Privacy Policy
Last updated: 2 August 2026
This Privacy Policy explains how Koode ("Squeezle", "we", "us", or "our") handles personal data when you use Squeezle, a multi-tenant SQL workbench for connecting to and querying your own databases.
Squeezle plays two different roles. For the data we need to run our business (your account, your organization, billing, and usage), we are the controller, and this policy describes what we do. For the data inside the databases you connect and the results of the queries you run (your "Customer Data"), we act as a processor on your behalf; that processing is governed by our Data Processing Agreement, and the organization that connected the database is the controller.
1. Who we are
Squeezle is operated by Koode (registered with the Netherlands Chamber of Commerce under KvK 71804005, VAT NL002347344B92), Koode, Postbus 8830, 1006 JA Amsterdam, the Netherlands. For any privacy question, or to exercise your rights, contact us at privacy@squeezle.app.
2. Data we collect
We collect the following categories of data.
- Account and identity data. Your name and email address, and the public-key credentials for your passkeys. Squeezle is passwordless: we never collect or store passwords. Where your organization uses single sign-on, we also process the identifiers your identity provider sends us.
- Organization data. Your organization's name, its members and their roles, and its settings, including access controls and column-sensitivity rules.
- Connection metadata and credentials. To connect a database you give us its host, port, database name, and username, and a password or other secret. The connection password is encrypted at rest; single sign-on secrets and any AI provider key you supply are also encrypted at rest (see Security).
- Customer Data and query results. When you run a query, we process the SQL you write, its parameters, and the results returned from your database. Results can contain personal data, which is why we provide sensitivity controls. A preview slice and the full result set are cached temporarily so you can view, export, and share them; saved queries and dashboards persist until you delete them.
- Usage and audit data. We keep an append-only audit log of security-relevant events, such as sign-ins, query runs (including the compiled SQL and its parameters), connection and permission changes, token creation, and AI requests. Audit entries include the actor, the action, a timestamp, the IP address, and the user agent.
- AI usage data. If you use the AI assistant, we record which organization used it and how many tokens were used, for metering. The prompt and context sent to the AI provider are described in the AI section below.
- Billing data. If you subscribe to a paid plan, we store your subscription state (customer and subscription identifiers, plan, seats, status, and renewal or cancellation dates). Card details are handled by our payment processor, Stripe, and are not stored by Squeezle.
- Cookies. We set one strictly necessary session cookie. See our Cookie Policy.
3. How and why we use data
We use the data above to:
- Provide the service: authenticate you, connect to your databases, run your queries, and return results.
- Apply your access controls and column-sensitivity rules so people see only what they are permitted to see.
- Keep the service secure, prevent abuse, and maintain the audit log for accountability.
- Provide optional AI assistance when you choose to use it.
- Process payments and manage subscriptions.
- Support you, respond to your requests, and send service and administrative messages.
- Comply with our legal obligations.
4. Legal bases (GDPR)
Where the General Data Protection Regulation applies, we rely on the following legal bases for processing the data for which we are the controller:
- Performance of a contract (Article 6(1)(b)): to provide the service to you and your organization under our Terms.
- Legitimate interests (Article 6(1)(f)): to secure the service, prevent abuse, keep audit records, and improve the product, balanced against your rights.
- Legal obligation (Article 6(1)(c)): to meet accounting, tax, and other legal requirements.
- Consent (Article 6(1)(a)): where we ask for it, for example any optional communications; you can withdraw consent at any time.
For personal data inside your Customer Data, your organization is the controller and determines the legal basis; we process it on your documented instructions as a processor.
5. AI features
The AI assistant is optional and off unless enabled for your organization. When it is used, we send the AI provider a prompt together with context needed to answer, which can include database schema information and, for some requests, samples of real data from the connected database (for example a small number of example rows or common values). The assistant is read-only and respects the acting user's permissions; it does not run the drafted query against your database.
Depending on your plan, AI runs with credits included in your plan (using our AI provider account) or with your own provider key. Our current AI provider is listed on the Sub-processors page. We do not use your Customer Data to train our own or third parties' AI models.
6. Data retention
We keep data for different periods depending on its purpose:
- Query results. Cached previews and full result sets are retained for a limited period (by default 72 hours) and then deleted automatically. They are a cache for convenience, not a permanent record.
- Saved queries and dashboards. Kept until you delete them.
- Sessions. The session cookie lasts up to 30 days; signing out ends the session.
- Share links and access grants. Expire at the time you set, or automatically.
- Audit log. Retained as an append-only record for accountability and security. How far back it can be queried may depend on your plan.
- Account, organization, and billing data. Kept for as long as your account is active and thereafter as needed to meet legal, accounting, and dispute-resolution obligations.
7. How we protect data
We use a range of technical and organizational measures to protect data, including:
- Encryption at rest for secrets. Database connection passwords, single sign-on secrets, and any AI provider key you supply are encrypted at rest using authenticated AES-256-GCM encryption, with keys held outside the application database. Other connection metadata (host, port, database name, username) is stored so the connection can be made.
- Encryption in transit. Traffic to the service is served over HTTPS/TLS.
- Passwordless authentication. Sign-in uses passkeys (WebAuthn), and optionally your organization's single sign-on; there are no passwords to steal.
- Tenant isolation and access controls. Each organization's data is separated, and per-person access controls, row limits, and column-sensitivity rules govern what each member can see. Queries that would touch data above a user's clearance are refused.
- Audit logging. Security-relevant events are recorded in a tamper-evident, append-only log.
No method of transmission or storage is completely secure, but we work to protect your data and to notify you of incidents as required by law. To report a security concern, contact security@squeezle.app.
8. Sub-processors
We use a small number of third-party providers to host the application, store data, process payments, monitor errors, send email, and provide optional AI. The current list, with each provider's purpose and location, is on our Sub-processors page. We put appropriate data-protection terms in place with each of them.
9. International transfers
Some of our providers are located in, or process data in, countries outside your own, including the United States. Where we transfer personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses [and the UK International Data Transfer Addendum]. You can contact us for more information about these safeguards.
10. Your rights
Subject to applicable law, you have rights over your personal data. Where the GDPR or similar laws apply, these include the rights to:
- Access the personal data we hold about you, and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), where the conditions are met.
- Restrict or object to certain processing.
- Data portability, where applicable.
- Withdraw consent where we rely on it, without affecting prior processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact privacy@squeezle.app. We will respond within the time the law allows. If your request concerns personal data inside an organization's Customer Data, we may need to refer you to that organization as the controller, and we will assist them in responding, as set out in our Data Processing Agreement.
11. Children
Squeezle is a business tool and is not directed at children. We do not knowingly collect personal data from children under 16 (or the age of digital consent in your country). If you believe a child has provided us personal data, contact us and we will take appropriate steps.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change, we will update the Last updated date above and, where appropriate, give you additional notice. Please review this page periodically.
13. Contact
For any privacy question, or to exercise your rights, contact privacy@squeezle.app, or write to Koode, Koode, Postbus 8830, 1006 JA Amsterdam, the Netherlands.