RawQL — Privacy Policy
Your files never leave your device.
RawQL is local-first. SQL runs in your browser via DuckDB WASM. Imported files live in your device's RAM and your queries and notebooks live in your browser's localStorage. We have no access to them and nothing is uploaded.
What stays on your device
- Imported files (CSV, JSON, Parquet, Excel) — in-memory only, cleared on refresh.
- SQL worksheets (
rawql-storage) and notebooks (rawql-notebooks) — browser localStorage. - Query results — never persisted.
Consequence: signing in on a new device restores access, not your local workspace. Files and queries must be re-imported there.
What we store server-side
| Data | Storage & retention |
|---|---|
| Name + email (pending signup) | Redis `beta:pending:<email>` — 7 days, deleted on verification |
| Signup / login PIN (6 digits) | Redis `beta:pin:<email>` — 7 days; signup code deleted on use, login code reusable until expiry |
| Verified account (name, email, join date) | Redis `beta:registry:<uuid>` + `beta:email:<email>` — kept until you ask for deletion |
| Access cookie `rawql_beta_access` | HttpOnly, SameSite=Strict — 30 days, identifies your verified account |
Emails & cookies
- Signup and login codes are sent by email (EmailJS) and contain only your name and the 6-digit code.
- The access cookie is HttpOnly and cannot be read by JavaScript.
- No analytics, no advertising, no sale of personal data.
Your rights
Access, correction, or deletion of your account (registry entry + email index): reply to any code email or write to the address shown in that email. Deletion removes server-side data; local browser data is cleared by clearing site data.
Last updated: September 2026.