Privacy Policy
This Privacy Policy explains how DBCanvas ("DBCanvas", "we", "us") collects, uses, and protects personal data when you use our browser-based database modeling service at https://dbcanvas.io and https://platform.dbcanvas.io (the "Service").
We designed the Service with the GDPR in mind: our application data is hosted in Frankfurt, Germany, and we collect only what we need to run the Service. Each section below starts with a short plain-English summary; the full text is what governs.
1. Who we are
DBCanvas operates the Service and acts as the data controller for the personal data described in this policy, except where stated otherwise (see the section on your project content). For any privacy question or request, contact us at support@dbcanvas.io.
2. Data we collect
We collect the following categories of data when you use the Service:
- Account data: your email address and name, used to create and manage your account.
- Authentication data: your password (stored as a secure hash) and, if you enable two-factor authentication, the data needed to operate your TOTP factor.
- Project content: the database models, diagrams, schemas, and files you create or upload, including the schema and sample rows imported from a database you connect, which become part of your project content. If your schemas or imported data themselves contain personal data, you are the controller of that data and DBCanvas acts as your processor, handling it only to provide the Service.
- Database connection credentials: if you import a schema from a live database, the credentials you provide are processed transiently server-side solely to run the import and are never stored.
- Billing data: subscription and payment records processed by Stripe. Card data never touches DBCanvas servers — we never see or store your full card number.
- Usage data: minimal telemetry about how the Service is used, to keep it reliable and secure.
- Support correspondence: messages you send to support@dbcanvas.io and our replies.
3. Purposes and lawful bases
We process personal data on the following legal bases under the GDPR:
- Performance of a contract: creating your account, hosting your projects, processing subscriptions and credit purchases, and providing support.
- Legitimate interests: securing the Service, preventing abuse and fraud, and understanding aggregate usage to improve the product — always balanced against your rights.
- Legal obligations: keeping billing and tax records where the law requires it.
- Consent: where we ask for it for optional processing; you can withdraw consent at any time without affecting prior processing.
4. AI processing (Copilot)
When you use the AI Copilot, your prompts, attached files, and relevant project schema are sent to third-party AI model providers, routed via OpenRouter, in order to produce responses. This transfer happens only when you actively use Copilot features, and the providers process each request transiently, solely to produce the response.
DBCanvas never uses your prompts, content, or schemas to train AI models. The AI providers' handling of the data they receive is governed by their own terms and privacy policies. AI output can be wrong; please review it before relying on it, as described in our Terms of Service.
5. Processors and service providers
We use the following processors and service providers to run the Service:
- Supabase (on AWS, eu-central-1, Frankfurt) — application database, file storage, and authentication.
- Vercel — web hosting and content delivery.
- Stripe — payment processing; Stripe handles card data directly under its own certifications.
- Resend — authentication, security and product notification emails.
- OpenRouter and the underlying AI model providers — processing Copilot prompts, attached files, and schema to generate responses.
6. International transfers
Primary storage of application data is in the European Union, in the AWS eu-central-1 region (Frankfurt). Some of our processors — in particular AI model providers, our email provider, and our payment provider — may process certain data outside the EU.
Where personal data is transferred outside the EU, those transfers rely on the European Commission's Standard Contractual Clauses or equivalent safeguards recognized under the GDPR.
7. Retention
We retain personal data only for as long as it is needed for the purposes described in this policy:
- Account and authentication data: kept while your account is active and deleted with your account.
- Project content: after an account or workspace is terminated, associated content is deleted on a commercially reasonable schedule, typically within 30 days; copies in backups age out through our normal backup rotation.
- Usage and telemetry data: retained in aggregate form for up to 24 months.
- Billing and tax records: retained for the periods required by applicable legal obligations, even after account closure.
- Support correspondence: kept as long as needed to resolve your request and for a reasonable period afterwards.
8. Your rights
Under the GDPR and similar laws, you have the right to:
To exercise any of these rights, email support@dbcanvas.io. We will respond within the timeframes required by law and may need to verify your identity first.
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to legal retention obligations.
- Receive your data in a portable, machine-readable format.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests.
- Lodge a complaint with your local data protection supervisory authority.
10. Children
The Service is not directed at children and is only available to people aged 16 or over. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us at support@dbcanvas.io and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time, for example when we change providers or add features. If we make material changes, we will notify you before they take effect, for example by email or by a notice within the Service. The date at the top of this policy shows when it was last revised.
12. Contact
For any question, concern, or request relating to this Privacy Policy or your personal data, contact us at support@dbcanvas.io.