Legal

Privacy Policy

Effective Date: 2026-09-23

1. Scope and our role

This Privacy Policy explains how Airbrx, Inc. (“Airbrx,” “we,” “us,” or “our”) handles personal information through our website, application, warehouse gateway, scan tools, support, and business relationships.

We are responsible for deciding how we use information to administer accounts, operate our website, communicate with people, manage billing, and protect our services. For these activities, we act as a data controller where that term applies.

Customers decide which warehouse connections, queries, users, and data they route through Airbrx. When we process personal information in that customer data on their behalf, we act as a processor or service provider, as applicable. Customer instructions, deployment settings, applicable agreements, and law govern that processing. A customer may itself be acting for another organization.

This notice does not replace a data processing agreement or other contractual terms required for a particular deployment. Contact us before using the service for processing that requires such terms. If your information is contained in an organization’s warehouse data, that organization’s privacy notice also applies.

2. Information we handle

Account and business information

We handle names, email addresses, profile information, organization details, account and tenant memberships, permissions, authentication records, and information supplied by your administrator or sign-in provider. Depending on your sign-in method, authentication may involve an identity provider, session tokens, or personal access tokens.

We also handle inquiries, support messages, feedback, contracts, billing contacts, invoices, subscription details, and transaction information. Payment providers handle payment credentials when used; Airbrx does not store full payment-card numbers.

Configuration and customer data

The service handles warehouse addresses, connection and storage settings, access permissions, cache rules, invalidation rules, and related configuration.

Depending on the features and deployment you use, customer data can include:

  • SQL statements, query parameters, database and table names, and query identifiers.
  • Usernames, tenant identifiers, token hashes, session information, and other identifiers associated with requests.
  • Query results and response files stored to answer later requests from the cache.
  • Query timing, response size, cache decisions, errors, and summaries of query activity.
  • Credentials needed to authenticate requests, retrieve query results, or monitor running warehouses when that option is enabled.

SQL text, parameters, logs, and cached results may contain personal or confidential information. A hash or normalized SQL statement is not necessarily anonymous.

Credentials

The gateway uses warehouse credentials supplied by the caller to authenticate requests and retrieve their results. The credential is maintained through the active request cycle, including asynchronous completion and result collection when needed. The executor uses that caller-supplied credential for the in-progress operation; it does not require a separate, standing warehouse credential for future queries.

Separately, a configurable warehouse-monitoring option can store a credential to check which warehouses are running. The credential is stored encrypted using a configurable encryption key. When enabled, this option uses the credential while it remains valid. It is separate from the credential used to complete an individual query. A credential’s expiry or revocation limits its use; it does not by itself establish when the saved record is deleted.

Airbrx login credentials and browser-saved scan connections are separate from warehouse credentials used by the gateway. See Section 4 for browser storage and the Security & data handling page for more detail.

Website and operational information

Our services and infrastructure providers receive information such as IP addresses, browser information, request URLs, timestamps, authentication events, and errors. We use operational records to deliver the service, troubleshoot problems, detect abuse, and manage security. Customer-facing query reports also summarize warehouse activity.

The public website does not use advertising pixels or third-party behavioral analytics. This does not mean that requests, account events, or warehouse activity are unrecorded.

3. Where customer data is processed and stored

Storage depends on the configured deployment.

DeploymentHow customer data is handled
Airbrx-hosted storageAirbrx operates the storage used for customer caches, query logs, and related records on the customer’s behalf. This includes hosted Starter deployments.
Customer-controlled storageThe configured caches, query logs, and related records are written to storage in the customer’s cloud account. Airbrx components access that storage using the permissions granted for the service.

Customer-controlled storage does not mean Airbrx never processes the data. Requests and responses pass through the gateway, and Airbrx services may access configured storage to operate the cache, produce reports, or perform other requested functions.

Airbrx separately handles account, authentication, configuration, support, billing, and operational records needed to run the service. Those records are not all confined to the customer’s warehouse or storage account. Confirm the storage arrangement for your deployment with us; a plan name alone does not describe every data flow.

4. Scan tools, cookies, and browser storage

Warehouse scans

In a connected scan, the browser sends connection details and credentials to a relay that communicates with the selected warehouse. Connection checks, warehouse discovery, scan execution, polling, and retrieval can involve multiple requests. The relay handles the returned query-history data before it reaches the browser for analysis.

If you run the supplied scan query yourself and paste or import its results, the scan analysis runs in your browser. Applying generated rules or using another connected feature can separately transmit information needed for that action.

Scan tools can save connection details, credentials, preferences, and scan results in browser storage between visits. Results can include SQL and usernames. Use Disconnect everything within the scan tool, or clear that site’s browser data, to remove its saved connections and results. Clearing browser storage does not revoke a credential at its issuer or delete records already held by a server.

