Privacy Policy
Effective: July 13, 2026
1. Identity & Contact
PgBeam ("we", "us", "our") operates the PgBeam platform, including our website, APIs, proxy services, and dashboard. For privacy-related inquiries, contact us at privacy@pgbeam.com.
2. Data We Collect
Account data: Name, email address, and authentication credentials when you create an account.
Organization data: Organization name, slug, member roles, and project configurations.
Usage and billing data: Query counts, cache hit rates, connection metrics, data transfer volumes, and Stripe subscription details.
Technical data: IP address, user agent, and session metadata collected during authentication (stored in the sessions table).
Transient cache data: Query results cached in-memory in the nearest data plane region. Cache data is not persisted to disk and is evicted automatically based on TTL and memory pressure.
3. What We Don't Store
Query results: Cached query results are held transiently in-memory only and are never written to disk or persisted.
Plaintext credentials: Database passwords are encrypted at rest using AES-256-GCM. We never store or log plaintext database credentials.
4. Legal Bases (GDPR Art. 6)
We process your personal data on the following legal bases:
Contract performance: Processing necessary to provide the PgBeam service, manage your account, and fulfill billing obligations.
Legitimate interest (Art. 6(1)(f)): Service security, fraud prevention, and infrastructure monitoring. We also process signed-in users' account identifiers (user ID, email, and name) together with product usage events in our product analytics (PostHog) for product analytics, service improvement, and security. We have assessed that this processing is necessary for these interests, that it is limited to the data needed to understand how authenticated users use the dashboard and website, and that it does not override your interests or fundamental rights and freedoms, because you have an existing relationship with us as a user, the data is not used for advertising or sold, and we apply access controls and retention limits. You have the right to object to this processing at any time under Art. 21 GDPR (see "Your Rights" below and contact privacy@pgbeam.com).
Consent: Marketing communications (you can opt out at any time via your dashboard email preferences or by contacting us).
Cookies: Our analytics run without cookies (see the Cookies and Analytics section below), so we do not set non-essential analytics or tracking cookies and no analytics cookie consent is required. The only cookies we use are strictly necessary ones, such as the dashboard authentication session, which are exempt from consent under the ePrivacy Directive.
5. Your Rights
Under GDPR and applicable privacy laws, you have the right to:
Access: Request a copy of the personal data we hold about you. Rectification: Correct inaccurate personal data. Erasure: Request deletion of your personal data. Portability: Receive your data in a structured, machine-readable format. Restriction: Request that we limit processing of your data. Objection: Object to processing based on legitimate interest.
6. How to Exercise Your Rights
You can export your account data directly from your dashboard settings. To request erasure, you can delete your account through the dashboard. For all other requests, contact us at privacy@pgbeam.com. We will respond within 30 days.
7. Data Retention
We retain data for the following periods:
Sessions: 30 days after expiry. Soft-deleted projects: 90 days (then permanently purged). Query insights: 90 days. Usage data: 365 days. Audit logs: 2 years. Account data: Retained until you delete your account.
8. International Transfers
Your data may be processed in the following locations: Fly.io (data plane proxy, multiple metros worldwide reached via global anycast routing), AWS (control plane, United States), Vercel (United States), PlanetScale (managed PostgreSQL), Stripe (payment processing), and PostHog (product analytics, European Union).
Transfers to the United States. Where we transfer personal data of individuals in the European Economic Area (EEA), the United Kingdom, or Switzerland to sub-processors that process it in the United States (for example AWS, Vercel, and Google LLC for transactional email), we rely on the European Commission's Standard Contractual Clauses (SCCs) adopted on June 4, 2021, incorporating the module appropriate to the transfer (controller-to-processor or controller-to-controller). Where a sub-processor is certified under the EU-US Data Privacy Framework (DPF), we may also rely on that certification for the relevant transfer; this basis is specific to each sub-processor and applies only for as long as that sub-processor maintains an active certification.
United Kingdom. For transfers of personal data subject to UK data protection law, the SCCs are supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner's Office (or, where used, the UK International Data Transfer Agreement (IDTA)). Where a sub-processor is certified under the UK Extension to the EU-US Data Privacy Framework, we may also rely on that certification.
Switzerland. For transfers of personal data subject to the Swiss Federal Act on Data Protection, the SCCs apply with the adaptations recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC), including references to Swiss law and the FDPIC as the competent authority. Where a sub-processor is certified under the Swiss-US Data Privacy Framework, we may also rely on that certification.
Product analytics (PostHog). Our product analytics data is processed by PostHog in the European Union (eu.i.posthog.com). Analytics data from EEA users is therefore not transferred outside the EEA on that leg, and no transfer mechanism is required for it.
Supplementary measures. In addition to these legal mechanisms, we apply supplementary technical and organizational measures that support the transfers, including encryption in transit (TLS), encryption at rest, and access controls that limit who can access personal data.
9. Sub-Processors
We use the following sub-processors to deliver the service:
Fly.io, Inc.: Hosting for the globally distributed database proxy (data plane). Database traffic routed through PgBeam, including queries, results, and connection metadata, is processed on Fly.io Machines across multiple metros worldwide, reached via global anycast routing. Amazon Web Services (AWS): Control plane hosting (United States), including compute, secrets management, and DNS. Vercel: Dashboard and marketing site hosting. PlanetScale: Managed PostgreSQL database for PgBeam's control plane data. Stripe: Payment processing and subscription management. PostHog: Product analytics (account identifiers such as user ID, email, and name, plus product usage events), hosted in the European Union. BetterStack: Uptime monitoring and log management. Google LLC: Transactional email delivery via Google Workspace and Gmail SMTP (for example, account and billing notifications); currently our email provider, hosted in the United States. GitHub: Source code hosting and container registry.
10. Cookies and Analytics
Our analytics do not use cookies. We do not set analytics or tracking cookies on our website, and we do not use a cookie consent banner because no non-essential cookies are set. The only cookies we use are strictly necessary ones, such as the dashboard authentication session, which are exempt from consent under the ePrivacy Directive.
We use Vercel Analytics, a cookieless, privacy-focused analytics service. It does not use cookies, does not track users across sites, and does not collect personally identifiable information.
We also use PostHog for product analytics to understand how the dashboard and website are used. PostHog is configured with memory-only persistence, so it sets no cookies and stores nothing on your device. When you are signed in, PostHog receives account identifiers (user ID, email, and name) associated with your product usage events, processed on the legitimate interest basis described in Section 4. Signed-out visitors are tracked only through anonymous usage events (such as page views), without account identifiers. PostHog processes this data on our behalf, hosted in the European Union.
11. Children
PgBeam is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us at privacy@pgbeam.com.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Categories of personal information collected: Identifiers (name, email, IP address), commercial information (subscription and billing data), and internet activity (usage metrics, session data).
No sale of personal information: We do not sell, rent, or share your personal information for monetary or other valuable consideration.
Your rights: Right to know what personal information we collect and how it is used. Right to delete your personal information. Right to opt-out of the sale of personal information (not applicable as we do not sell data). Right to non-discrimination for exercising your privacy rights.
To exercise your CCPA rights, contact us at privacy@pgbeam.com or use the data export feature in your dashboard.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect. Continued use of the Service after changes take effect constitutes acceptance.
Contact
Questions about this Privacy Policy? Contact us at privacy@pgbeam.com.