Privacy Policy

Last updated: July 6, 2026

This is a plain-language policy for an early-stage service. It is not a substitute for legal advice.

1. Who we are

Unbase (unbase.dev) is a hosted SQL database service operated by Gonçalo Henriques. This policy explains what data we handle when you use the site and the service, and what your rights are.

2. What we collect

  • Email address — only if you claim a project. We use it to send the claim magic link and to associate projects with your account. Anonymous usage requires no personal details at all.
  • IP addresses — processed transiently for rate-limiting and abuse prevention. They are not attached to your account or projects.
  • Usage metrics — per-project counters (reads, writes, storage size) used to enforce plan limits and keep the service healthy.
  • Your project content — whatever you choose to store in your projects. We host it; it's yours (see the processor section below).

3. What we don't do

  • We don't sell your data. To anyone. Ever.
  • We don't show ads or share data with advertisers.
  • We don't read the content of your projects, except where strictly needed to operate the service, to debug an issue with your consent, or where the law requires it.

4. Sub-processors

We rely on a small set of infrastructure providers to run Unbase:

  • Cloudflare — compute and storage for the database service (Workers and Durable Objects) and nightly backups (R2, with 30-day point-in-time recovery).
  • Vercel — hosting for this website.
  • Resend — sending claim (magic link) emails.
  • Stripe — payment processing, once paid plans are self-serve.

Each processes data only as needed to provide their part of the service. We'll update this list if the set of providers changes.

5. Data retention

  • Anonymous projects are permanently deleted 7 days after creation unless claimed.
  • Claimed projects and your email are kept until you delete the project or ask us to delete your account.
  • Backups age out on a rolling schedule; Cloudflare provides 30-day point-in-time recovery, after which old backup data is gone.

6. Your rights

  • Export — pull a full SQL dump of any project at any time via the export endpoint (GET /export).
  • Deletion — permanently delete any project at any time via the delete endpoint, or by emailing us.
  • GDPR rights — where the GDPR applies, you have the rights of access, rectification, and erasure over the personal data we hold about you (your email and account data). Email privacy@unbase.dev to exercise them.

7. Data processing (DPA-lite)

For the content you store in your projects, you are the data controller and Unbase is the data processor. In that role we:

  • process your content only to provide the service — never for our own purposes;
  • apply appropriate technical measures: encrypted transport, isolated per-tenant databases, and hashed access tokens;
  • notify you of any personal data breach without undue delay;
  • delete your content when you terminate (subject to backups aging out as described above).

If you need a formal, signed Data Processing Agreement, email privacy@unbase.dev.

8. International transfers

Unbase runs on Cloudflare's global network, so data may be processed outside your country. Where transfers of personal data out of the EU/EEA occur, they are covered by standard contractual clauses or equivalent safeguards provided by our sub-processors. Regional data pinning is planned as a future paid feature but is not available today — we do not currently guarantee data residency in any specific region.

9. Contact

Privacy questions and rights requests: privacy@unbase.dev. Abuse reports: abuse@unbase.dev. See also our Terms of Service.