Last updated: July 2026

This Privacy Policy explains how we collect, use, and protect data across our main website (boringsql.com) and our product platforms, including labs.boringsql.com and hindsight.boringsql.com. boringSQL is operated by Clusterity s.r.o., the data controller for the purposes of this policy.

1. The main website and blog (boringsql.com)

We believe in privacy by design. The main website and blog are built to be as privacy-respecting as possible.

  • Trackers and cookies. We do not use third-party analytics, tracking cookies, or marketing trackers on this domain.
  • Server logs. Like most websites, our servers log basic, non-identifying technical data (such as your IP address and browser type) to ensure site security and stability. This data is kept temporarily and is never used to track you.
  • Newsletter. If you subscribe to the newsletter, we store the email address you provide solely to send you the newsletter. You can unsubscribe at any time using the link in every email.

2. SQL Labs and products (labs.boringsql.com)

When you use our interactive tools or create an account at SQL Labs, we process the minimum amount of data required to provide the service.

  • Account information. If you sign up, we collect your email address and authentication details.
  • Cookies. We use strictly necessary cookies to keep you logged into your account.
  • Product data. Any code, queries, or logs you submit or test within the product are processed strictly to return your results and to maintain your account history. We do not use your submitted data to train models or for any purpose beyond running the service.

3. Hindsight (hindsight.boringsql.com)

Hindsight is our hosted snapshot and insight engine. It is not yet publicly available; this section describes how it handles data for early users. Hindsight is a schema advisor: it works from snapshots of your database structure and does not connect to your production database or store your table data.

  • Account information. If you create an account, we collect your email address and an authentication credential (stored only as a secure hash). We record whether your email has been verified.
  • Team invites. If you invite someone to a workspace, you provide their email address so we can send them a one-time invite link. We use that address only to deliver the invitation and to prefill their signup.
  • Cookies and tokens. We use strictly necessary session cookies to keep you logged in. Access tokens for programmatic and MCP access are stored only as hashes, never in plaintext.
  • Snapshot data. Snapshots you push contain PostgreSQL schema metadata and planner statistics, not your production rows. Planner statistics can include sample values drawn from your columns; Hindsight supports a data-masking mode so these can be excluded before upload. Snapshots are processed strictly to produce your results and workspace history, and are never used to train models.

4. Service providers

We rely on a small number of third-party service providers to run boringSQL and its products. Each processes data only on our behalf, under contract, and only as needed to provide the service:

  • Hetzner (Hetzner Online GmbH): hosting and database infrastructure, in EU data centres. Used across the website and all products.
  • Postmark: transactional email (such as account verification, password reset, and team invites) for SQL Labs and Hindsight.
  • Buttondown: newsletter subscription management and delivery.

We also use a payment processor to handle billing for paid plans.

5. Your rights and data control

Depending on your location (such as the EU under the GDPR or California under the CCPA), you have the right to access, correct, export, or delete the personal data we hold about you, which is primarily your account email. To exercise any of these rights, contact us using the details below.

6. Contact us

If you have any questions or want to request data deletion, contact us at privacy@boringsql.com.