Privacy Policy
Preliminary version ยท August 1, 2026
This version governs initial access while controller identity, jurisdictions, contacts, final retention periods, transfers and professional review are completed. Material changes will be published under a new version and require renewed acceptance.
1. Scope and controller
This Policy explains how PloyDB Cloud processes personal information when you visit the public site, create an account, join an organization, contact support or use the control plane.
The final legal identity, registered address and privacy contact of the data controller must be inserted before this Policy is published for acceptance.
2. Information we process
Account data includes display name, email, preferred language, authentication state, legal-document acceptances, organization and project memberships and security settings.
Operational data may include server and database resource identifiers, configuration, health observations, operation history, audit events, support context, IP address, browser user agent and session metadata. PloyDB does not need your application database contents for ordinary control-plane operation, except when you explicitly request a feature that processes selected content.
3. Sources
We receive information directly from you, organization administrators, authenticated browsers, PloyDB agents running on authorized infrastructure and service providers you choose to connect.
GitHub identity data will not be processed until that integration is configured and you explicitly start the connection flow.
4. Purposes and legal bases
We process information to provide and secure the service, authenticate users, maintain organization boundaries, execute authorized operations, deliver transactional email, prevent abuse, investigate incidents, support recovery, comply with law and improve reliability.
Depending on the jurisdiction and context, processing relies on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations or consent where required. The final jurisdiction-specific basis must be reviewed before publication.
5. Cookies and local state
PloyDB uses strictly necessary cookies for sessions, CSRF protection, OAuth state, onboarding and language preferences. Security cookies use appropriate HttpOnly, Secure and SameSite attributes according to their purpose.
This draft does not authorize advertising cookies or cross-site behavioral tracking. Any future non-essential technology requires separate disclosure and consent where applicable.
6. Service providers and disclosure
We disclose only the information necessary to infrastructure, transactional-email, identity, payment, monitoring and support providers used to operate PloyDB. Resend currently processes transactional-email delivery data. GitHub and payment processing remain disabled until separately configured.
We may also disclose information when required by law, to protect rights and security, or as part of a corporate transaction subject to appropriate safeguards. We do not sell personal information.
7. International transfers
Providers and infrastructure may process information outside your country. Before launch, PloyDB must document applicable transfer locations and safeguards, including contractual mechanisms required by relevant privacy law.
8. Retention
We retain account and operational records only as long as needed for the purposes described, including security, audit, recovery, billing and legal obligations. Authentication tokens have bounded expiry; revoked sessions and durable audit evidence may be retained longer to investigate abuse and demonstrate authorized operations.
Final retention periods for account deletion, backups, support records, invoices and security evidence must be approved and published before registration opens.
9. Security
PloyDB uses controls including strong password hashing, multi-factor authentication for privileged roles, HttpOnly sessions, CSRF protection, rate limiting, encrypted sensitive values, parameterized database access, tenant isolation and durable audit records.
No system is completely secure. You are responsible for protecting your credentials, reviewing sessions and organization access, and reporting suspected compromise promptly.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, request portability, withdraw consent and complain to a supervisory authority. Identity verification may be required before a request is completed.
The final request channel, response periods, authorized-agent process and jurisdiction-specific rights must be inserted before this Policy becomes effective.
11. Children
PloyDB is intended for professional database operations and is not directed to children. The minimum account age and any required parental-consent rule must be selected according to launch jurisdictions before public registration is enabled.
12. Changes and contact
We may update this Policy prospectively and will present a new version for acceptance when a material change requires it. The final effective date, privacy email, legal notice address and supervisory-authority details must be completed before publication.