Semantic Rails website and Cloud privacy notice
Version 2026-09-12.
Who handles your information
Semantic Rails, Inc. operates the Semantic Rails website and Cloud Service. Contact will.tremml@semantic-rails.com with a privacy, security or information-rights request.
We act as a GDPR processor for personal data we process on a customer's behalf through its Cloud projects, warehouse connections and instructed operations. The customer acts as controller, or as a processor authorized by its controller. Our DPA governs that processing. Contact the workspace's owner about its business use of your data; we help route and fulfill appropriate requests.
We act as controller for information we use to administer our own user accounts, contracts, billing, security, support and optional product measurements. This notice explains those purposes. It is not a consent request for all processing, and accepting subscription terms does not subscribe you to marketing.
What we receive and why
| Information and source | Purpose |
|---|---|
| Email and account details from you; verified email, identity-provider subject and optional display name from Google or another enabled identity provider | Verify sign-in, recover access and distinguish accounts |
| Workspace invitations, roles and membership state from you or administrators | Provide access to the right workspaces and administer invitations |
| Project definitions, connection information, credentials, query instructions and returned data from customers and their warehouses | Perform customer-instructed configuration, validation and warehouse/API/MCP operations |
| Request IDs, operation/status/timing, workspace and user IDs, usage units and audit records generated by the Service | Operate, secure and troubleshoot Cloud and administer usage |
| Billing contacts and subscription, invoice and payment references from you and Stripe when enabled | Charge and reconcile the accepted subscription, administer taxes and resolve billing issues |
| Messages and attachments you send to support | Respond and investigate your request |
| Limited optional product events described below | Understand adoption and feature performance |
Google sign-in uses identity information rather than access to your Gmail messages, Drive documents or calendar. Our business email service separately sends sign-in and service messages. Payment entry takes place on Stripe-hosted pages; Cloud receives billing metadata and references rather than operating its own card-entry form.
Warehouse queries and results pass through Cloud to the requesting browser or MCP client. Project objects, configured warehouse files and operational records can be stored. Enabled acceleration features can also retain query instructions, rendered SQL, plans and performance metadata to provide that feature. Product analytics described below is a separate, more limited data flow. We do not promise that all customer data stays exclusively in the warehouse.
Purposes and legal bases
Where GDPR applies to our controller activities, we rely on contract when processing is necessary for our contract with the individual; on legitimate interests in administering business-customer accounts, securing and improving the Service and responding to support when those interests are not overridden by individuals' rights; and on legal obligations for applicable tax, accounting and legal requirements. For a business user's account, the employer's contract does not automatically make that individual a contracting party.
We use consent for optional browser analytics wherever it is required and for marketing where required. Withdrawing consent does not affect processing already lawfully performed. Essential identity, access, security and billing information may be necessary to provide the requested feature. Customer Personal Data under the DPA is processed on documented customer instructions, not under a blanket claim that our own legitimate interests authorize use of warehouse content.
Browser storage and analytics
Authentication and security use necessary browser/session mechanisms. Optional browser analytics remains off unless enabled with the choices required for the visitor. You may refuse or withdraw optional analytics consent where that choice is offered without losing access to the core Service. If the necessary consent controls are unavailable, optional browser analytics is not collected.
When enabled, PostHog receives selected page and successful feature events. A random identifier is held in the tab's session storage; signed-in Cloud events can use internal user and workspace IDs. These IDs are pseudonymous, not fully anonymous. The website and Cloud do not join anonymous identifiers across their separate origins. The integration does not use session replay or automatically record everything you click or type.
The product-event policy excludes query text, SQL, query results, project contents, emails, names, credentials and raw page URLs. The recipient necessarily receives network transport information including the connecting IP; our analytics configuration discards client IP data from stored product events. This does not mean the recipient never processes transport metadata.
We may separately keep limited, server-authored account-verification, workspace- creation and invitation-acceptance records for service measurement. They contain opaque IDs and allowlisted facts, not warehouse content, and may be exported to PostHog when configured. They are distinct from contractual billing and security records. Browser analytics and internal measurement do not authorize training on customer warehouse content.
