Legal
Privacy
Last updated: 16 July 2026
Plain-English on purpose, and honest — this page describes only what nlqdb actually does today. Questions: hello@nlqdb.com.
nlqdb collects as little as it can. This page lists everything we touch — if it isn't here, we don't collect it.
Who runs nlqdb
nlqdb is operated by Omer Hochman, an individual (sole proprietor) based in Switzerland. For anything on this page — access, deletion, questions, complaints — the data controller's contact is hello@nlqdb.com.
What we collect
- Account (only if you sign in). Signing in uses Google or GitHub OAuth, or an emailed magic link. We receive and store your email address (and the basic profile an OAuth provider shares), plus a session cookie so you stay signed in. We never see your provider password.
- Query text. The plain-English questions you ask, and the data in the databases you create, are sent to a large-language-model provider so nlqdb can turn them into a query and answer them. Providers in our chain are listed under Subprocessors below. If you bring your own LLM key, your query text goes to the provider you chose, under your own account.
- Anonymous use. Before you sign in, your prompts and a temporary token live in your browser's local storage on your device, not on our servers. Databases you create anonymously are temporary and are deleted automatically (see the Terms). The queries you run are still sent to our API and an LLM provider to be answered.
- Crash & telemetry. If a page crashes, the browser sends us the error message, the URL, and your browser's user-agent string so we can fix it. We also record operational telemetry (timings, error rates, coarse request metadata) to keep the service fast and reliable. Best-effort, never used for advertising.
- Product analytics. On the signed-in product surfaces
(
/app) we use PostHog to understand which features are used. Session replay masks all inputs and the conversation area, so your query text and database contents are not recorded. Marketing pages ship no analytics SDK; public page views use Cloudflare's cookieless analytics. - Support chat. App pages (
/app, not marketing pages) load a Tawk.to chat widget so you can message us. Tawk.to may set its own cookies and processes chat messages on its infrastructure under its own privacy policy (see Subprocessors below). - Payments. If you subscribe to a paid plan, Stripe processes the payment. We receive billing status and customer identifiers from Stripe; we never see or store your full card number.
What we don't do
- No advertising or marketing trackers, no third-party ad pixels.
- We don't sell or share your personal information, in the CCPA sense or any other.
- We don't use your data to train our own models.
Why we're allowed to (legal bases)
If the EU/UK GDPR or the Swiss Federal Act on Data Protection (FADP) applies to you, we rely on these bases:
- Contract. Handling your account, answering your queries, and running paid plans — the processing needed to give you the service you asked for.
- Legitimate interests. Crash telemetry, security, abuse prevention, and product analytics, to keep the service working and safe. You can object to processing based on this.
- Legal obligation. Keeping the payment and tax records the law requires.
Subprocessors
We use a small set of infrastructure providers to run the service. They process data only to provide their part of it, under their own privacy terms.
- Cloudflare (US) — hosting, Workers compute, object & edge storage, bot protection (Turnstile), the LLM request gateway, and one LLM inference option (Workers AI).
- Neon (US) — the managed Postgres that stores your databases.
- Tinybird (US) — the ClickHouse analytics engine and query-log store.
- Groq (US) — LLM inference.
- Google (Gemini via Google AI Studio, US) — LLM inference.
- Cerebras (US) — LLM inference.
- Mistral AI (EU/France) — LLM inference.
- OpenRouter (US) — LLM inference routing (fallback).
- Stripe (US/EU) — payment processing for paid plans.
- Resend (US) — transactional email (magic links, receipts).
- Grafana Cloud (US) — observability and error telemetry.
- PostHog (EU region) — product analytics on
/apponly. - tawk.to (US) — in-app support chat on the
/apppages only (chat messages, visitor metadata). - LogSnag (US) — internal operational event notifications.
On a paid or premium tier, query text may additionally be routed to a frontier LLM provider (currently Anthropic or OpenAI) to improve answer quality. We'll keep this list current; material additions are dated at the top of this page.
International transfers
We're based in Switzerland and many of our subprocessors are in the United States, so your data may be transferred outside Switzerland and the EEA. Where a provider is in a country without a Swiss/EU adequacy decision, the transfer is covered by the appropriate safeguard — the EU/Swiss–US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses (with the Swiss FDPIC addendum) otherwise.
How long we keep it
We keep your data for as long as you have an account. When you delete your account (or ask us to delete your data), we remove it from our live systems and purge it from backups within 30 days. Anonymous databases are deleted automatically, at the latest 90 days after they were last used. We keep the minimum payment and tax records the law requires for longer.
Your rights
Under the GDPR, the Swiss FADP, and the CCPA you can ask us to give you a copy of your data, correct it, delete it, or restrict or object to how we use it — and, where the CCPA applies, to know what we collect. We don't sell or share personal information, so there's nothing to opt out of, and we won't discriminate against you for exercising any right. To make a request, email hello@nlqdb.com; we'll respond within the time the applicable law allows. You may also complain to your data-protection authority — the Swiss FDPIC, or your EU/UK supervisory authority.
Changes
If this policy changes materially, we'll date the change at the top of this page.