Legal · Privacy policy

Privacy policy

DBHost is a one-person managed PostgreSQL service operated from Norway. This page explains what personal data we collect, why we collect it, where it lives, and what rights you have. It pairs with our Data Processing Addendum (which covers the database contents you upload) and our Security policy.

Last updated: July 22, 2026

What we collect

  • Account data: your email address (via Clerk, our identity provider) and payment details (via Stripe, our payment processor). We never see or store raw card numbers.
  • Database connection metadata: database names, region, plan, storage size, connection counts. We do not read the rows inside your databases.
  • Audit log: a record of dashboard and API actions you take (database created, backup triggered, key issued) so you and we can trace activity.
  • Contact submissions: your name, email, optional company, topic and message, together with delivery status and basic request metadata such as IP address, referrer, user agent and signed-in user ID when available.
  • Cookies and analytics: essential session cookies are set by Clerk. Vercel Analytics supplies aggregate, cookie-free page-usage measurements. DBHost does not load Google Analytics.

Why we collect it

  • To operate the service: provision databases, run backups, bill you, send transactional email.
  • To send critical security notices (account changes, abnormal access patterns, breach notifications).
  • To prevent abuse and protect the platform from misuse.
  • To comply with tax, accounting, and legal obligations under Norwegian and EU law.

Where it’s stored

Primary data stores are in the EU. Vercel serves the web application through its global network, with DBHost functions configured in Stockholm (arn1). Hetzner HEL1 (Helsinki) hosts the control-plane and tenant databases, and AWS S3 in Stockholm (eu-north-1) stores encrypted backups. Clerk, Stripe, and Resend process some data in the United States under their applicable GDPR transfer mechanisms, including EU Standard Contractual Clauses where required.

The full list of sub-processors lives in our Data Processing Addendum.

How long we keep it

  • Account data: while your account exists and as needed to operate it. Cancelling a paid subscription does not itself delete the account; verified deletion requests are handled separately.
  • Contact submissions and audit records: while needed for support, sales follow-up, security, and an operational trace. You can request deletion where no legal or security obligation requires continued retention.
  • Backups: 30 days, enforced by an S3 lifecycle rule on the backup bucket.
  • Payment and invoice records: five years after the end of the relevant financial year, as required for primary accounting documentation under Norwegian law.

Your rights

Under GDPR you have the following rights, and DBHost honours them:

  • Access and export: download your audit activity as CSV from /settings/data.
  • Correction: edit your profile and email from the dashboard.
  • Deletion: email stian@dbhost.app. Our verified process covers account data, contact submissions and customer data; plan cancellation alone is not a deletion request.
  • Portability: the audit CSV export above is machine-readable. Database contents are yours — take a backup from the dashboard at any time.
  • Objection / restriction: contact us and we will pause non-essential processing while we discuss.

Security

The technical and organisational measures we use to protect your data are described in our Security policy.

Children

DBHost is a developer tool and is not directed at users under the age of 16. We do not knowingly collect personal data from children.

Contact and complaints

For any privacy question, email stian@dbhost.app. If you are unhappy with our response, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

Changes to this policy

We may update this policy as the service evolves. Material changes are notified by email at least 30 days before they take effect. Minor edits (clarifications, typo fixes) are reflected by the “Last updated” date at the top of the page.

Questions?

Privacy questions, data requests, or anything you’d like clarified — we read every message.

Contact the team →