Privacy Policy
Last updated 4 October 2026
What we collect, what the AI model sees, and who else handles it.
1. Who is responsible
BeyondQueries is run by Irevex. Irevex is responsible for the personal data described here. For anything in this policy, write to support@irevex.com.
2. What we collect
Your account. Your name, email address and a hashed form of your password (we never store the password itself).
Your database connection. Host, port, database name, username and password. The password is encrypted before it is stored. We also read and keep the structure of the tables you choose to expose: table names, column names and types.
Your AI provider key, if you connect your own model. It is encrypted before it is stored.
What you do in the product. Your questions, the SQL generated for them, the results returned by your database (up to 1,000 rows per query), the written answers, and the notes, flags and corrections you and your teammates write. This is what makes your query history and corrections work.
How you use the website. Through Google Analytics, which pages are visited and how they are used: the page address with account and workspace identifiers removed, the page you came from, and your browser, device type and approximate location. It is not linked to your account, and it never includes your questions, SQL, results, database details, name or email address. It is off for browsers that send a Global Privacy Control or Do Not Track signal.
Security records. A log of sensitive account actions, which can include the IP address the action came from.
3. What the AI model sees
To answer a question, the model you have configured receives:
- your question;
- the names and types of the tables and columns you have exposed, and your notes about them;
- the rows your query returned, so it can write the answer in plain English. How many it gets depends on the chat mode.
Supervisor mode (the default). If a result has 40 rows or fewer, the model receives all of them. If it has more, the model reads all the rows returned (up to 1,000) and writes a short summary, and the answer is written from that summary.
Classic mode. The model receives only the first five rows of each result.
Tables and columns you switch off are never sent. If you connect your own provider, it receives this data under your agreement with it. If you have not connected one, we use a default model provider on your behalf. Model providers do not receive your database password.
4. How we use it
- to run the service: answer questions, keep history, apply approved corrections;
- to send account emails, such as verification, password reset and invitations;
- to keep the service secure and investigate misuse;
- to see, in aggregate, how the product is used, so we can improve it.
5. What we do not do
- We do not sell your data.
- We do not use the contents of your database to train AI models.
- We do not show advertising, and we do not use advertising cookies. Google Analytics runs with its advertising features off.
6. Services that process data for us
We use these providers to run BeyondQueries. Each processes data only to provide its service to us.
- Vercel — hosts the website.
- Oracle Cloud — runs the application server.
- Neon — hosts our application database.
- Qdrant — stores schema notes and approved corrections for search.
- OpenRouter — turns schema notes and corrections into search vectors.
- Groq — the default AI model provider, when you have not connected your own.
- Resend — sends account emails.
- Google Analytics (Google LLC) — measures anonymous page visits and how the website is used, with advertising features and Google signals off. It sets analytics cookies.
- Polar — sells paid plans as our reseller and merchant of record, and handles payment.
Some of these providers process data outside the country you are in.
7. Cookies and browser storage
We keep your login session and a few interface preferences, such as the workspace you last used, in your browser’s local storage.
Google Analytics sets two first-party analytics cookies, “_ga” and “_ga_<id>”, which hold a random identifier so repeat visits can be counted. They last up to two years. We set no advertising cookies. If your browser sends a Global Privacy Control or Do Not Track signal, Google Analytics is not loaded and these cookies are not set. You can also block or delete them in your browser settings.
8. How long we keep it
We keep your data while your account is open. When you delete a workspace, its connection details and query history are deleted with it. When you ask us to close your account, we delete all of your data, including notes and corrections kept in our search index, within 30 days, except where we must keep a record by law.
9. Your choices and rights
You can ask to see, correct, export or delete your personal data by writing to support@irevex.com. We answer within 30 days. You can also change your name and email in your profile at any time.
10. Security
Database passwords and AI provider keys are encrypted at rest, and traffic between your browser and BeyondQueries uses HTTPS. The connection from BeyondQueries to your database is encrypted when you turn on “Require SSL”, which we recommend. No system is perfectly secure; if a breach affects your data, we will tell you without undue delay.
11. Children
BeyondQueries is not for children, and we do not knowingly collect data from anyone under 18.
12. Changes to this policy
We will update this page when what we collect or who processes it changes, and tell you by email or in the product if a change matters.
Related: Terms of Service · Privacy Policy · Refund Policy