Skip to content
Rowsafe

Privacy policy

Last updated: September 24, 2026

1. Who is responsible

Rowsafe is operated by Adraa Labs (“Adraa Labs”, “we”, “us”). We are the controller for the personal data described here. Contact us at [email protected]. If you use Rowsafe on behalf of an organization and your database metadata contains personal data, we process it on that organization's behalf; a data processing agreement is available on request.

2. What we collect

  • Account data: your name, email address, password (stored as a hash) or GitHub sign-in, organization and member roles, and invitations.
  • Billing data: your plan and subscription status. Payment details are collected and processed by Polar, our merchant of record; we don't receive your card number.
  • Database metadata sent by the agent: host names, database names and sizes, table counts, PostgreSQL version and settings, backup, restore check and restore point results, task logs, and performance metrics such as connections, locks, disk use and host CPU and memory.
  • Query statistics: normalized statements from pg_stat_statements, in which PostgreSQL replaces literal values with placeholders.
  • Query text of long-running queries: for sessions running or idle in a transaction for over a minute, the first 500 characters of the statement as sent by the client, which can include literal values. You can turn this off with ROWSAFE_COLLECT_QUERY_TEXT=false on the agent.
  • Usage and security data: sign-in events, the audit log of changes, API key usage, IP addresses and basic device information in server logs.
  • Communications: messages you send us and notification settings, such as the email addresses, Slack, Discord or webhook destinations you configure for alerts.

3. What we never see

  • The contents of your backups. They are encrypted on your server with your passphrase before they are uploaded, and go directly to your own bucket, not through us.
  • Your encryption passphrase and your bucket credentials. They stay on your server.
  • The rows in your database. The agent reports metadata and statistics, not table contents.

4. Why we use it

  • To provide the Service: run your account, schedule backups and checks, show health in the dashboard and send the alerts you set up (performance of our contract with you).
  • To bill you through Polar and meet tax and accounting obligations (contract and legal obligation).
  • To keep the Service secure, prevent abuse and fix problems (legitimate interests).
  • To send service emails, such as verification, alerts and important changes. We only send marketing emails if you opt in, and you can unsubscribe anytime.
  • To measure our advertising, only if you accept analytics and advertising cookies (consent).

5. Who processes it for us

We use these subprocessors, each bound by contract to protect the data:

  • Cloudflare: website hosting, content delivery, DNS and network protection.
  • LightNode: hosting of our control plane and dashboard, in Germany.
  • Amazon Web Services (Amazon SES): sending email.
  • Polar: payments, subscriptions, tax and invoices, as merchant of record.
  • GitHub: sign-in, only if you choose to sign in with GitHub.
  • Google: advertising and analytics measurement on the website, only if you accept those cookies.

Some of these providers may process data outside your country. Where required, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses. We'll update this list before adding a new subprocessor.

6. How long we keep it

  • Account and organization data: while your account is active, and deleted within 30 days after you delete it, except what we must keep for legal or tax reasons.
  • Performance metrics: up to 90 days, at decreasing detail. Resolved alerts: 90 days. Delivered notifications: 30 days.
  • Backup, restore check and task history: while the database is registered with Rowsafe.
  • Backups of our own systems roll over within 35 days.
  • Billing records are kept by Polar and us as long as tax law requires.

7. Your rights

Depending on where you live, including under the GDPR, you can ask us to access, correct, export or delete your personal data, to restrict or object to how we use it, and to withdraw consent at any time. Email [email protected]; we'll answer within 30 days. You can also complain to your local data protection authority.

8. Cookies and similar storage

The website and dashboard use essential storage only, such as your sign-in session and your light or dark theme preference. If the website shows a cookie banner, advertising and analytics cookies (Google) are used only after you accept, and you can change your choice by clearing the site's storage in your browser. We use Google Consent Mode, so without your consent Google tags don't store advertising or analytics cookies.

9. Security

We protect your data with encryption in transit, hashed passwords and tokens, access controls and audit logs. Our security page explains how Rowsafe is designed so that we never hold the keys to your backups.

10. Children

The Service is for businesses and professionals and is not intended for children under 16.

11. Changes

We'll update this policy when our practices change and change the date above. For material changes we'll notify account owners by email or in the dashboard.