Cookies and similar storage

ItemPurpose and duration
Theme and interface preferencesRemember your display choices and application state. Local storage can persist until cleared; session storage generally lasts for the browser session.
Application authenticationThe dashboard stores an access token in a cookie and a refresh token in local storage. Access tokens are normally valid for one hour, although cookie storage and token validity have different lifetimes. Signing out clears the dashboard’s stored authentication tokens.
Scan-tool authenticationSaved gateway connections can contain personal access tokens or refresh tokens in local storage; exchanged access tokens can be held in memory. Use the scan tool’s disconnect control to remove its saved connections.
Referral attribution: abx_affWith your agreement, records the partner code and arrival time for up to 90 days so a signup can be attributed to that referral.
Referral choice: abx_aff_consentRecords acceptance or refusal for up to 180 days so we can remember your choice. Refusing attribution cookies can still store this choice cookie.
Contact-form protectionLoading the HubSpot contact form can set Cloudflare’s short-lived bot-protection cookie on HubSpot’s domain, typically for about 30 minutes.

If you decline referral attribution cookies, the referral code can still accompany a link from that landing page to the Airbrx application. Refusing persistent attribution does not remove a code already present in a link. Referral information may be associated with a signup for partner credit and should not be assumed anonymous.

You can clear referral cookies using the control below or your browser settings. Removing a cookie stops that cookie from being used on future requests; it does not automatically erase an existing signup-attribution record.

No referral cookie is set, and you have not been asked for one.

Loading externally hosted site assets or the contact form also sends ordinary request information, including your IP address, to the relevant provider. Browser storage is specific to the site or origin involved; clearing one Airbrx application may not clear another.

5. Purposes and legal bases

We use information to provide the functions you request, including warehouse monitoring when enabled; manage accounts and permissions; process billing; respond to inquiries; communicate about the service; administer referrals; improve reliability; prevent abuse; and meet legal obligations.

Where the GDPR applies to processing for which Airbrx is a controller, our bases depend on the activity:

ActivityLegal basis
Providing a service contracted directly with youPerformance of that contract or steps you request before entering it.
Managing an organization’s account and its users; support and business communicationsOur legitimate interests in providing and administering the organization’s service.
Security, fraud prevention, troubleshooting, and service reliabilityOur legitimate interests in protecting and maintaining the service; a legal obligation where one specifically applies.
Billing and financial recordsContract performance where applicable, legitimate interests in administering customer relationships, and applicable accounting or tax obligations.
Optional referral storage and consent-based marketingYour consent where required. Limited referral administration and permitted business marketing may rely on legitimate interests where the law allows.
Responding to lawful requests and establishing or defending legal claimsApplicable legal obligations or legitimate interests in protecting legal rights.

Where we rely on legitimate interests, we must consider the effect on your rights. You may object as described below. Where we rely on consent, you can withdraw it without affecting processing that was lawful before withdrawal. Information required for authentication, service delivery, or billing is necessary to provide those functions; without it, we may be unable to provide them.

For customer data processed on an organization’s behalf, that organization determines its legal basis and gives the relevant processing instructions.

AI assistance and product improvement

If you use the AI rule-recommendation endpoint, Airbrx sends the submitted SQL and associated query metrics and identifiers to Anthropic to generate recommendations. Input validation and SQL normalization do not guarantee removal of personal information, confidential names, or values embedded in SQL.

That feature is separate from the browser-based scan analysis and ordinary gateway caching. Only submit information your organization permits to be processed for that purpose.

This notice does not grant Airbrx permission to use customer query content or results to train general-purpose AI models. Any materially different use of customer content requires an appropriate legal basis and, where applicable, separate customer instructions or agreement. Provider retention and permitted use must be addressed in the arrangements applicable to the AI feature; this notice does not promise zero retention by an AI provider.

For product improvement and reporting, we may use service metrics and information that has been appropriately aggregated or de-identified. We will not treat identifiable SQL, user-linked records, or reversible identifiers as anonymous merely because they have been reformatted or hashed.

6. Who receives information

Information may be disclosed to:

  • Your organization and authorized users: administrators and other users according to their assigned access, including access to account information and customer query reports.
  • Service providers: infrastructure and storage providers such as AWS; authentication providers such as Descope and the sign-in provider you select; HubSpot for contact forms and CRM; communication providers, including Slack where operational notifications are configured; payment providers where used; and Anthropic when the AI rule-recommendation feature is invoked. Providers receive information relevant to their role, not necessarily every category described in this notice.
  • Customer-selected services: the warehouse, cloud storage, and other integrations configured by you or your organization.
  • Referral partners: attribution or credit information needed to administer the referral relationship. We do not provide partners with your warehouse query content for that purpose.
  • Professional advisers and appropriate authorities: where reasonably necessary for legal advice, lawful obligations, fraud prevention, security, or protection of legal rights.
  • Parties to a corporate transaction: subject to appropriate confidentiality protections and applicable law when considering or completing a financing, acquisition, restructuring, or similar transaction.

