Privacy Policy
Effective date: March 30, 2026 · Last updated: September 3, 2026
1. Introduction
PackDB ("we", "us", or "our") operates the PackDB platform, including our website, dashboard, APIs, and related services (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
2. Information We Collect
Account information
When you create an account we collect your name, email address, and optionally your company name. If you sign in via a third-party provider (such as Google, Apple, or GitHub) we receive the profile information that provider shares, which typically includes your name, email address, and profile picture.
Contact form messages
When you write to us through the contact form — to request a demo or an AI Reliability Evaluation, to join the waitlist, to reach support, or to talk to sales — we store the name, email address, subject, and message you enter, which page or button you came from, the date you submitted it, and delivery status and attempt timestamps so failed forwarding can be recovered. We do not store your IP address, browser, or any tracking identifier with the message. Cloudflare processes the IP address and security-verification token momentarily to protect and rate-limit the form. Mailtrap accepts the email notification for delivery to our inbox; neither the IP address nor the token is written to our records.
We use what you send for one purpose: to answer you and to follow up on what you asked about. We do not sell it, share it with third parties for their own marketing, or add it to unrelated mailing lists. Ask us to delete your message at any time by emailing privacy@packdb.io, and we will remove it.
Billing information
Payment processing is handled by Stripe. We do not store your full credit card number. Stripe may share with us a card token, last four digits, and expiration date to display billing status.
Customer telemetry data
When you use the Service, you send us telemetry payloads — including metrics, logs, and traces — for ingestion, storage, querying, and correlation. We process these payloads solely to provide and operate the Service on your behalf. We do not use the contents of your telemetry payloads for advertising, profiling, or any purpose unrelated to delivering the Service.
We also record aggregate usage metrics such as bytes ingested and query counts to enforce plan limits and display usage dashboards.
AI features and your telemetry
Some features use AI models to help you investigate — for example summarizing an incident, proposing a query, or drafting investigation notes from evidence you selected. When you use one of these features, the telemetry needed to answer that request is sent to the model along with your prompt. That can include log lines, span attributes, metric labels, and service names from your workspace, so treat AI features the same way you treat any other read of your telemetry.
Three commitments apply to every AI feature we ship:
- Your data is not training data. We do not use your telemetry, prompts, or AI outputs to train or fine-tune models, and we contractually require the same of the model providers we use.
- It stays inside your workspace.An AI feature reads only the workspace you are working in, under your own permissions. It cannot read another customer's data, and its output is not shared with other customers.
- You choose when it runs. AI features act on a request you make. We do not run them across your telemetry in the background, and we do not enable them for a workspace that has not opted in.
AI processing may involve a third-party model provider acting as our sub-processor under a written agreement, with no right to use your data for its own purposes. We keep prompts and outputs only as long as needed to deliver the feature and to investigate abuse, and AI output is retained under the same retention window as the workspace it belongs to. These features are assistive and can be wrong — see the Terms of Service. Some are still in development; if we change how they process your data, we will update this section before that change takes effect.
Tenant and organization identifiers
Each API request includes tenant and organization identifiers (such as those transmitted in request headers) that we use to route, isolate, and attribute telemetry data to your workspace. These identifiers are logged as operational metadata for request routing, access control, debugging, and audit purposes.
Device and log data
When you visit our website or use the dashboard we automatically collect standard server log information such as your IP address, browser type, operating system, referring URL, pages visited, and timestamps. We use this data for security, debugging, and aggregate analytics.
Cookies and similar technologies
We use strictly necessary cookies for authentication and session management. We do not use third-party advertising or tracking cookies. If we introduce analytics cookies in the future we will update this policy and provide an opt-out mechanism.
3. How We Use Your Information
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Process payments and enforce plan entitlements
- Send transactional communications (account confirmations, billing receipts, security alerts)
- Reply to messages you send us through the contact form or by email
- Deliver AI-assisted investigation features you invoke, as described in section 2
- Monitor for abuse, fraud, and security threats
- Comply with legal obligations
We do not sell your personal information. We do not use your data for targeted advertising. We do not use your telemetry, prompts, or AI outputs to train models.
4. Third-Party Authentication Providers
You may choose to sign in with Google, Apple, or GitHub. When you do so, the provider shares limited profile information with us as described in section 2. We do not receive or store your password for these providers. The privacy practices of those providers are governed by their own policies, and you can revoke PackDB's access at any time through the respective provider's account settings.
5. Data Sharing and Disclosure
We may share your information with:
- Service providers who help us operate the platform (e.g., Stripe for payments, Supabase for authentication and database hosting, Cloudflare for content delivery and form protection, and Mailtrap for transactional email and contact-form notifications)
- AI model providers that process a request you make through an AI feature, strictly as our sub-processors and with no right to use your data for their own purposes or for training
- Legal authorities when required by applicable law, regulation, or valid legal process
- Business transfers in connection with a merger, acquisition, or sale of assets, in which case your data would remain subject to this policy
6. Data Retention
We retain your account information for as long as your account is active. If you delete your account we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as resolving disputes. Aggregate, de-identified usage statistics may be retained indefinitely.
7. Data Security
We implement industry-standard technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. No system is 100% secure and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on your jurisdiction you may have the right to access, correct, delete, or export your personal data. You may also object to or restrict certain processing activities. To exercise any of these rights, contact us at the address below.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, use our contact form or write to us at privacy@packdb.io.