Ad measurement on this website

With your consent, we use Google Ads to measure whether our ads lead to downloads. Google sets cookies for this and processes data, including in the USA. We do not use it for personalised advertising. You can withdraw your consent at any time under “Privacy settings” at the bottom of the page. Privacy policy

sqlclient
Features For teams Documentation Log in
Download
enEnglish deDeutsch frFrançais itItaliano esEspañol plPolski roRomână nlNederlands svSvenska csČeština

Privacy Policy for sqlclient

Last updated: 18 September 2026. This is a translation of the German privacy policy at sqlclient.eu/privacy/; in case of doubt, the German version prevails.

1. Controller and contact

The controller within the meaning of Art. 4 No. 7 GDPR is Datargo GmbH, Omniturm, Neue Mainzer Str. 52-58, 60311 Frankfurt am Main, Germany. Managing director: Andreas Mallek. Commercial register: Amtsgericht Friedberg (Hessen), HRB 9742. VAT ID: DE320115003. You can reach us at info@datargo.com.

No data protection officer has been appointed. For privacy requests, please write to the e-mail address above.

2. Legal bases and your rights

We process personal data only to the extent required for the purposes described below. The legal bases are in particular Art. 6(1)(b) GDPR (contract and pre-contractual measures), Art. 6(1)(c) (legal obligation), Art. 6(1)(f) (legitimate interest in the secure and economical operation of our services) and, where expressly obtained, Art. 6(1)(a) GDPR (consent).

Subject to the statutory conditions, you have the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Art. 6(1)(f) GDPR. You may withdraw consent at any time with effect for the future. A message to the address given in section 1 is sufficient to exercise your rights.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for Datargo GmbH is the Hessian Commissioner for Data Protection and Freedom of Information, Wilhelmstraße 7, 65185 Wiesbaden, Germany, datenschutz.hessen.de.

3. Website, downloads and technical provision

Our marketing website is served by Cloudflare Pages. Purchase, account, licence retrieval, device reconciliation and the receipt of payment webhooks run on Cloudflare Workers; shop data is processed in Cloudflare D1. Public download files are served from dl.sqlclient.eu.

When you visit, the data technically required for an HTTP request may be processed, in particular IP address, date and time, requested address, referrer (where transmitted), browser and operating system information, response status, and security and diagnostic information. The purposes are delivery, security, error analysis and the prevention of abuse. The legal basis is Art. 6(1)(f) GDPR.

Cloudflare processes data as a technical service provider. Information on its processing can be found in the Cloudflare privacy policy. Data may also be processed outside the European Economic Area; the safeguards used follow from Cloudflare’s contractual and privacy documentation.

4. Browser storage and language settings

The website stores the display mode you choose under sc-theme in local storage. A deliberately chosen language (sc-lang) and the status of a dismissed language hint (sc-langhint-weg) are stored locally for 24 hours each. An automatic language redirect is marked only for the duration of the session under sc-lang-auto in session storage. These values are not transmitted to us. Your decision on ad measurement (section 5) is stored under sc-consent in local storage for twelve months so that we do not ask again on every visit; only the decision is stored, no user identifier.

This storage serves to provide the display and language settings you chose and to document your decision. Where strictly necessary for this, we rely on § 25(2) No. 2 TDDDG (German Telecommunications Digital Services Data Protection Act); the processing of personal data rests on Art. 6(1)(f) GDPR. The display setting remains stored until you delete or change it in your browser; the other values expire as described.

For the price display, the website may read the country code determined by Cloudflare from a technical response in order to show a suitable currency. The country code is not stored in the browser.

5. Google Ads conversion measurement

We run ads on Google. To measure whether these ads lead to downloads, we use Google Ads conversion tracking, but only with your consent. On your first visit we ask you in a notice at the bottom of the screen. As long as you have not agreed, the Google script is not loaded and no data is transmitted to Google (Consent Mode v2, basic variant). Declining is as easy as accepting and has no disadvantages for using the website.

After you consent, your browser loads the script gtag.js from googletagmanager.com. Google then sets the cookies _gcl_au and, if you arrived via an ad, _gcl_aw (each valid for 90 days) and processes the ad click identifier (gclid), your IP address, browser and device characteristics, the address requested, the referrer, the time and the measured event. Measured events are the click on the app download and copying the install command. Google and we use this data to attribute ad clicks to these events and to evaluate the effectiveness of the ads. We do not use the data for personalised advertising; the corresponding setting (ad_personalization) remains disabled even after your consent.

With your consent, we also store the click identifier under sc-gclid in your browser’s local storage for 90 days. It serves to attribute a later purchase to the ad through which you found us; in that case we transmit the identifier together with the time of purchase and the status of your consent to Google Ads. No transmission takes place from within the app.

