Privacy Policy
Last updated: July 19, 2026
NexQL is a local-first VS Code extension — most of what you do (connecting to databases, running queries, viewing results) never leaves your machine. This page explains, in full, the data our website and backend services (checkout, license activation, optional Cloud Sync, optional hosted AI) do collect, and — just as importantly — what they don't.
1. What stays on your machine
The extension core runs entirely inside your VS Code instance. Database connection credentials (hosts, usernames, passwords) are encrypted and stored locally using VS Code's built-in Secret Storage (OS keychain) — they are never sent to NexQL servers, even if you use paid features. Query results and table data you view in NexQL never pass through our backend at all; they go directly between your machine and your database.
2. Data we collect, and why
| Data | When | Why |
|---|---|---|
| Email address | Checkout (via Razorpay) or GitHub OAuth sign-in for NexQL Free AI / Cloud Sync | Deliver your license key, identify your account, send billing receipts |
| License key & subscription status | After a paid checkout | Activate Sponsor/Singularity features in the extension |
| GitHub user ID | Only if you sign in with GitHub for free-tier AI or Cloud Sync | Identify your session without a license key; enforce free-tier usage limits |
| Device ID / device name | Cloud Sync device authorization | Let you see and revoke which devices are linked to your account |
| Connection profiles, saved queries, notebooks (no passwords) | Only if you opt in to Cloud Sync (paid feature) | Sync your workspace across your own devices |
| Monthly AI token counts | Any AI request through the NexQL Free AI gateway | Enforce the monthly usage cap for your tier — we do not log the content of your prompts or AI responses |
| Standard request logs (IP, timestamp, endpoint) | Every request to our API, via our host (Vercel) | Security, abuse prevention, debugging — not used for tracking or advertising |
3. What we never collect
- Database passwords or connection credentials (local Secret Storage only)
- Your query results, table contents, or schema data
- Full payment card numbers — Razorpay handles and stores those under PCI-DSS
- The text of your AI prompts, generated SQL, or AI responses
4. Third parties we use
- Razorpay — payment processing for Sponsor/Singularity subscriptions. See their privacy policy.
- Resend — sends license-key and receipt emails.
- Neon (Postgres) — stores license/subscription records, Cloud Sync data, and AI usage counters.
- Vercel — hosts the website and serverless API, and generates standard access logs.
- AI providers — if you bring your own API key (OpenAI, Anthropic, Gemini, etc.), your prompts go directly to that provider under their own privacy policy. NexQL Free AI routes through our managed AI gateway, which does not retain prompt content beyond what's needed to complete the request.
- Google Fonts — the website loads typefaces from Google Fonts' CDN, which sees the request per Google's own policies. No analytics or advertising trackers are used on this site.
5. Data retention
License and billing records are kept for as long as your account is active, and afterward as needed for tax/accounting records. Cloud Sync data for an account that loses paid access is retained for 30 days and then permanently purged (see the retention job in our backend). Monthly AI usage counters reset every calendar month and aren't kept indefinitely.
6. Your choices
- Cloud Sync is entirely opt-in — the extension works fully without it.
- You can revoke a linked device from your account at any time.
- You can cancel your subscription anytime; see the Terms of Service.
- To request deletion or an export of the data we hold about you, email support@astrx.dev from the address on your account. We'll respond and act on verified requests.
7. Children's privacy
NexQL is a developer tool and is not directed at, or knowingly used to collect data from, children under 13.
8. Changes to this policy
If we change what we collect or how we use it, we'll update the "Last updated" date above and, for material changes, note it in the changelog.
9. Contact
Questions, data requests, or concerns: support@astrx.dev.