Skip to content

Legal

Privacy Policy

Last updated

DuckHouse runs DuckDB warehouses for you. This policy explains what we collect about you and your team, what we do with the data you put in your warehouses, who else handles it, and what you can ask us to do about it.

01Who we are

DuckHouse is operated by JoeDesigns.com, 110 2nd St Sutie 501 Albuquerque NM 87102 ("DuckHouse", "we", "us"). Questions about this policy go to hello@duckhouse.co.

For your account, organization and billing details we decide what is collected and why. For the data you load into a warehouse, you decide; we store and process it on your instructions, as your service provider.

02What we collect

Your account. Your name and email address, and a profile image if you sign in with Google or GitHub. If you sign in with a password we store only a hash of it. If you sign in with Google or GitHub, we store the tokens that provider gives us for the sign-in.

Your sessions. The IP address and browser user agent of each signed-in session, so you can recognise your sessions and we can spot abuse.

The waitlist. If you ask for an invite: your email address and, if you give them, your name, company and what you plan to use DuckHouse for.

Your organization. Its name, its members and their roles, invitations you send (including the invitee's email address), and the API keys, OAuth grants and database tokens created in it.

Billing. Your organization's name and the billing contact's email address, which we share with Stripe. Card details go directly to Stripe; we never see or store a full card number. We keep a record of your usage (how long each warehouse ran and at what size, and how much storage it used), the statements we issue and any credits on your account.

Service logs. Our servers record requests, errors and performance data so we can run and fix the service. These records can include IP addresses, account and organization identifiers and, occasionally, an email address in an error message.

Website analytics. On our public website (not in the dashboard) we count page views with Umami, a privacy-focused analytics tool that does not use cookies or track you across sites.

03The data in your warehouses

The tables you create, the data you load and the data our connectors sync for you belong to you. We do not sell it, use it to train models, or look through it.

To run the service we read a small amount about your warehouses, not from them:

  • Sizes: how much storage a database uses, its memory use, how many tables it has and an estimate of how many rows they hold.
  • Query activity: how many queries ran each minute, how many failed and how long they took. Your warehouse briefly holds the text of recent queries in memory to produce these counts, then discards it. We do not store query text or results.
  • Connector runs: when each sync ran, how many rows it moved, and the error message if it failed.

Our staff access the contents of a warehouse only when you ask us to (for example, to help with a support request), when it is necessary to keep the service secure, or when the law requires it.

Connector credentials. Passwords, API keys and other secrets you give a connector are encrypted before we store them, and are used only to sync the sources you configured.

04How we use it

  • To provide the service: create and run your warehouses, sync your connectors and sign you in.
  • To bill you for what you use, and to keep the records tax law requires.
  • To send you the emails the service needs, such as an invitation to an organization.
  • To keep the service secure, investigate abuse and fix problems.
  • To understand, in aggregate, how the website and product are used, so we can improve them.

05Who else handles it

We do not sell personal information or share it for advertising. We use these service providers, each only for the job listed:

  • Fly.io: runs our servers and your warehouse machines and disks.
  • Tigris: object storage for your warehouse data, snapshots and backups.
  • PlanetScale: our own database (accounts, organizations, billing records) and the catalogs of DuckLake warehouses.
  • Stripe: payment processing and invoices.
  • Maple: service logs, traces and metrics.
  • Bird: delivers the emails the service sends.
  • Google and GitHub: only if you choose to sign in with them.

Connectors send requests to the services you connect (for example your Postgres database, Stripe or Shopify account) using the credentials you provide. What those services do with that access is governed by your agreement with them.

We may also disclose information when the law requires it, to protect the rights and safety of our users or the service, or to a successor if DuckHouse is sold or merged, in which case this policy continues to apply to it.

06Where it lives

You choose the region each warehouse runs in when you create it, and its data stays in that region's machine and storage. Our own systems, which hold account, organization and billing information, run in the United States. If you are outside the United States, that information is transferred there.

07How long we keep it

  • Warehouse data stays until you delete the database. Deleting a database removes its machine, disk, storage and backups straight away; it cannot be undone.
  • Backups are kept on a rolling schedule (daily, weekly and monthly copies, at least 30 days) while the database exists.
  • Your account is kept while it is active. To have it deleted, email us at hello@duckhouse.co.
  • Billing records are kept for 10 years, as tax and accounting law requires, even after an account is deleted.
  • Service logs are kept for 30 days.
  • Waitlist entries are kept until you are invited or ask us to remove you.

08Cookies and browser storage

We use only what the site needs to work. There are no advertising or tracking cookies.

  • duckhouse.session_token and duckhouse.session_data: keep you signed in, for up to 7 days.
  • sidebar_state: remembers whether the dashboard sidebar is open.
  • In your browser's local storage: your light or dark theme choice, and which changelog entries you have seen.

09Security

Each database runs on its own machine with its own disk, storage bucket and storage credentials. Traffic to DuckHouse and to your warehouses is encrypted in transit, warehouse disks are encrypted at rest, connector credentials are encrypted before storage, and API keys are stored only as hashes.

No system is perfectly secure. If a breach affects your information, we will tell you without undue delay and as the law requires. To report a vulnerability, email hello@duckhouse.co.

10Your rights

Depending on where you live (for example in the EU, the UK or California), you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy of it, or object to how we use it. Anyone can ask; email hello@duckhouse.co and we will answer within 30 days. We will not treat you differently for asking.

For data inside a warehouse that belongs to your organization, contact the organization's owner; we act on their instructions. You can also complain to your local data protection authority.

11Children

DuckHouse is a service for businesses and developers. It is not meant for anyone under 16, and we do not knowingly collect their information.

12Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we handle your information, we will tell account owners by email or in the dashboard before it takes effect.