Privacy policy
Operational text for private beta. Formal review still required before payments or public launch. Last updated: 7 October 2026.
This document sets out what Query & Co. stores, why, for how long, and what you can do about it. It is written from the code, so it describes what the product actually does rather than a general intention.
The most important part first
The SQL you write never leaves your computer. The lesson databases — the supermarket, the football club, the agency — are downloaded into your browser and run there, inside a PostgreSQL compiled to WebAssembly. No query you write reaches our server, not even to be marked: the marking happens in your browser too. We do not store your query text on our servers and cannot read it there.
So you can resume an unfinished query or export it, your browser may keep that draft on this device only. It is not synced to your account or sent to Query & Co. You can delete it from Settings or by clearing this site's browser data.
EasyQL: your own files and public sheets
EasyQL is a sibling tool on this same site. If you choose a CSV or Excel file, its contents, your changes before import, SQL queries and results are processed in your browser's memory. They are not uploaded to Query & Co. or stored in Supabase. Reloading EasyQL clears them. Language, theme and character may be remembered as local browser preferences. The server delivers the app files but does not receive your file content or queries. Do not use files containing other people's personal data unless you are authorised to process them on your device.
You can also paste a Google Sheets link that is already public or shared by link. To work around Google browser restrictions, Query & Co. uses a restricted, temporary relay to fetch its CSV export. The link and CSV pass through that relay only to return the data to your browser: we do not retain either one, do not sign in to Google and do not receive Google credentials. The sheet does not stay in sync: importing it again fetches the version available then.
Operational controller
For this private beta, Query & Co. acts as the operational product controller. The privacy, account and beta contact channel is `pivotdatalabs@gmail.com`. Before payments or a public launch, the formal legal controller details will be completed.
What we store
If you request beta access
- Your email, language, whether you would rather start from scratch or take the placement test, and the screen where you sent the request.
- Your country of residence, if you choose to provide it. We store only its country code, not a precise location. It does not affect access.
- We also store the version of this policy you accepted and when you made the request.
We use this only to organise invitations, understand which countries requests come from and which starting route prospective testers need. Requesting access does not create an account or grant access automatically. We keep the request until we invite you, close it or you ask us to delete it, with an operational maximum of 12 months for requests that do not become accounts.
So you can have an account
- Display name, username and email address. You choose them when you sign up.
- Password, stored as a hash: we do not keep the password itself and cannot read or recover it.
- Sessions: an identifier, when it was created, when it expires, and the browser you signed in from.
We do not store your IP address in the session. The authentication system recorded it by default; the database blanks it at the moment of writing. To limit repeated attempts and slow down abuse, we store separate technical counters. When a limit depends on the request origin, we use an HMAC key that does not allow the original IP address to be read from the database.
So the product works
- Your progress: which lessons you have started and finished, which block you stopped at, and which skills you have proven.
- Your character, your colour and the company you chose, and any items you have unlocked.
- Experience and credits you have earned.
Legal basis: performance of the contract. Without these there is no product to use.
Only if you agree
- Learning analytics: which exercises cause trouble, where a lesson gets abandoned, how many hints get asked for. It exists so we can fix content that does not work.
These events never include the text of your queries, their results, your email, tokens or IP addresses: the code prevents it explicitly, it is not just a promise in this document.
You can accept or refuse in Settings, and change your mind whenever you like. Refusing limits nothing. Legal basis: consent.
Aggregate website traffic
We use Vercel Web Analytics to understand aggregate traffic to the public website: page routes, referring site, browser/device category and approximate location. This helps us see whether people arrive from places such as TikTok or Discord and which pages they reach.
We do not send custom events, your email, your SQL, query results or URL query parameters to this service. It does not join this traffic data to your Query & Co. account or create an advertising profile. It uses no cross-site tracking cookies; Vercel publishes aggregate traffic statistics separately from the optional learning analytics above.
Your privacy decisions
Every decision you make is stored as a new row rather than overwriting the last one: there is a record of what you accepted, against which version of the text, and when. If we change a text in a way that matters, the earlier acceptance stops counting and we ask you again.
If you write to us
If you send feedback from inside the app, we store what you write and the category you pick. Only write there what you want us to read.
Legal basis: consent. Sending feedback is optional and you can ask us to delete it.
Minimum age
The private beta is intended for people aged 18 or older. We do not ask for date of birth or verify age because we do not want to collect more data than necessary. If we find that an account belongs to someone under 18, we may close it and delete its data.
For how long
- Account and progress: while the account exists.
- Beta requests without an account: up to 12 months, unless you ask us to delete them sooner.
- Sessions: they expire after 30 days.
- Analytics: individual events are kept for up to 90 days and then pruned periodically.
- Consent decisions: while the account exists, because they are the record of what you agreed to.
Deleting your account deletes all of the above. There is no copy we can restore afterwards: if you change your mind, you start from scratch.
What you can do
- Download everything. Settings has a button that produces a file with everything we hold about you, table by table and unsummarised. It leaves out your session token: anyone reading the file could sign in with it.
- Delete your account. Also in Settings. It asks for your password and for a typed confirmation, because it cannot be undone.
- Change your mind about analytics, whenever you like.
- Correct your display name and language in Settings.
Who else touches your data
- Supabase, which hosts the database.
- Vercel, where the application runs.
Vercel also processes the aggregate website traffic described above. We strip URL parameters before a page view is sent.
Neither of them receives your SQL queries, because those never leave your browser.
Cookies
Only the ones needed to keep you signed in. There are no advertising or cross-site tracking cookies, which is why you will not see a banner asking permission for them.
Contact
Write to pivotdatalabs@gmail.com from the address you signed up with.