The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which processes the data as an independent controller; data may also reach Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023). How Google processes data from sites that use Google services is explained at business.safety.google/privacy; Google’s privacy policy is at policies.google.com/privacy.

The legal basis for storing and reading information on your device is § 25(1) TDDDG, and for the processing of personal data Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by choosing “Privacy settings” at the bottom of any page and clicking “Decline”. On withdrawal we delete the _gcl_ cookies set by Google and the stored click identifier. Data already transmitted to Google is not affected; the lawfulness of processing before the withdrawal remains unaffected.

6. Reach measurement with Umami

To understand which pages are read and which campaigns bring visitors, we use the open-source software Umami, which we run ourselves on a server in the European Union. No third parties are involved. Measurement is server-side: your browser loads no measurement script, no cookies are set and no information is stored on or read from your device. Page views are counted by our server from the request your browser makes to load the page anyway. When you click the download, copy the install command or view the prices, the page sends a short message to our own server (sqlclient.eu/t/event) containing only the name of the event and the page requested. We also count actual fetches of the installer, the install script and the app’s update check on our download server (dl.sqlclient.eu). Umami records only the file fetched, the kind of program fetching it (browser, terminal, Homebrew, app) and the country. The app’s update check itself is unchanged: it transmits no identifier, no settings and no content. The browser settings “Do Not Track” and “Global Privacy Control” are respected; in that case no measurement takes place.

Collected are the page requested (without click identifiers; of the address parameters only the campaign values utm_ are kept), the referrer, browser and operating system type, language, the country derived from the IP address and the events mentioned. The IP address is used only transiently to form a daily changing visitor hash salted with a secret and is not stored. This does not allow us to identify you. The statistics are deleted after 13 months.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is measuring the reach of our website and our ads without using third-party tracking services. You may object to this processing at any time under Art. 21 GDPR, for example by enabling “Do Not Track” in your browser or by a message to the address given in section 1.

7. Contact and CRM chat

If you contact us by e-mail, we process the data you provide, in particular e-mail address, name and message content, to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns a contract or its initiation, otherwise Art. 6(1)(f) GDPR.

The chat is operated by Datargo GmbH itself and is not embedded when the page loads. Only after you deliberately choose “Open chat” does your browser load the widget from api.crm.datargo.com. From that moment the chat service processes the technical request of your browser and, if used, the content of your message and any contact details you provide voluntarily. Our contact form is available as an alternative.

Clicking “Open chat” calls up the chat function you requested. The processing serves to handle your enquiry and rests on Art. 6(1)(b) or (f) GDPR.

Opening the contact page loads the contact-form widget of our self-hosted Datargo CRM from api.crm.datargo.com. Submitting the form sends your name, email address, optional company, message and the SQLClient product association to our CRM to handle your enquiry. Technical requests and abuse-prevention measures occur when opening or using the form. The processing uses the legal bases stated above for contact enquiries.

8. Purchase, payment and contract management

For a purchase you are redirected to a checkout page provided by Stripe. There, Stripe directly processes the data required for payment and invoicing. The purchase service transmits to Stripe the chosen plan, database scope, billing interval, number of seats, currency, language and, if available, your pre-filled e-mail address. Billing address, tax ID collection and automatic tax calculation are enabled in the checkout.

After a successful purchase, Datargo processes in the shop database in particular your e-mail address, Stripe customer, checkout and subscription identifiers, plan, scope, number of seats, currency, contract status and term. For the contract confirmation we also store the order and invoicing details transmitted at conclusion, the specific scope of services and prices confirmed, and the version of the contract documents sent at conclusion. To issue and manage your licence, Datargo also processes licence key, the signed licence token, entitlements and licence status. The purpose is the initiation, performance and management of the licence agreement, payment processing, invoicing, fraud and abuse prevention and compliance with legal obligations. The legal basis is Art. 6(1)(b) and (c) GDPR; for security and anti-abuse measures Art. 6(1)(f) GDPR.

A customer portal provided by Stripe may be used to manage a running subscription. Stripe processes data according to its own privacy information: stripe.com/privacy. Data may also be processed outside the European Economic Area; the safeguards used by Stripe follow from its privacy and contractual documentation.

9. Account, magic link and e-mails

There is no password for accessing the account. When you request a sign-in link, we store your e-mail address, the cryptographic hash of the one-time link, the time of creation, the expiry time and, where applicable, the time of use. The link is valid for 20 minutes and can be used only once. IP addresses are not stored in the shop database for this.

To prevent abuse, at most three link requests per e-mail address are possible within 15 minutes. For this counter only an HMAC value of the e-mail address formed with a secret key is stored; the counter is removed automatically after more than 24 hours.

