Privacy Policy
The short version: FathomSQL is a local Mac application. Your database credentials never leave your device. We collect only what's needed to process your purchase. We don't sell your data, ever.
1. Who We Are
FathomSQL is developed and operated by Durandal. You can reach us at [email protected]. When this policy refers to "we", "us", or "our", it means Durandal.
2. What This Policy Covers
This policy applies to the FathomSQL macOS application and the website at fathomsql.com. It describes what personal data we collect, why we collect it, how we use it, and what rights you have over it.
This policy does not constitute legal advice. The English version controls in any translation conflict.
3. Data We Collect
3.1 Purchase Data (via LemonSqueezy)
When you purchase FathomSQL, your transaction is processed by LemonSqueezy, who acts as the Merchant of Record. LemonSqueezy collects your email address, name, billing address, and payment information. We receive your email address and purchase record so we can deliver your license and provide support. We never see or store your full payment card details.
3.2 Support Communications
If you contact us by email, we receive and retain the content of that communication and your email address in order to respond to you.
3.3 Website Analytics
Our website uses privacy-respecting, cookie-free analytics to understand aggregate traffic patterns (page views, referrers, country-level geography). No personally identifiable information is collected through website analytics, and no cookies are set for tracking purposes.
3.4 What We Do Not Collect
We do not collect, transmit, or store any of the following:
- Your database connection details, hostnames, or credentials
- Your database passwords (these are stored exclusively in the macOS Keychain on your device)
- Any query results, table data, or schema information from your databases
- In-app usage telemetry or behavioural analytics
FathomSQL communicates directly between your Mac and your PostgreSQL server. Nothing passes through our infrastructure.
4. Local Data (Stored Only on Your Device)
The following data is stored exclusively on your Mac and is never transmitted to us:
- Connection configurations — saved connection names, hosts, ports, and usernames
- Passwords — stored in the macOS Keychain using Apple's secure credential storage APIs
- App preferences — your UI settings and window layout
You are responsible for backing up this local data. We have no ability to recover it if your device is lost or reset.
5. How We Use Your Data
We use the data we collect to:
- Deliver and activate your FathomSQL license
- Provide customer support and respond to your enquiries
- Send transactional emails related to your purchase (receipts, license confirmation)
- Comply with legal and accounting obligations
- Improve the website based on aggregate usage patterns
We do not use your data for automated decision-making, profiling, or advertising.
6. Legal Bases for Processing (GDPR)
If you are located in the EU or EEA, we process your personal data under the following legal bases:
- Performance of a contract (Article 6(1)(b)) — to deliver your license and provide support
- Legitimate interest (Article 6(1)(f)) — for aggregate website analytics and fraud prevention
- Legal obligation (Article 6(1)(c)) — to comply with tax and accounting requirements
- Consent (Article 6(1)(a)) — for any optional marketing communications, which you may withdraw at any time
7. Third-Party Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| LemonSqueezy | Payment processing & Merchant of Record | Email, name, billing address, payment info |
| Website host | Hosting fathomsql.com | IP addresses, access logs |
| Email provider | Transactional emails (receipts, license delivery) | Email address |
Each provider is required to protect your data in accordance with applicable privacy law. We do not sell your personal information to any third party.
8. Cookies and Tracking
Website: We do not use cookies for analytics or advertising. Our analytics provider is cookie-free. LemonSqueezy may set strictly necessary cookies during the checkout process.
macOS App: The application does not use browser cookies. All local data is stored in macOS-standard locations (Keychain, UserDefaults, or the application's container).
9. Data Retention
- Purchase records — retained by LemonSqueezy per their tax and accounting obligations (typically 5–10 years)
- Support email — retained while your query is open, plus a reasonable period thereafter
- Website analytics — aggregated and anonymised; no individual retention period applies
- Local app data — retained on your device until you delete it
10. Data Security
We take appropriate technical and organisational measures to protect your personal data. Database credentials are stored in the macOS Keychain. Data in transit between FathomSQL and your PostgreSQL server is protected by TLS where your server supports it. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. International Data Transfers
LemonSqueezy operates in the United States. If you are located in the EU, EEA, or UK, transfers to LemonSqueezy are subject to appropriate safeguards including Standard Contractual Clauses or LemonSqueezy's own compliance certifications. Our website host may also process data outside the EU; such transfers rely on the same mechanisms.
12. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your personal data (subject to legal retention obligations)
- Restriction — ask us to limit processing in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, email [email protected]. We will respond within 30 days.
13. EU/EEA Users — GDPR
If you are located in the EU or EEA, the General Data Protection Regulation (GDPR) applies to our processing of your personal data. Your rights are as described in Section 12. You also have the right to lodge a complaint with the supervisory authority in your country of residence. A list of EU data protection authorities is available at edpb.europa.eu.
14. UK Users — UK GDPR
If you are located in the United Kingdom, the UK GDPR and Data Protection Act 2018 apply. Your rights mirror those described in Section 12. International transfers use International Data Transfer Agreements or UK-approved Standard Contractual Clauses. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
15. California Residents — CCPA/CPRA
If you are a California resident, you have the right to know what personal information we collect, delete it, correct it, and opt out of any sale or sharing. We do not sell or share your personal information. To exercise your rights, contact us at [email protected]. We will respond within 45 days of verifying your identity.
Categories of personal information collected include: identifiers (email address), commercial information (purchase records), and internet activity (aggregate website analytics).
16. Other US State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other US states with comprehensive privacy legislation have rights similar to those in Section 12. Exercise your rights by contacting [email protected].
17. Children's Privacy
FathomSQL is intended for use by developers and database professionals aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
18. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email to the address associated with your purchase, or via a notice on our website. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of FathomSQL after changes are posted constitutes your acceptance of the updated policy.
19. Contact
For any privacy-related enquiries or to exercise your rights:
Durandal
[email protected]
We aim to respond to all enquiries within 30 days.