Settings and file locations
Tools → Settings, or the Settings button in the toolbar. Two tabs: General and AI.
General
| Setting | Options |
|---|---|
| Interface language | English, Croatian, Bosnian, Slovenian, Italian, German |
| Theme | Dark or Light |
| UI font | System UI (default), Inter, Segoe UI, Roboto, Arial, Monospace |
| Font size (UI) | Size of the interface text |
| DataGrid font | System Mono (default), Consolas, JetBrains Mono, Fira Code, Courier New, Cascadia Code |
| Font size (Grid) | Size of the text in data grids |
A live preview shows both fonts as you change them. Save settings applies, Reset to defaults restores the originals.
A monospaced grid font is worth keeping — columns of numbers line up, and it makes a misaligned import obvious at a glance.
AI
Provider connections are configured on the AI tab — see Setting up a provider.
File locations
Everything NabuSQL stores lives in the application-data directory:
| Platform | Path |
|---|---|
| Windows | %APPDATA%\com.nabusql.app |
| macOS | ~/Library/Application Support/com.nabusql.app |
| Linux | ~/.local/share/com.nabusql.app |
Inside it:
| Item | Contents |
|---|---|
connections.json | Every connection; passwords and SSH passphrases are encrypted |
ai_connections.json | AI provider connections; API keys are encrypted |
license.json | Your activated license |
scheduled_tasks.json | Scheduled tasks |
ssh_keys/ | SSH keys that came with an imported connection file |
plugins/larql/ | The LARQL add-on for Knowledge Lab |
knowledge/models/ | Prepared models (large) |
knowledge/patches/ | Knowledge patches |
Interface settings and query history are kept by the embedded browser component — on Windows in %LOCALAPPDATA%\com.nabusql.app.
How passwords are protected
Database passwords, SSH passwords and passphrases, and AI API keys are encrypted with AES-256-GCM before they are written to disk. The key that encrypts them is kept in your operating system's credential store — Windows Credential Manager (entry NabuSQL/master-key), macOS Keychain or the Linux Secret Service (GNOME Keyring, KWallet). Where no credential store is available, the key is kept in secret.key in the application-data directory, readable only by your account.
On Linux, if your session has no default keyring yet, GNOME asks you to create one the first time NabuSQL saves a password. Give it the same password as your login and it unlocks automatically when you sign in. If the keyring is locked, NabuSQL asks you to unlock it rather than losing saved passwords.
Nothing changes in how you work: NabuSQL decrypts the values in memory when a connection needs them. Connections saved by version 1.0.105 or earlier are encrypted automatically the first time a newer version starts.
Encrypted for this machine only
Because the key stays in this computer's credential store, a connections.json copied to another machine opens without passwords. Use the encrypted export in Moving connections and queries to move connections.
Deleting local data
Settings → Local data → Delete all local data (two clicks to confirm) removes saved connections and their passwords, AI connections and API keys, scheduled tasks, imported SSH keys, the stored license key, interface settings and history, and the encryption key in the credential store. Your own files — query folders, exports, backups — are not touched.
Uninstalling keeps your data unless you tick Delete the application data in the Windows uninstaller; a silent uninstall (for example winget uninstall) keeps it too. The privacy policy lists every location and how to remove it by hand.
What is not stored there
- Saved query files — when a connection has a Queries folder, the
.sqlfiles live in the folder you chose. - Exports, dumps and backups — wherever you saved them.
- Window layout and open tabs — session state is not persisted; NabuSQL opens with a clean workspace.
Resetting
Delete all local data (above) returns NabuSQL to a fresh install. You lose your connections, license activation and scheduled tasks — export what you need first, and keep your license key, which you can re-enter afterwards.
