Nabukodonozor d.o.o.
Palinovečka 19c, 10000 Zagreb, Republic of Croatia
OIB (tax ID): 10903838103
E-mail: gdpr@nabukodonozor.hr
This Privacy Policy describes how we process the personal data of visitors to nabusql.nabu.work and buyers of the NabuSQL software, in accordance with Regulation (EU) 2016/679 (GDPR) and the Croatian GDPR Implementation Act.
When you purchase a license we collect: first and last name, e-mail address and device identifier (Machine ID); for business buyers additionally the company name, registered address, city, postal code, country and tax/VAT number (required for issuing a business invoice). We also record your IP address to prevent abuse (rate limiting).
| Purpose | Legal basis (GDPR) |
|---|---|
| Issuing and delivering the license key, performance of the purchase contract | Art. 6(1)(b) — performance of a contract |
| Issuing and retaining invoices, fiscalisation, tax obligations | Art. 6(1)(c) — legal obligation |
| Preventing abuse and ensuring system security | Art. 6(1)(f) — legitimate interest |
| Responding to inquiries and complaints | Art. 6(1)(b) / (c) / (f), depending on the nature of the inquiry |
Card payments are processed by Stripe (Stripe Payments Europe, Ltd., Ireland). Card data (number, expiry date, CVC) is entered directly into Stripe's system and we never see or store it. Stripe's privacy policy: stripe.com/privacy.
The trial version is downloaded without registration and without entering any personal data. As is standard, the server keeps technical logs (IP address, time, downloaded file) for security and operational statistics (legitimate interest).
If you contact us by e-mail, we process your e-mail address and the content of your message in order to respond to your inquiry.
When the Website loads, your browser fetches fonts from Google Fonts (Google Ireland Ltd.) and the payment script from Stripe servers; your IP address is technically transmitted to those providers in the process.
Stripe and Google may carry out part of their processing outside the EEA (USA). Such transfers are based on appropriate safeguards: the EU–U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
You have the right of access to your data, rectification, erasure (within the limits of statutory retention obligations), restriction of processing, data portability, and the right to object to processing based on legitimate interest. You can submit a request to gdpr@nabukodonozor.hr; we will respond without undue delay and at the latest within one month.
If you believe we process your data unlawfully, you have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr, or with the supervisory authority of your EU member state.
Strictly necessary cookies (always on): a session cookie (PHP session) that remembers your language choice and enables the purchase form to work, and a cookie that stores your cookie-consent choice (nabusql_consent). No consent is required for these. Stripe may set its own cookies necessary for secure payment processing when you use the payment form.
Analytics cookies (with consent): we use Google Analytics 4 (Google Ireland Ltd.) for visit statistics and to improve the site. Analytics is disabled until you give consent via the cookie banner (Google Consent Mode — analytics_storage defaults to "denied"). Only after your consent are analytics cookies set (e.g. _ga, _ga_*) and usage data collected; your IP address is anonymised. You can withdraw consent at any time via the "Cookie settings" link in the page footer.
The legal basis for analytics cookies is your consent (Art. 6(1)(a) GDPR, together with the Croatian Electronic Communications Act). More about Google Analytics: policies.google.com/privacy.
The NabuSQL application runs locally on your computer. Your databases, connection credentials and queries are not transmitted to our servers. The license is verified offline, without sending any data.
If you enable the AI assistant in the application, the text of your prompts (and any schema/context you choose to include) is sent to the AI provider you select (e.g. OpenAI, Anthropic, Google) using your own API key, which is stored locally on your computer (see 8.1). Such processing is subject to the selected provider's terms; the AI features send nothing without your action.
NabuSQL stores its configuration only in your user profile. The application data folder is:
%APPDATA%\com.nabusql.app (application files) and %LOCALAPPDATA%\com.nabusql.app (user-interface storage of the embedded WebView2 browser);~/Library/Application Support/com.nabusql.app, plus ~/Library/WebKit/com.nabusql.app and ~/Library/Caches/com.nabusql.app;~/.local/share/com.nabusql.app.| Data | Where | Protection |
|---|---|---|
| Database passwords, SSH passwords and SSH key passphrases | connections.json | Encrypted (AES-256-GCM) |
| AI provider API keys | ai_connections.json | Encrypted (AES-256-GCM) |
| Encryption master key | Operating-system credential store: Windows Credential Manager (entry NabuSQL/master-key), macOS Keychain, Linux Secret Service (GNOME Keyring / KWallet) | Protected by the operating system and your user account |
| Other connection settings (host, port, user name, database, SSH host, path to the SSH private key) | connections.json | Not encrypted (not secret) |
| SSH private keys | NabuSQL stores only the path to your key file and never copies it. Exception: keys contained in a connection export that you import are written to the ssh_keys subfolder. | As the key file itself (its own passphrase, if any) |
| License key, license e-mail and trial start date | license.json | Digitally signed (Ed25519), not encrypted |
| Scheduled tasks | scheduled_tasks.json | Contain no passwords |
| Settings, query history, saved-query index, window/grid state | WebView storage (%LOCALAPPDATA%\com.nabusql.app on Windows) | Contain no passwords or API keys |
| Knowledge Lab models and patches (optional add-on) | knowledge and plugins subfolders | Contain no credentials |
Passwords and API keys are decrypted only in the application's memory when a connection or AI request needs them. Encrypted values can be decrypted only on the same computer by the same user account, because the master key never leaves the operating-system credential store. If the credential store is not available (for example on a Linux system without a Secret Service), the master key is stored in the file secret.key in the application data folder, readable only by your user account. Connection export files (.enc) are protected separately with a password you choose (PBKDF2-SHA256 and AES-256-GCM).
Earlier versions: versions up to and including 1.0.105 stored passwords and SSH passphrases in connections.json and AI API keys in WebView storage without encryption, protected only by the file permissions of your user profile. Starting with version 1.0.106 these values are encrypted automatically the first time the application starts after the update; no action is required on your part. Remnants of the previously unencrypted values may temporarily remain in the internal files of the WebView storage (until its automatic cleanup) and in any backups of your user profile. The application no longer reads them. If you want them removed completely, delete the local data as described in 8.3, or change the affected passwords and API keys.
Uninstalling removes the program files. Your data is kept by default, so that a reinstallation or update keeps your connections:
%APPDATA%\com.nabusql.app and %LOCALAPPDATA%\com.nabusql.app) and the master key in Windows Credential Manager are deleted. If you do not select it, everything listed in 8.1 remains on your computer.winget uninstall Nabukodonozor.NabuSQL): the data is not deleted. Use one of the methods in 8.3.The license data held on our servers in connection with a purchase is described in sections 2 and 5 and is not affected by uninstalling.
NabuSQL/master-key (or run cmdkey /delete:NabuSQL/master-key); on macOS remove the NabuSQL item in Keychain Access; on Linux remove the NabuSQL entry in Passwords and Keys (Seahorse) or KWallet.Files you created yourself outside the application data folder (SQL files in the query folders you chose, backups, exports, connection export files, your SSH key files) are never deleted by NabuSQL and remain under your control.
We apply appropriate technical and organisational measures: encrypted communication (HTTPS/TLS), restricted database access, no storage of card data, and server-side-only storage of access keys.
We may update this Privacy Policy from time to time. The current version is always published on this page with the date of the last update.