Last updated 21 September 2026
Privacy Policy
Denis Cloud is a hosted database service. This page says exactly what we store about you, why, for how long, and how you exercise your rights. It follows the EU General Data Protection Regulation (GDPR) and applies to every user, wherever they are.
1. Who is responsible
The data controller is Hacı Mert Gökhan. Contact for anything in this policy: hacimertgokhan@gmail.com.
2. What we store, and why
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Name, email address, password hash (or the identity returned by GitHub if you sign in that way) | Your account: signing in, showing who did what, contacting you about the service | Contract (GDPR art. 6(1)(b)) | Until you delete the account |
| Session records: a random token, IP address, browser user agent, timestamps | Keeping you signed in; spotting stolen sessions | Contract; legitimate interest in security (GDPR art. 6(1)(f)) | 30 days after the last use, or until you sign out |
| Databases you create: name, region, limits, usage counters, the engine project token | Providing the service and enforcing the quotas you agreed to | Contract | Until you delete the database or the account |
| The contents of your databases (keys, values, tables) | Stored and returned on your instructions only. You decide what goes in; we do not read it except to operate the service | Contract; you are the controller of any personal data you put there and we act as your processor (GDPR art. 28) | Until you delete it; at most 30 days in backups afterwards |
| API keys (hashed), members, database accounts (hashed passwords) | Letting applications, teammates and AI assistants use a database with the access you chose | Contract | Until revoked or the database is deleted |
| Command history: the command text, who ran it, the result and latency | Letting you audit what happened in your database; abuse detection | Legitimate interest (security, accountability); shown to the database's owner, admins, editors and viewers | 30 days, then deleted automatically. Sign-in lines are never stored |
| Audit log: account and database events (created, deleted, shared, suspended) | Support and accountability | Legitimate interest | 12 months |
| Email: your address, for verification and sign-in codes, password resets, notices about sign-ins from new browsers and — only if you opted in — product updates | Confirming the address is yours, signing in without a password, recovering access; telling you about releases | Contract for codes and resets; consent for product updates (withdraw with one click in any message or under Settings) | Codes expire after 10 minutes; the opt-in until you withdraw it. Sent through Resend as our processor |
| Request logs on the server: IP address, path, status, timing | Keeping the service up; rate limiting; investigating attacks | Legitimate interest | 14 days |
We do not run advertising, analytics or tracking scripts, we do not sell data, and we do not build profiles. Nothing on these pages loads from a third party except your GitHub avatar if you chose GitHub sign-in.
3. Cookies
Only strictly necessary cookies are set: the session cookie after you sign in, a cookie per database when you sign in to a database's own login page, and a theme preference kept in your browser's local storage. None of them is used to track you across sites, so no consent banner is needed. Details are on the cookie page.
4. Who else sees the data
Processors that host the service: the server provider that runs the engine, the web app and the PostgreSQL database that holds account data (all in the same data centre region), Resend (resend.com), which delivers our email and sees the address and content of each message, and GitHub if you sign in with GitHub (only your public profile and email are received). Each processor is bound by a data processing agreement. We disclose data to authorities only when the law requires it, and we tell you unless that is prohibited.
5. Where the data lives
Account data and database contents are stored in the region shown on the database (eu-central at the moment). If we ever transfer data outside the European Economic Area, we rely on the European Commission's standard contractual clauses or an adequacy decision, and update this page first.
6. How we protect it
TLS everywhere, passwords hashed with scrypt, API keys stored only as SHA-256 hashes and shown once, per-database isolation inside the engine, rate limits on sign-in and on the API, security headers and a content security policy, and access to production limited to the operator. The security page goes into detail and explains how to report a vulnerability.
7. Your rights
Under the GDPR (articles 15 to 22) you can ask what we hold about you, get a copy, have it corrected or deleted, restrict or object to processing, take your data elsewhere, and complain to the data protection authority of your country. Two of these you can do yourself, right now:
- Export: Settings → Your data → Download my data gives you a JSON file with everything in the table above that belongs to you.
- Delete: Settings → Your data → Delete account removes the account, every database you own, its API keys, members, database accounts and sessions immediately; backups expire within 30 days.
For anything else write to hacimertgokhan@gmail.com from the address on your account. We answer within one month, as the GDPR requires, and aim for a few days. No fee is charged.
8. Children
The service is not directed at children under 16 and we do not knowingly create accounts for them.
9. Changes
When this policy changes in a way that matters, the date at the top moves and signed-in users see a notice in the application before the change takes effect. Earlier versions are available on request.