The short version
SeedQL is built and run by one independent developer and funded by voluntary supporter donations (Buy Me a Coffee memberships) — not by ads, data resale, or venture capital. That model is why this policy is short on collection and long on restraint: we keep the minimum needed to run the service, we never see your payment card, we never store the synthetic data we generate for you, and we have no business reason to track you around the web. Supporting the developer keeps it that way.
1. Scope of this policy
This policy describes how SeedQL ("SeedQL," "we," "us," "our") collects, uses, retains, and shares personal data when you visit seedql.io, sign up for an account, or use the SeedQL service to generate synthetic test data. It does not cover third-party websites you reach via links from our service.
2. What we collect
- Account data — your email address and the workspace / organization names you create. Sign-in is handled by Supabase Auth (email + password, or Google sign-in); your password is stored as a salted hash by Supabase and never reaches SeedQL's application servers.
- Support & membership data — SeedQL is funded by donations via Buy Me a Coffee. When you join a membership there, BMC notifies us (over a signed webhook) of your supporter email, the membership level, and its status, which we use to unlock the matching feature tier and honour cancellations. Card numbers, CVV, and bank details are handled entirely by Buy Me a Coffee and its payment providers — they never reach our servers, and we issue no invoices.
- Usage telemetry — counts of generations, row counts, template identifiers, request timestamps. Used to enforce tier quotas and to surface usage on your Settings page.
- Database connection metadata — host, port, database name, and a credential reference you supply when configuring a target. Credentials are encrypted at rest and used only to write the synthetic rows you request.
- Server logs — IP address, user agent, request path, response status, and approximate geographic region. Rotated per the retention schedule in §4.
- Error telemetry — when the application encounters an exception, the stack trace and (where set) a user identifier are sent to our error-monitoring sub-processor (see §6).
3. What we don't collect
We don't collect, retain, or analyze the synthetic data SeedQL generates. The synthetic rows produced by your generation jobs flow directly from our generator to your target database; we do not store a copy. We don't read the contents of your existing tables beyond the schema metadata required to honour foreign-key relationships during generation.
We don't use marketing cookies or third-party advertising trackers. We don't sell personal data, and we don't share it with data brokers.
4. Retention
| Data class | Retention window |
|---|---|
| Account data | Lifetime of account; 30 days after deletion request |
| Support & membership records (BMC webhook events) | Lifetime of account; removed with your account on deletion request. Payment records themselves live with Buy Me a Coffee under its own policy. |
| Usage telemetry (per-request detail) | 90 days, then aggregated |
| Server logs | 30 days |
| Error telemetry (Sentry) | 90 days (per Sentry default) |
| Generated synthetic data | Not retained (ephemeral; streamed direct to your target) |
5. Legal basis for processing (EEA / UK users)
- Contract — account data, billing data, and the database connection metadata needed to deliver the service.
- Legitimate interests — usage telemetry for quota enforcement, server logs for security and abuse detection, error telemetry for incident response.
- Legal obligation — billing data retained for tax / accounting periods.
- Consent — any optional features marked as such at the point of collection.
6. Sub-processors
SeedQL relies on the following sub-processors to deliver the service. We share with them only the data needed for their function, under data-processing agreements (DPAs) where applicable.
| Sub-processor | Function | Data shared | Location |
|---|---|---|---|
| Buy Me a Coffee (Publisherr, Inc.) | Donation & membership platform — supporters pay BMC directly under BMC's own terms and privacy policy; BMC notifies SeedQL of memberships via signed webhook | We RECEIVE (not send): supporter email, membership level, status. Payment instruments never reach SeedQL. | United States |
| Supabase, Inc. | Database hosting (PostgreSQL) and authentication (Supabase Auth — password hashes, OAuth identities) | All account, membership, and usage telemetry data; credentials for sign-in | United States (us-east-1) |
| Cloudflare, Inc. | DNS management for seedql.io | DNS query metadata only (site traffic is served by Vercel / Railway, not proxied through Cloudflare) | Global network |
| Resend, Inc. | Transactional email (organization invitations; operator notifications for contact-form and capacity requests) | Email address, message body, send timestamp | United States (us-east-1) |
| Vercel, Inc. | Frontend hosting, edge functions | IP address, user agent, request path (transient) | United States (iad1) |
| Railway Corp. | Backend application hosting | All server-side request data during processing | United States (us-east) |
| Functional Software, Inc. (Sentry) | Error monitoring, exception tracking (integrated; data flows only once monitoring is switched on) | Stack traces, request context, optional user identifier | United States |
We update this list before adding a new sub-processor that materially affects how personal data is handled. Email privacy@seedql.io to subscribe to sub-processor change notifications.
7. International transfers
Our sub-processors are primarily located in the United States. For EEA / UK / Swiss data subjects, transfers occur under the Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms established with each sub-processor. Specific transfer-impact assessments and DPA references will be added after operator-led legal review.
8. Your rights
Subject to applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Deletion — ask us to delete your account and the personal data tied to it (subject to billing-record retention obligations in §4).
- Restriction — ask us to limit how we process your data while a complaint is open.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests; we will weigh your objection against the interest.
- Withdraw consent — where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint — with your local supervisory authority.
To exercise any of these rights, email privacy@seedql.io. We aim to respond within 30 days. We will not discriminate against you for exercising your rights.
9. California residents (CCPA / CPRA)
In the past 12 months we have collected the categories of personal data described in §2 for the purposes described in §2 and §5. We do not sell personal information and we do not share it for cross-context behavioural advertising. California residents may exercise the rights described in §8 and may designate an authorised agent to make a request on their behalf.
10. Security
We protect personal data in transit with TLS 1.2+ and at rest with encryption provided by our database sub-processor (Supabase). Passwords are stored as salted hashes inside Supabase Auth and never reach SeedQL's application servers. Payments happen entirely on Buy Me a Coffee — SeedQL never sees card numbers, CVVs, or bank details; the only payment-related data we hold is the supporter email, membership level, and status delivered over an HMAC-signature-verified webhook.
The database connection credentials you supply for generation targets are encrypted at rest and wiped from storage as soon as the job that needed them reaches a terminal state.
No system is perfectly secure. If we discover a security incident affecting your personal data, we will notify you and the relevant authorities as required by applicable law.
11. Children
SeedQL is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, email privacy@seedql.io and we will delete it.
12. Beta period
SeedQL is in active development. Features, pricing, and data- handling practices may change. Material changes to this policy will be communicated by email and reflected in the "Last updated" date at the top of this page at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
13. Governing law
[Placeholder — to be set after legal review] This policy and any dispute or claim arising out of it are governed by the laws of [jurisdiction TBD], without regard to its conflict-of-laws principles.
14. Contact
Privacy questions, rights requests, or sub-processor change subscriptions: privacy@seedql.io
This page is a first draft authored 2026-05-28. Specific clauses about governing law, international transfers under SCCs / IDTA, California-resident rights phrasing, and any jurisdiction-specific data-subject rights phrasing will be confirmed (and any inaccurate placeholders corrected) after operator-led legal review and before the D5 real-production cutover.