Privacy Policy
Last updated 26 August 2026
This policy explains what hellodb collects when you use hellodb.io, why it is collected, and what you can do about it.
hellodb is a visual canvas for database schemas. Most of what it holds is work you made: models, fields, relations and the arrangement you put them in. That content is yours, and this policy is mostly about how it is handled.
1.What we collect
Account details, when you sign in with Google:
- Your name, email address and profile picture URL, as supplied by Google
- Your Google account identifier, used to recognise you on the next sign-in
- We never receive or store your Google password
2.Schemas and canvas content
Everything you draw is stored so it can be loaded back: model, field and relation names, data types, descriptions, colours, positions, nested document structure, and the version snapshots you cut.
Schema content is treated as your private work. It is not used for advertising, not sold, and not used to train models.
3.Sharing and collaboration
- Email addresses you invite to a schema, and the access level you granted
- Public share links, which carry a random token in the URL — anyone holding that link can read the schema without signing in, so treat the link itself as the credential
- Rotating a share link revokes the previous one
4.Agent access tokens
Tokens created for AI agents are stored as a hash, never as plaintext. The full token is shown once at creation and cannot be retrieved afterwards. We keep the token name, a short non-secret prefix so you can tell them apart, and the time it was last used.
5.Bug reports
If you report an issue, we attach diagnostics to help reproduce it: the page path, app version, browser user agent and viewport size, along with the schema it concerned.
6.Collected automatically
- IP address, browser and device information, and pages visited
- Google Analytics cookies, used to understand which features get used. Once you are signed in, your account identifier — not your email — is attached, so visits from your phone and your laptop count as one person rather than two.
- Microsoft Clarity cookies, which record how a page is used — clicks, scrolling and mouse movement — so problems in the interface can be found. Once you are signed in, your email address is attached to that recording so a problem you report can be traced to it. Clarity does not run on shared or embedded schema pages.
- A session cookie once you sign in, which is what keeps you signed in
- Preferences such as your theme, stored in your browser and never sent to us
7.The playground needs no account
Playground schemas are static files served to your browser. Nothing you do there is sent to a server, stored, or associated with you — edits live in the tab and are gone when you close it. You can use the product fully without ever creating an account.
8.How we use information
- To operate the canvas: storing your schemas and loading them back
- To sign you in and keep you signed in
- To share schemas with the people you invite
- To understand which features are used, so the product can be improved
- To investigate bugs, abuse and security problems
- To meet legal obligations
9.What we do not do
- We do not sell personal information
- We do not use your schema content to train AI models
- We do not show advertising
- We do not process payments — hellodb is free, and no card details are collected
10.Third-party services
Sign-in is provided by Google. Analytics is Google Analytics and Microsoft Clarity. The service runs on Amazon Web Services. These providers operate independently under their own privacy policies.
You can block analytics cookies through your browser settings; the product works normally without them.
11.Where data is stored
Data is processed and stored on cloud infrastructure located in India. Backups are encrypted and retained on the same infrastructure.
12.Retention
Schemas and account details are kept while your account exists. Delete a schema and it is removed along with its versions. Ask for your account to be deleted and we remove your account record and the schemas you own, except where something must be retained for legal or security reasons.
13.Security
Traffic is served over HTTPS, sessions are cookie-based, and agent tokens are stored only as hashes. No system can promise absolute security, and we do not claim to.
14.Your rights
- Ask what personal information we hold about you
- Correct anything inaccurate
- Ask for your account and schemas to be deleted
- Export your schemas at any time — Markdown and full-fidelity JSON, from the canvas itself, with no request needed
- Withdraw consent by signing out and deleting your account
15.Children
hellodb is not intended for anyone under 18, and we do not knowingly collect their information.
16.Changes
This policy may be updated. The revision date at the top always reflects the current version, and continued use after a change means you accept it.
17.Contact
For privacy questions or any request above, write to hello@hellodb.io.