Recipients and international processing
Cloud uses infrastructure operated by Semantic Rails. We use Cloudflare for relevant website and network delivery, Google for enabled identity and business email, Stripe for billing when enabled, and PostHog for optional analytics when enabled. Providers receive information appropriate to their function under applicable agreements. The DPA describes customer-data subprocessors and the process for changes.
Workspace administrators can see information available to their role and manage membership. When you connect a warehouse, repository, MCP client or AI assistant, the recipients you select may receive the information needed for that integration. In particular, a chosen AI client/model provider can receive authorized tool results. Its independent retention and model-training practices are governed by your arrangement with it, not a promise we can make on its behalf.
We do not sell personal information or disclose it for cross-context behavioral advertising. We do not use Customer Data to train general-purpose AI models. We may disclose information where legally required, to address fraud/security issues, or in a lawful business transaction subject to applicable safeguards.
Information may be processed in the United States and other countries where our approved providers and authorized support operate. No particular residency commitment applies unless we expressly agree to it. We do not undertake a restricted international transfer of Customer Personal Data until an applicable lawful mechanism and required safeguards are in place. Contact us for the locations applicable to your subscription and a copy or description of relevant transfer safeguards, with confidential information protected where necessary.
Retention and security
| Record | Retention policy |
|---|---|
| Active account, membership and project information | While needed to provide the requested account/workspace; following verified deletion, active Customer Data is removed within 30 days, or within 60 days after termination absent an earlier instruction |
| Connection credentials | While needed for the authorized connection, then removed under the applicable deletion instruction and data-exit schedule; revoking access at the warehouse remains available independently |
| Recoverable backup copies of deleted data | Restricted to recovery and expired within 90 days of active-system deletion |
| Optional browser analytics and internal product milestones | Up to 13 months from the event, then deleted or converted to aggregates that no longer identify a person |
| Routine operational logs | Up to 90 days unless selected evidence is needed for a documented security incident or legal matter |
| Security audit and access evidence | Up to one year in active audit storage and up to seven years total in restricted archives where needed for security accountability or legal claims |
| Billing, tax and contract/acceptance records | Up to seven years after the relevant financial year or contract end, as appropriate for accounting and legal claims |
| Support correspondence | Up to two years after the request closes, unless necessary for an ongoing issue or legal matter |
We retain information longer only where law requires it or a specific documented claim, investigation or legal hold justifies it, limit access and use to that purpose, and remove it when the exception ends. Access revocation or archiving alone is not deletion. After restoring a backup, completed deletion requests are reapplied before the affected data is returned to ordinary service. We do not use legal-retention exceptions to retain usable warehouse credentials indefinitely.
We use workspace authorization, restricted access, encryption of stored warehouse credential payloads and encrypted backups. An authorized running service must be able to use credentials for instructed operations; these measures do not eliminate all risk from compromised hosts or accounts. Semantic Rails has no SOC 2 attestation and does not promise absolute security or an uptime SLA. Security requests can be sent to the contact at the top of this notice.
Your rights and choices
Depending on applicable law, you may request access, correction, deletion, portability, restriction or objection, withdraw consent, and complain to the relevant supervisory authority. For controller processing under GDPR, we respond without undue delay and ordinarily within one month; lawful extensions and exceptions will be explained. We verify identity proportionately and do not require unrelated sensitive information. If another customer controls the data, we route the request and assist that customer under the DPA.
We do not discriminate for exercising a privacy right. Where applicable law provides an appeal or authorized-agent process, contact us to use it and we will explain the applicable steps. Marketing opt-outs are honored separately from necessary service communications. The Service is directed to adult business and professional users, not children; contact us if a child has provided information so we can investigate and remove it where appropriate.
We date updated notices and give additional notice where a material change or law requires it. A notice change does not retroactively permit an incompatible new use of previously collected personal information.