Privacy Policy

Last updated: July 18, 2026

This Privacy Policy explains what data DataBelta collects, how it is used, and the choices you have. We have tried to keep it in plain language; if anything is unclear, contact us using the details at the end.

1. Who We Are

DataBelta is operated by PrimeLink (Arab Republic of Egypt, Tax Registration No. 773-491-759), which acts as the data controller for the personal data described in this policy.

2. What We Collect

  • Account information: your name, email address, and hashed password, plus two-factor settings if you enable them.
  • Google sign-in: if you choose to sign in with Google, we receive your name, email address and whether Google has verified that address. Nothing else, and we never gain access to your Google account, your contacts or your files. You can sign in with an email address and password instead.
  • Workspace content: your chat messages, including AI answers (which may embed rows of query results you asked for), saved items, and any Excel/CSV files you upload.
  • Database connection details: host, database name, and credentials. Credentials are encrypted with AES-256 before storage and can never be viewed by anyone after saving, including DataBelta staff.
  • Usage data: AI token and credit usage per message, and product analytics events (pages visited, features used).
  • Session replay: a reconstruction of a browsing session (pages viewed, clicks, scrolling) recorded by PostHog, so we can see where the product gets in the way. Inside the app, text typed into fields is masked before the recording is sent, so what you type is never captured.

3. What We Don’t Collect

  • No payment card data. Payments are processed by Paddle as our merchant of record; card details go to Paddle and are never collected or stored by DataBelta. Custom arrangements billed by direct invoice involve no card data at all.
  • We never copy or mirror your database. Queries run live against your source database; DataBelta does not ingest or replicate its contents. Only the chat answers you request (which may include result rows) are stored as chat history.

4. How We Use Data

  • To provide the Service: run your questions, render results, generate exports.
  • To secure accounts: email confirmation, lockouts, optional two-factor authentication.
  • To meter usage against your plan’s AI credit and storage limits.
  • To understand product usage and improve the Service (analytics).
  • To send transactional email such as confirmations, invitations, and security codes.

5. Subprocessors

We use a small number of service providers to operate DataBelta:

  • Moonshot AI (Kimi): the AI model provider. It processes your questions and the data needed to answer them, and returns the answers.
  • PostHog: product analytics and session replay, hosted in the European Union. It receives usage events such as pages visited and features used, along with session replays.
  • Resend: transactional email delivery. It receives your email address and the content of the emails we send you.

6. Data Retention

  • Generated export files (Excel, PDF, Word, PowerPoint) are automatically deleted after 24 hours unless you explicitly save them.
  • Chat history is kept until you delete it.
  • Account deletion has a 7-day grace period, after which all your data, including generated files and uploaded files, is permanently and irreversibly deleted.

7. Security Measures

  • Database credentials encrypted with AES-256; never retrievable after saving.
  • Passwords hashed with industry-standard PBKDF2, never stored in plain text.
  • Optional two-factor authentication (email code or authenticator app).
  • Strictly read-only database access, enforced at every layer.
  • Fully isolated workspaces: every piece of data is scoped to its workspace.

8. Sessions & Local Storage

Signing in stores an authentication token in your browser’s local storage, valid for up to 30 days. We also store your theme preference locally. We do not use third-party advertising cookies.

9. Your Rights

You can request access to, correction of, or deletion of your personal data at any time by contacting us at the details below. Account deletion can also be initiated directly from the product and follows the 7-day grace period described above.

10. Children

DataBelta is a business tool and is not intended for anyone under 18 years of age. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy from time to time. The "Last updated" date above reflects the current version, and material changes will be communicated to you.

12. Contact