Privacy Policy
Last updated: 18 July 2026
1. Introduction
DataBook Studio ("we", "our", or "us", operated by Subodh Sharma) respects your privacy. We are committed to protecting your personal data and ensuring transparency about how our desktop application and website operate. Because DataBook Studio is a local-first desktop application, your data stays on your machine by design.
This Privacy Policy explains what information we do and do not collect, how it is used, and the choices available to you. It applies to the DataBook Studio desktop application (the "App") and our website at databook-studio.github.io (the "Website").
2. Data Collection in the Desktop Application
No Telemetry or Analytics: The DataBook Studio application does not include any telemetry, usage analytics, or crash reporting software. We do not track how you use the app, which features you click, or how often you open it.
Network Calls the App Does Make: The App is not entirely silent on the network. It makes exactly three categories of outbound calls, each covered in more detail elsewhere in this policy:
- AI providers — optional and only when you actively chat with SAYA AI using a cloud provider (see Section 3);
- License server — when you start a trial or activate/deactivate a license (see Section 4);
- Update check — a periodic HTTPS fetch of a static update manifest hosted on GitHub Releases, used only to discover new versions. No account or usage data is sent; as with any web request, standard request metadata (such as your IP address) is visible to the host.
Outside of these three cases, the App does not communicate with our servers or any third party.
Your Database Data: Your database credentials, queries, and query results never touch our servers. The application connects directly from your local machine to your databases (PostgreSQL, MySQL, Snowflake, DuckDB, etc.).
Local Storage: The App stores the following locally on your device — in a local SQLite database and/or your operating system's keychain — and never on our servers:
- Database connections, queries, results, and notebooks;
- SAYA AI chat sessions, including full transcripts, generated SQL, and token-usage counts;
- A local query-insight cache used to speed up repeated analysis;
- A local AI governance and audit log (see our Security page for details);
- Database credentials and AI provider API keys, stored in your operating system's keychain or credential manager (e.g., macOS Keychain, Windows Credential Manager) rather than in plaintext configuration files. If the keychain is locked or unavailable, the App degrades gracefully and does not fall back to writing keys to disk.
Any data you choose to export is also written to your local filesystem. Managing, backing up, or deleting this local data is your responsibility; see Section 6 for the in-app tools available to clear it.
3. Third-Party AI Providers (SAYA AI)
SAYA AI, our built-in AI copilot, is optional and user-initiated. To use a cloud provider, you supply your own API key for that provider — a "bring your own key" model. The supported cloud providers are:
When you chat with SAYA using a cloud provider, the request goes directly from your device to that provider under your own API account — we do not intercept, log, or store these requests or their responses. What is sent depends on your settings:
- Always sent: your prompt, the conversation history, and relevant database schema metadata (table and column names, DDL) needed to generate accurate SQL.
- Sent only if you enable "cloud data sharing": sampled row data or query results. When this setting is disabled, row and sample data are withheld from cloud providers — only schema metadata and prompts are sent.
To reduce your token costs, the App makes use of provider-side prompt caching where available (for example, Anthropic's short-lived ephemeral prompt cache). This means a provider may briefly cache prompt content on its own infrastructure under its own retention policy. Your use of these AI models is governed by the respective terms and privacy policies of those providers, linked above — we encourage you to review them. You are responsible for deciding what data is appropriate to send to a third-party model.
Fully local option: If you use a local model via Ollama or a local OpenAI-compatible endpoint, no data leaves your machine or network — SAYA AI runs entirely on-device.
4. Website and Licensing Data
When you visit our Website or purchase a license, the following applies:
- Website Analytics: We use privacy-respecting analytics (Google Analytics) to understand aggregated website traffic. This may collect limited information such as approximate region, browser type, and referring pages. You can opt out via your browser settings, a Do Not Track signal, or the cookie-consent banner described in Section 5.
- Payments: All payments and license key generation are handled securely by our Merchant of Record (Creem). We do not collect or store your credit card or payment card information. Creem processes payment data according to its own privacy policy and PCI-DSS requirements.
- Trial Records: When you start a free trial, the App sends a device identifier to our license server. Trials are 7-day and single-use per device, so we keep a durable server-side trial record to enforce single use; this record is retained for as long as needed to enforce trial eligibility.
- Licensing Data: When you activate or deactivate a licensed seat, we store the email address associated with your purchase, your license key, and a device identifier in order to issue, validate, and manage per-seat licenses. Deactivating a seat frees it for use on another device. We keep activation and deactivation records for as long as needed for license management, and may also keep transaction records as required for accounting and tax purposes.
- Support Communications: If you contact us for support, we retain the information you share (such as emails and any files you send) for as long as needed to resolve your request and for a reasonable period thereafter.
5. Cookies and Similar Technologies
The Website uses cookies and similar technologies for limited purposes, including enabling Google Analytics and remembering basic preferences. The App itself does not use cookies or web trackers.
- Analytics cookies: used to measure aggregated traffic.
- Essential functionality: required for the Website to operate correctly.
You can control or delete cookies through your browser settings, and you can decline analytics cookies via the cookie-consent banner on the Website. Disabling analytics cookies will not prevent you from using the Website. We do not use cookies to sell or share your personal information for cross-context behavioral advertising.
6. Data Retention
Because the App is local-first, the data you create in it — including your database connections, queries, notebooks, SAYA AI chat history, and audit log — is retained on your device until you delete it or uninstall the App. The App includes in-app tools for clearing this local data. We do not retain your database data or AI prompts on our servers.
Trial records and licensing/seat activation data are retained for as long as needed to enforce trial single-use and manage your license, and thereafter as needed for legal, accounting, and tax obligations. Support communications are kept for as long as reasonably necessary to provide support and improve our service.
7. Security
The local-first design of DataBook Studio means the primary security boundary for your data is your own device. We encourage you to use full-disk encryption, strong device passwords, and secure backups.
For the limited data we do hold (such as licensing and support records), we employ reasonable technical and organizational measures to protect it. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights
Depending on where you live, you may have rights regarding your personal data, including the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request deletion of your personal data (subject to legal retention obligations);
- Receive a copy of your data in a portable format;
- Object to or restrict certain processing;
- Withdraw consent where processing relies on it.
To exercise any of these rights, contact us at databook.studio@gmail.com. We will respond in accordance with applicable law. If you believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
9. International Data Transfers
Your data may be processed by third parties (such as Creem, Google, OpenAI, and Anthropic) that operate in countries other than your own. By using the Website and these integrations, you acknowledge that your information may be transferred to and processed in such countries, which may have different data protection laws. We rely on providers' standard contractual clauses and similar safeguards where required.
10. Children's Privacy
DataBook Studio is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Do Not Sell or Share
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We only share data with service providers (such as Creem and Google) as needed to operate our business, under appropriate confidentiality and data-protection terms.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide a more prominent notice. We encourage you to review this page periodically. Continued use of the App or Website after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have any questions about this Privacy Policy or your personal data, please contact us at: databook.studio@gmail.com.
