Draft — not in effect. These pages describe intended practices and will change before launch.

Privacy

A short summary of what Querlyn intends to collect, and what it is designed never to see.

Querlyn is a service from Converged Innovations, LLC.

Your databases

  • Querlyn's servers never proxy database traffic, and never see SQL or query results: the app connects directly from your computer to your databases.
  • No analytics on database content. Your queries, schemas and data are never analysed.
  • Telemetry is off.

Encrypted sync

Sync is planned. Content you sync will be end-to-end encrypted on your devices, and Querlyn will never be able to read it.

Synced data is stored, encrypted, in our database. For synced content the servers store only ciphertext and what keeping it in order needs: object identifiers chosen by your devices, kinds (connections without their passwords, SSH routes, saved queries, snippets and settings; database passwords and query history only if you turn each on), sizes and hashes of the encrypted data, revision numbers, dates, the devices that made each change, and your storage usage. Never connection names, host names, SQL or results in readable form.

Teams (planned)

Teams are planned. For a team, Querlyn will store administrative records — the team, its members and their roles, seat assignments, and an audit log of team changes — so it can manage access and billing. Shared team workspaces will be end-to-end encrypted like personal ones: Querlyn will not be able to read them.

Support bundles

A support bundle is a diagnostics file the desktop app sends only when you agree to that upload. Only Querlyn staff can open it, each opening is recorded, and it is deleted after 14 days. A deleted bundle remains in our encrypted backups for up to seven days, until those backups expire.

Retention

  • Accounts whose email address is never verified: removed seven days after sign-up (eight while a verification link sent near the end is still valid), with their password.
  • Synced data after a subscription ends: readable for 30 days; deletion schedule to be decided.
  • Backups (encrypted): retention period to be decided; deleted data leaves backups when they expire. Deleted synced data remains in our encrypted database backups until those backups expire.
  • Security events and sign-in records: retention period to be decided.

To be decided before launch: these periods and the jurisdiction.

Account data we store

  • Your email address, and whether you have verified it.
  • Sign-in sessions: when each began and was last used, with a short browser description and the IP address it came from, so you can recognise and end them.
  • Security events, such as sign-ins, password changes and changes to two-step verification, with the IP address each came from, so you and we can investigate problems. They are kept when you delete your account.
  • Support requests you send from your account or the app, our replies, and notes our support staff keep about them. Deleting your account deletes them, and your account export includes your requests and our replies.

Your password is stored only as a one-way hash, never as readable text.