Privacy

Privacy Policy

DBX is local-first. The application does not require a DBX cloud account, and the project maintainers do not receive your database contents or credentials by default.

Effective date
September 27, 2026
Last updated
September 27, 2026

Local by default

Application settings, saved SQL, connection definitions, and protected secrets stay in the DBX data directory you control.

Network access is contextual

DBX contacts databases and optional services only as required by the connections and features you configure or use.

Website data is separate

Website analytics, GitHub sign-in, and support submissions are described separately from data stored by your DBX installation.

01

Scope and responsibility

This policy covers the official DBX application, including desktop, Web, Docker, and NAS distributions, and the dbxio.com website operated for the DBX project.

When you self-host DBX, you or your organization controls the deployment, users, databases, backups, and access policies. The DBX project is normally not the controller or processor of data stored inside that deployment.

A database, AI provider, synchronization service, identity provider, plugin source, application store, or other third party you choose has its own terms and privacy practices.

02

Data stored by the DBX application

DBX stores the information needed to provide the features you enable. Depending on how you use it, this can include:

  • Database connection definitions, application preferences, saved SQL, query-related workspace state, and backup metadata.
  • Plugin settings, AI provider settings, SSH tunnel settings, and WebDAV or code-hosting synchronization settings.
  • Credentials such as passwords, tokens, and private-key passphrases when you choose to save them.

Sensitive fields are protected by the DBX Secret Store before they are written to the application database. On Web, Docker, and NAS deployments, the encryption key and database are part of the same data-directory recovery unit. Anyone who can copy the complete application data volume may be able to copy both, so operating-system permissions, NAS access controls, and backup security remain important.

03

When the application uses the network

Not every installation uses every service below. Network requests occur when a configured feature needs them, or when you explicitly invoke that feature.

FeatureDestination and possible data
Database connections

The database or data-service endpoint you configure. Protocol traffic can include credentials, queries, metadata, and returned data.

AI assistance

The AI provider or compatible endpoint you select. Requests can include your prompt and the SQL, schema, error, selection, or other context needed for the requested task.

Synchronization

The WebDAV, GitHub, or Gitee service you configure. DBX sends the synchronization package and the authentication information required by that service.

Plugins, drivers, and updates

Official or user-configured download sources. Requests can reveal ordinary network metadata and the version, platform, package, plugin, or driver being requested.

OAuth and external authentication

The identity provider required by the database or service you choose. The exchanged identity and tokens follow that provider's protocol and policy.

DBX does not control how a destination service retains or uses data. Review the destination, minimize the context you send, use TLS where available, and do not send sensitive production data to a service you do not trust.

04

Data handled by dbxio.com

Hosting and analytics

The website loads an analytics script from analytics.unihub.top. Website hosting and analytics requests may process technical information normally sent by a browser, such as IP address, user agent, referrer, requested page, timestamp, and usage events, depending on the active service configuration.

GitHub sign-in

If you choose GitHub sign-in for a website feature, GitHub authenticates you and the site reads your GitHub login, avatar URL, and profile URL. The temporary OAuth access token is discarded after that public identity is read. A signed session cookie can remain for up to seven days.

Issue drafting and submission

The issue form sends the description and any screenshots you provide to the configured AI service to prepare a draft. A draft is kept for about 30 minutes, the anonymous issue session for up to 24 hours, and rate-limit records for about one hour. Nothing is published until you review and confirm the draft.

Public support content

After confirmation, the issue title, body, and uploaded images become public on GitHub and associated public image hosting. Do not submit passwords, tokens, private keys, connection strings, unredacted logs, customer data, or other confidential or personal information.

05

Retention, export, and deletion

Application data remains in the data directory, system credential store, configured synchronization destination, and backups until you or the system administrator removes it. Deleting a connection or configuration does not automatically erase independent backups or copies already synchronized to a third party.

You can delete application records through DBX and remove the application data directory when uninstalling. Export anything you need before deletion. For fnOS and other application stores, the final removal behavior also depends on the choices and rules presented by that platform.

Short-lived website authentication, draft, and rate-limit records expire as described above. Published GitHub Issues and images follow GitHub and hosting retention rules and may remain in caches, forks, notifications, or archives even after a deletion request. Operational logs and analytics data are retained according to the current hosting and analytics configuration for security, abuse prevention, and maintenance.

06

Security boundaries

DBX uses safeguards such as encrypted secret storage, signed packages, sandboxing for supported plugin paths, and authenticated website sessions where applicable. No system can guarantee absolute security.

Protect the device and data directory, restrict network exposure, use strong DBX and database credentials, keep DBX and its dependencies updated, verify third-party endpoints, and secure exported or synchronized data. If you operate DBX for other people, you are responsible for appropriate access control, notices, and legal compliance.

07

Policy changes and contact

We may update this policy when DBX features, website services, or legal requirements change. The effective date at the top identifies the current version. Material changes should be reflected in the project website or release materials.

For privacy or security questions, contact the DBX maintainers through the GitHub support channel. Do not include sensitive information in a public Issue; ask for an appropriate private contact path first if the request itself contains confidential details.

Open the DBX support channel

This policy describes the official DBX project. A distributor or organization offering its own DBX service may provide additional terms that also apply.