Back to home

Privacy Policy

Last updated · June 20, 2026

This Privacy Policy explains what personal data QueryScratch (“we”, “us”, “our”) collects, why we collect it, how we use and share it, and the choices and rights you have. It applies to the QueryScratch website and services. We aim to collect only what we need to run a SQL-learning product well.

1Data we collect

We collect the following categories of data:

  • Account data — your email address, username, and password (stored only as a salted hash by our authentication provider).
  • Profile data — optional display name, bio, location, and website that you choose to add.
  • Learning data — questions you attempt, your submitted SQL, progress, streaks, and bookmarks.
  • Technical data — IP address, browser type, device information, and basic usage events needed for security and to keep the Service working.
  • Cookies — see our Cookie Policy for details on essential and optional cookies.

Your SQL queries run locally in your browser via an in-browser SQLite engine; the query text is only sent to our servers when needed to save your progress.

2How we use your data

  • To create and manage your account and authenticate you.
  • To provide the Service — tracking progress, checking answers, and saving bookmarks and profile details.
  • To secure the Service, prevent abuse, and debug problems.
  • To communicate with you about your account and important changes to the Service.
  • To analyze aggregated, non-identifying usage so we can improve the product.

3Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we rely on these legal bases: performance of a contract (to provide the Service you signed up for), legitimate interests (to secure and improve the Service), consent (for optional cookies and any marketing), and legal obligation (where required by law). You can withdraw consent at any time.

4How we share data

We do not sell your personal data. We share it only with:

  • Service providers — our hosting and authentication/database provider (Supabase) and infrastructure vendors who process data on our behalf under appropriate agreements.
  • Legal and safety — when required by law, to enforce our Terms, or to protect the rights and safety of users and the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

5Data retention

We keep your account and learning data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements.

6Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and request a copy.
  • Correct inaccurate or incomplete data (you can edit most of this in your profile).
  • Delete your data or close your account.
  • Object to or restrict certain processing, and withdraw consent.
  • Data portability — receive your data in a portable format.

To exercise these rights, email privacy@sqlab.dev. You also have the right to lodge a complaint with your local data-protection authority.

7Security

We use industry-standard safeguards — encryption in transit, hashed passwords, and row-level access controls — to protect your data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you and the authorities of breaches where required.

8International transfers

Your data may be processed in countries other than your own, including where our service providers operate. Where required, we use appropriate safeguards such as standard contractual clauses to protect your data during these transfers.

9Children’s privacy

The Service is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us data, contact us and we will delete it.

10Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice through the Service.

11Contact

For any privacy question or request, contact our team at privacy@sqlab.dev.

Terms of ServicePrivacy PolicyCookie Policy