Privacy Policy
Last updated: August 2026
Overview
DBHelm is a desktop application that stores database credentials and kubeconfigs locally on your machine. A free DBHelm account (email) is required to download installers and to manage Free / Pro / Platform subscriptions online. This policy describes what we process on our accounts service versus what stays on your device.
Desktop app (local)
After install, the app is offline-first. Kubeconfigs, connection secrets, local users, and settings are stored in an encrypted SQLite database on your machine (AES-256-GCM). We do not receive your database contents, query results, or kubeconfig files unless you explicitly enable optional features that call third parties you configure (for example a BYO AI provider).
Delete this folder to remove local DBHelm data. Optional opt-in error reporting can be disabled in Settings.
DBHelm account & website
When you use dbhelm.com/account we process:
- · Email address (sign-in via one-time code; new emails create a Free account)
- · Download events (platform, file name, app version) when you download installers while signed in
- · Subscription and license metadata for Pro / Platform (tier, status, expiry, seats, device activations)
Account data is stored in our Cloudflare Workers / D1 accounts service. Magic-code and license emails are sent via Resend from a DBHelm address (for example licenses@dbhelm.com).
Browser session (localStorage)
The marketing account portal stores a short-lived session token in your browser's localStorage so you stay signed in across tabs on dbhelm.com. Clearing site data or using Sign out removes it. This token is only for the website portal — it is not the desktop app login, and it is not sent to your databases.
Payments (Lemon Squeezy)
Paid Pro and Platform checkouts are processed by Lemon Squeezy (merchant of record). Lemon receives billing details you enter at checkout; we receive subscription and customer identifiers needed to issue and renew license keys. Manage cards, invoices, and cancellation in the Lemon customer portal (linked from your DBHelm account when subscribed).
Other network activity
- · Update checks for new desktop versions (Windows/Linux may install in-app; macOS may open the download page until signed builds ship)
- · Connections you configure: Kubernetes APIs, databases, cloud providers, optional Git remotes, optional BYO AI providers
- · The marketing site is mostly static; the account portal calls the accounts API above
What we do not sell
We do not sell personal data. We do not use third-party advertising trackers on the marketing site.
Contact
Privacy questions: hello@dbhelm.com. Security reports: security@dbhelm.com.