After successful sign-in we set a signed cookie sc_session. It contains your encoded e-mail address, is set HttpOnly, Secure and SameSite=Lax and is valid for at most 14 days. Its purpose is secure access to the account. The legal basis is Art. 6(1)(b) GDPR; storing the cookie is necessary for the sign-in you requested under § 25(2) No. 2 TDDDG.

We send licence, purchase and sign-in link e-mails via our SMTP service. Recipient address, subject, message text and technical delivery information are processed. Licence e-mails may contain licence key, plan, entitlements and term; purchase e-mails contain the contract confirmation including order, service, price and contract documents; sign-in link e-mails contain the one-time link. In the shop database, e-mail address, delivery type, delivery status, error details and timestamps are logged so that delivery and retries can be operated. The legal basis is Art. 6(1)(b) GDPR and, as far as operational and abuse security is concerned, Art. 6(1)(f) GDPR.

10. Payment webhooks, licence retrieval and device reconciliation

Stripe transmits payment events to our webhook. We process at least the Stripe event identifier, event type, processing status and time of receipt. For events relevant to contract performance, the contract and licence data described in section 8 are updated. The purpose is the secure and single attribution of payments and licences. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

Using your licence identifier, the app can retrieve a signed licence token via https://sqlclient.eu/license. For an active direct-sales licence this happens automatically at most once a day, at most every six hours shortly before expiry, or manually at your request. Under an active direct-sales contract, the app may additionally transmit, at most once a day, the licence ID and a licence-bound pseudonymous device hash to https://sqlclient.eu/api/devices. The hash is formed from a hardware identifier and the licence ID; if no hardware identifier is available, the app uses a locally generated random identifier. It serves solely to control the number of seats agreed in the contract.

The device hash cannot be reused across different licences. Device hashes whose last contact is more than 90 days ago are removed at the next device report. The legal basis for licence retrieval and seat control is Art. 6(1)(b) GDPR; in addition Art. 6(1)(f) GDPR for protection against licence abuse.

11. The macOS app: local data and iCloud sync

The app stores connection profiles including host, port, user name, database name, password and TLS and SSH settings locally in an encrypted database. Profiles are encrypted with AES-256-GCM; the key is derived from the master password. The master password is not stored. With Touch ID enabled, the derived key may be placed in the macOS keychain.

The app may also store locally SQL documents including their content, SQL history, snippets and an audit log. The audit log may contain time, connection identifier, database, the writing SQL or DDL statement, result and affected rows. It is limited to 2,000 entries. This local data does not leave your device unless you use one of the functions described below.

iCloud sync is optional. If you enable it, a sync file is stored in your iCloud Drive. Connection profiles are encrypted in it. Profile name, whether a password is present, and modification and deletion times are in plain text to control synchronisation. Individual profiles can be excluded from sync. The master password is not transmitted to Datargo. Processing by Apple/iCloud follows the Apple privacy information applicable to your Apple account.

12. Updates and local AI feature

Retail versions of the app may fetch update information from https://dl.sqlclient.eu/sqlclient/latest.json at launch and thereafter at most once a day. The update check can be switched off; download and installation take place only after your confirmation. App Store versions use no updater of their own. During the request, the technical infrastructure processes the data required for the HTTP request, in particular your IP address and request metadata. The legal basis is Art. 6(1)(f) GDPR.

The app uses no usage, analytics or crash telemetry of its own. This does not cover unavoidable technical logs of the online services named in this policy or system services of your operating system.

The optional local AI feature uses Apple Foundation Models. When used, it processes only the error texts, SQL statements and column names and types handed to it, not table rows. Processing by Apple system services follows Apple’s privacy information.

13. Retention and security

We delete or anonymise data as soon as it is no longer required for the respective purpose and no statutory retention obligations or legal claims stand in the way. Magic link rate-limit values are removed automatically after more than 24 hours. Inactive device hashes are removed at the next device report if the last contact is more than 90 days ago.

Customer, purchase, licence, sign-in link, e-mail log and webhook data are stored for contract management, technical operation, error analysis and, where required, to comply with statutory retention obligations and to establish, exercise or defend legal claims. Sign-in links can no longer be used for sign-in after they expire or are used.

We use technical and organisational measures to protect data appropriately against loss, alteration and unauthorised access. These include encrypted transmission, signed licence and session data, one-time sign-in links, limited link requests and cryptographic verification of payment webhooks. Security measures are reviewed continuously and adapted to the state of the art.

sqlclient © 2026 Datargo GmbH · Frankfurt am Main · Contact
Documentation Features SQLite on Mac For teams Windows Log in Imprint Terms Privacy Cancel subscription
Language English Deutsch Français Italiano Español Polski Română Nederlands Svenska Čeština

Contact