// the fine print, but honest

Privacy Policy

Or as I like to call it: the page where I promise not to be a creep.

By reading this page, you consent to me knowing exactly what you’re thinking right now, in real time, and selling that information to the highest bidder. Your innermost thoughts, your doubts about that LEFT JOIN you wrote last Tuesday, the way you briefly considered switching to NoSQL - all of it, packaged and monetized. Don’t worry, I’ll get top dollar.

Just kidding. But here’s the thing - that’s essentially what everyone else’s privacy policy says, buried under 4,000 words of legalese and a cookie banner with a “Reject All” button that’s somehow four clicks deep. Every app you use is out here hoovering up your data like a dragon guarding its hoard - fiercely, greedily, and with zero intention of sharing the gold with you. They track your clicks, your scrolls, your hesitations, your location, your dog’s name. They build shadow profiles. They sell you to advertisers. You are the product, the cattle, the resource being mined. And they have the audacity to call it “enhancing your experience.”

SQLly does none of that. Everything you do with this app is none of my business. I don’t collect your queries, your schemas, your connection strings, your browsing habits, or your taste in wallpapers. I don’t have analytics dashboards showing “user engagement funnels.” I don’t run A/B tests on you. There is no telemetry pipeline, no data lake, no “anonymized” dataset that - surprise - turns out to be trivially deanonymizable. Nothing. Nada. Zilch. The app runs on your machine, talks to your databases, and that’s where the story ends.

Down the road, I might add some totally anonymized feature-usage collection. Not real-time, not tied to you, not spooky - just a way for me to see which features people actually use so I can pour my limited time into the ones you love. That’s it. That collection, if it ever happens, won’t track your OS, won’t log your IP, and won’t be tied to you in any way - the only IP addresses and platform details recorded anywhere are the download and checkout records described in What I do track below. And to be crystal clear about the feature-usage thing: I will update this very page before I add it to the app. It will be off by default. It will be clearly stated in the changelog that it was added, that it’s off by default, and exactly what it does. No sneaky rollouts, no “minor improvements” that are actually telemetry. You’ll know before it ships, and you’ll have to opt in. The app stores logs on your machine, but I have no way to get to them unless you physically send them to me. Your data stays your data, on your disk, behind your firewall, guarded by your own personal dragon.

And a word about what’s coming: SQLly Cloud will let the app reach your databases through a relay I operate. That relay is zero-knowledge by design - your queries, results, and credentials travel end-to-end encrypted with keys that exist only on your devices, so I couldn’t read them if I wanted to. What the relay necessarily does see is routing metadata: which of your paired devices talked, when, and how many encrypted bytes moved. That’s inherent to being the thing in the middle that forwards your traffic. The full design - what’s visible, what never can be - is spelled out on the Cloud Relay page, and when you use the relay that page counts as part of this policy.

A quick word about the website, since you’re on it. If you create an account, I store what an account needs: your email, a display name if you give one, and which license or subscription you bought. Payments are handled by a real payment processor - card numbers never touch my servers. The download page counts downloads (a number goes up; nothing about you is attached to it), and if you write a review it’s tied to your account, because that’s the entire point of a review. The fine print on downloads and purchases is in What I do track below. No analytics suite, no ad pixels, no fingerprinting script quietly judging your scroll speed.

What I do track

“I don’t track you” deserves fine print, so here it is - the complete, honest list of what gets recorded when you touch this site.

Downloads

Every time anyone downloads any version of SQLly, the download records the IP address the request came from, the browser’s user agent, which version of SQLly was downloaded, the platform (Windows, Linux, or macOS), and the architecture (x64 or ARM). It does not matter whether you are logged in or out - I do not track who downloaded it, and none of that information is associated with your account or with anything else that could identify you. It exists so the download counter is honest and I can see which platforms and versions people are grabbing.

Purchases

When you buy a subscription, I record what you purchased, the account that bought it, and the IP address used at checkout. Payments themselves are processed by Stripe, so whatever data Stripe collects and retains about your payment - your card details, billing information, and their own fraud-prevention records - lives with Stripe under their policies, not on my servers. Card numbers never touch my servers.

🐉

I do my best to make SQLly secure. I follow good practices, I don’t store secrets in plaintext, I don’t do anything reckless. But I’m going to be honest with you: I have a day job and I am not a security expert. This is a tool built by one person who cares, not a corporation with a SOC 2 audit and a dedicated security team. If this thing gets popular and I start making some real money from it, I’ll get every claim on this page third-party reviewed and audited. I’ll put my money where my mouth is. But until then, you’re taking the word of a pig mascot and the human behind it. I think that’s worth something, but I understand if you want to verify.

Here’s the real business model, stripped of all pretense: I will offer you an app. I will nag you to pay for it. If you don’t pay - and you really should if you like it - I will keep nagging you. Gentle, playful nagging, the kind a friend does when you still haven’t watched that show they recommended. But if you do pay, I’m out of your hair. No more nags, no more prompts, no more “hey have you considered the pro tier.” Just the app, doing its job, quietly. And here’s the kicker: even if you never pay, even if you ride the free tier forever, I still don’t track you. The nagware is the worst you’ll get from me. That’s my promise. Most companies can’t say that because their business model depends on you being the product. Mine depends on you maybe, eventually, optionally, buying a license. That’s it.

Honestly, I’m a little surprised you found this page. The footer link just says “Privacy” and most people scroll right past it. I kind of assumed the only person who’d ever read this would be me, checking the formatting at 2 AM. But here you are, actually reading the privacy policy. That tells me you’re either the kind of person who reads terms of service for fun, or you’ve been burned before and you want to make sure I’m not going to sell your soul to an ad network. Either way, I respect it. I respect you. And I promise: no dragons were harmed in the making of this policy, and no data was collected from your reading of it. Though if I were tracking you, I’d at least have the decency to tell you. Which, come to think of it, I just did. So we’re good.

TL;DR

I don’t collect your data. I don’t track you. I don’t know what you’re doing and I don’t want to. The app is yours, your data is yours, your logs are yours. The website keeps only what an account needs, downloads and purchases record the basics spelled out above (never tied to who you are when you download), and the cloud relay is built so it can route your traffic without ever reading it. I’ll nag you to pay if you don’t, but even then I won’t spy on you. If this gets big enough, I’ll get audited to prove it. You found this page, which is kind of wild. Thanks for reading.