Datlas Privacy Policy
Datlas is an application that runs on your computer and connects directly to the databases you choose. This policy explains what stays on your machine, what may leave it and what your rights are under Brazil’s General Data Protection Law (Lei Geral de Proteção de Dados, Law 13,709/2018).
This is a translation; in case of divergence, the Portuguese version prevails. Read the original in Portuguese.
- The data in your databases and all query results
- Passwords, stored in Windows Credential Manager
- Projects, queries, dashboards and alerts
- The database structure: names and types of tables and columns
- Small data samples, if the project allows it (on by default)
- Your questions and the context you write
- Sent to the AI provider you choose, using your own key
- The error type and where it occurred in the Datlas code, with none of your data; turn it off in Settings
1. Who we are
Datlas is developed and distributed by the party identified below, which acts as the controller of the personal data processed by Datlas itself.
Controller: Caotec · Privacy contact: [email protected]
2. What stays on your computer
Datlas has no server of its own that receives your data. Everything below is stored locally, in your Windows account:
- Connections: the address, name and username of each data source you add.
- Passwords and API keys: in Windows Credential Manager, never in a text file.
- Projects: queries, conversations, dashboards, alerts and the AI context you write.
- Alert history: only the number measured at each check, never the rows of the result.
- Diagnostic logs: error codes and AI provider response times, without the content of your questions or your data.
Query results are kept in memory while the application is open. They are written to a file only when you export them.
3. Connection to your databases
Queries go directly from your computer to the database, using the credentials and permissions you configured. By default, Datlas opens connections in read-only mode and sends to the database only the SQL that you run or approve.
4. Artificial intelligence
Natural-language questions use an AI provider of your choice (for example DeepSeek, OpenAI, Anthropic or a local model via Ollama), with your own key. Nothing is sent before you configure a provider and authorize its use.
When you ask a question, Datlas sends the provider:
- the structure of the project’s sources: names and types of tables and columns, relationships and database comments;
- your question, the answers you give in the conversation and the project’s AI context;
- small data samples, when the project allows it (on by default; turn it off in AI context): values of a column containing a word, the minimum, maximum and counts of a column, and up to 20 rows of check queries or of the result preview. Always read-only.
With samples turned off, Datlas sends the provider no rows from your databases and no query results. The provider processes the data it receives under its own policy; read the policy of the provider you choose. With a local model (Ollama), nothing leaves your computer.
5. Sharing
Datlas does not sell, rent or share data. The only transmissions are those described in this policy: to your databases, to the AI provider you choose and the anonymous error reports (section 6). The Microsoft Store collects installation and purchase data under Microsoft’s privacy policy.
6. Anonymous error reports
When Datlas fails or closes unexpectedly, it automatically sends an anonymous report so that the failure can be fixed. The service used is Sentry (Functional Software, Inc.), which receives the report on behalf of the controller of Datlas. When the AI cannot prepare a query, the report also says which AI provider and model were used, the kind of source (for example, PostgreSQL), the step that failed and the sequence of the assistant’s steps, without the question, the SQL, table names or data.
- What is sent: the error type, a message without names or values, the files and lines of the Datlas code where it occurred, the Datlas and Windows versions and a random installation identifier.
- What is never sent: SQL, query results, table or column names, values from your data, passwords, connection addresses, the computer name, the Windows username or files.
- Legal basis: legitimate interest in keeping the application working (LGPD, art. 7, IX). You can turn this off at any time in Settings → Privacy → Send anonymous error reports.
- Retention: reports are kept for up to 90 days.
6.1 Download and usage counts
To know how many people download and use Datlas, the datlasdb.com site counts, without identifying anyone: installer downloads, clicks on the Microsoft Store button, page visits (with the site the visitor came from, domain only, such as google.com) and the update checks the app makes when it opens (which only state the Datlas version and the system, Windows or Linux).
- How it is counted: the visitor's IP address is replaced, on the site itself, by a code that cannot be reversed (made with a key only the site has). The server that keeps the counts never receives the address.
- What is never sent: nothing from your databases, queries, projects, user name or computer name. The app sends nothing beyond the update request it already made.
- Retention: the codes are kept for 31 days, to count unique visits per day, week and month; after that only daily totals remain.
- Legal basis: legitimate interest in understanding product use and planning releases (LGPD, art. 7, IX).
6.2 Google Analytics on the site
The datlasdb.com site uses Google Analytics 4 (Google LLC) to measure visits and where they come from, and Google Search Console to understand how the site appears in search. The Datlas app does not use Google Analytics.
- Cookies only with your consent: the site asks first. If you decline, Google only receives cookieless signals without an identifier, for aggregate statistics. Your choice is stored in your browser; to change it, clear the site's data.
- No advertising: ad storage and ad personalization are always off.
- Legal basis: consent (LGPD, art. 7, I) for cookies; legitimate interest for the aggregate signals.
7. Your rights and how to delete everything
Under the LGPD, you may request confirmation of processing, access to, correction of and deletion of your data. Because the data stays on your computer, you can also exercise these rights yourself:
- Delete a source, query, dashboard or alert directly in the application.
- To delete everything: uninstall Datlas and delete the
%APPDATA%\Natural DBfolder. In the Microsoft Store version, uninstalling already removes the application’s data. - Remove saved passwords in Windows Credential Manager.
For questions or requests, write to the privacy contact listed in section 1.
8. Security
Credentials are kept in the operating system’s vault, queries run in isolated processes and connections use encryption (TLS) whenever the database supports it. Even so, we recommend using a database user with the least privilege necessary in Datlas.
9. Children
Datlas is a professional tool and is not intended for anyone under 18 years of age.
10. Changes to this policy
When this policy changes, the effective date at the top will be updated and material changes will be announced in the application.