationships) but does not store your full source files.
- Analytics or tracking data — we do not use third-party analytics trackers, advertising pixels, or fingerprinting technologies.
- Behavioral profiling data — we do not build user profiles for advertising, marketing, or sale to third parties.
4. How We Use Your Information
The information we collect is used solely to:
- Provide and operate the Service — authenticate your identity, establish database connections, execute queries, and render results;
- Maintain conversation context — store chat history so you can revisit previous questions and the AI can provide contextually relevant follow-ups;
- Enable collaboration — allow project owners to invite collaborators who share the same project configuration;
- Improve the Service — identify and fix bugs, improve AI agent accuracy, and enhance the user experience. Any improvements are made to the open-source codebase and benefit all users.
We do not sell, rent, or trade your personal information to any third party. Ever.
5. Data Storage and Security
Where your data lives depends on how you run CheckMyData.ai:
- The hosted service stores internal application data in managed PostgreSQL, with vector embeddings in the same database (pgvector);
- Self-hosted and development installs store the same data in SQLite, with embeddings in ChromaDB alongside the application;
- All sensitive credentials (database passwords, SSH private keys) are encrypted at rest using a per-deployment encryption key;
- Your session is carried by an httpOnly cookie over HTTPS, so no script on the page can read it;
- Password hashes use bcrypt with appropriate cost factors.
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We encourage self-hosting for maximum control over your data security.
6. Third-Party Services
CheckMyData.ai shares data with three kinds of external service: the Large Language Model providers that answer your questions, the payment processor that bills the hosted service, and the error monitor that tells us when something breaks. Here is exactly what each one receives:
6.1 LLM Providers (OpenAI, Anthropic, OpenRouter)
| Sent to LLM | NOT sent to LLM |
|---|---|
| Your natural-language question | Database credentials or passwords |
| Up to 20 result rows per query, plus sample values taken from your columns when the schema is indexed | Anything from a connection your question did not touch |
| Database schema metadata (table names, column names, types) | Whole tables or unbounded exports |
| Conversation context (previous Q&A in the session) | SSH keys or private keys |
| Repository structural metadata (for knowledge-based queries) | Your full source code files |
Each LLM provider has its own privacy policy and data handling practices. We recommend reviewing them if you have concerns about how your query text is processed.
6.2 Google OAuth (Optional)
If you choose to sign in with Google, we receive your email address and display name from Google. We do not access your Google Drive, Gmail, Calendar, or any other Google services.
6.3 Stripe (payments, hosted service only)
When you start a subscription we create a customer record with Stripe and send your email address and display name. Card details go to Stripe directly and never reach our servers. Self-hosted installs with billing disabled contact Stripe at no point.
6.4 Sentry (error monitoring)
When something fails, the backend and the browser send the error and its stack trace to Sentry so we can fix it. Two layers of scrubbing run before anything leaves: one removes values that look like secrets, the other removes fields whose names suggest them. We do not send your query results or your database contents to Sentry, and it is off entirely when no Sentry address is configured — which is the default for self-hosted installs.
7. Open Source Transparency
Because CheckMyData.ai is open source, every claim in this Privacy Policy is verifiable. You can audit the codebase to confirm:
- What data is collected and where it is stored;
- What data is sent to LLM providers;
- How credentials are encrypted;
- That no hidden telemetry or tracking exists.
We believe transparency is the strongest form of privacy assurance.
8. Data Retention and Deletion
We retain your data only for as long as your account is active or as needed to provide the Service:
- Account data — retained until you delete your account;
- Chat history — retained until you delete individual sessions or your entire account;
- Connection configurations — retained until you remove them or delete your account;
- SSH keys — retained until you delete them through the interface or delete your account;
- Repository index data — retained until you remove the project or delete your account.
- Query results stored with a chat message (up to 500 rows) — deleted with that chat session, its project, or your account;
- Sampled column values collected while indexing a database — deleted when you remove the connection, its project, or your account.
Upon account deletion, all data associated with your account is permanently removed. For self-hosted deployments, data lifecycle is entirely under your control.
10. Children’s Privacy
The Service is not directed at individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at [email protected] and we will promptly delete the information.
11. International Data Transfers
If you access the hosted version of CheckMyData.ai from outside the country where our servers are located, your information may be transferred across international borders. By using the Service, you consent to such transfers.
For users in the European Economic Area (EEA), we process data based on legitimate interest (providing the Service you requested) and consent (where applicable). You have the right to access, rectify, erase, restrict processing of, and port your personal data. Contact us at [email protected] to exercise these rights.
If you require full data sovereignty, we recommend self-hosting CheckMyData.ai on infrastructure within your jurisdiction.
12. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you;
- Rectification — request correction of inaccurate data;
- Erasure — request deletion of your account and all associated data;
- Restriction — request that we limit how we process your data;
- Portability — request your data in a structured, machine-readable format;
- Objection — object to processing of your data in certain circumstances.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last updated” date at the top of this page;
- Where possible, notify registered users via email;
- Commit the changes to the open-source repository so they are publicly visible and auditable.
We encourage you to review this page periodically. Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
See also our Terms of Service for the full terms governing your use of CheckMyData.ai.