We do not sell personal information or share it for cross-context behavioral advertising. Service-provider disclosures, customer-directed integrations, and referral administration are described separately above.

7. Retention and deletion

Retention depends on the information’s purpose, the deployment, customer instructions, and applicable legal requirements.

InformationRetention considerations
Account and configuration recordsNeeded to administer an active relationship, then limited to information needed to close the account, settle obligations, address disputes, or maintain required records.
Hosted caches, query logs, and execution recordsGoverned by the configured storage lifecycle and customer-data deletion process. Query-log retention, completion and cleanup of request state, and cache freshness are separate settings and processes.
Optional warehouse-monitoring credentialsStored encrypted using a configurable encryption key when the monitoring option is enabled, and used while valid. Credential lifetime and cleanup of the stored record are separate; contact us for the configuration and removal arrangements for your deployment.
Data in customer-controlled storageGoverned by the customer’s storage lifecycle, versions, backups, and deletion instructions. Removing Airbrx’s access does not itself delete the customer’s stored objects.
Operational, security, and audit recordsRetained for troubleshooting, security investigation, accountability, and applicable recordkeeping needs. Different systems can have different periods, including longer retention for protected audit records.
Billing and transaction recordsRetained for applicable accounting, tax, contractual, and legal requirements.
Inquiries and marketing recordsRetained while needed to respond or maintain the relationship. After an opt-out, a limited suppression record may be kept to respect that choice.
Browser-stored informationRetained as described in Section 4, or until you use the relevant removal controls or clear site data.

A cache’s time-to-live determines when a cached result may be served. Expiry or invalidation does not necessarily delete the stored object. Disabling a tenant, deleting an account record, disconnecting a browser, revoking a credential, and deleting cached data are also different actions.

Contact us for the retention settings and deletion arrangements applicable to your deployment or to request deletion. We assess requests under applicable law and customer instructions. If information must be retained, we will explain the applicable reason where required. Backups, historical versions, and protected audit records must be considered separately; we do not promise that closing an account immediately erases every copy.

8. Security

We use technical and organizational measures intended to protect information, including authentication and authorization controls, tenant-aware access, encrypted public-service connections, and storage and credential protections appropriate to the configured deployment. The Security & data handling page explains relevant design choices and configuration dependencies.

No service or storage system can guarantee absolute security. Contact privacy@airbrx.ai with privacy or security concerns; do not include passwords, access tokens, or unnecessary customer data in your message.

9. International processing

Airbrx is based in the United States. Information may be processed in the United States and in locations used by the providers and deployment you select. Using storage in a particular country does not by itself restrict all gateway processing, support access, account services, or provider processing to that country.

Where a transfer requires a legal transfer mechanism, the applicable arrangement must be established before the covered transfer occurs. Depending on the circumstances, this may require an adequacy decision, Standard Contractual Clauses, or another lawful mechanism, together with any necessary additional safeguards. This privacy notice does not itself establish that mechanism, and using the service is not blanket consent to international transfers.

Contact privacy@airbrx.ai for the processing locations and transfer arrangements applicable to your proposed or existing deployment, including how to obtain a copy of any applicable safeguards.

10. Your choices and rights

Depending on applicable law and our role, you may have rights to know whether we process your information; access or receive a portable copy; correct or delete information; restrict or object to processing; withdraw consent; and complain to a supervisory authority. Where applicable, you may also appeal a refusal of a privacy request.

You can unsubscribe from marketing messages using their unsubscribe control or by contacting us. Service, billing, and security communications may continue where needed to administer your account.

Send privacy requests to privacy@airbrx.ai. Describe your request and the account or service involved. We may verify your identity by matching information already held or asking you to authenticate. We request additional information only where reasonably needed to process the request. Do not send your password or access token.

An authorized agent may submit a request on your behalf. We may request evidence of authorization and verification permitted by law. We will not discriminate or retaliate against you for exercising applicable privacy rights.

We respond within the period required by applicable law and explain any permitted extension. GDPR requests are generally handled within one month; California requests to know, correct, or delete are generally handled within 45 days, subject to applicable extensions and other requirements. Different request types can have different deadlines.

If the request concerns information we process for a customer, we may refer you to that organization and assist it with the request as applicable. If we decline a request, we explain the reason and available review or complaint options where required. To appeal where that right applies, reply to our decision or email us with “Privacy appeal” in the subject line.

California residents

Where the CCPA applies, rights include knowing the categories and specific pieces of personal information collected, sources, purposes, and disclosures; correction; deletion; and protection against retaliation. Rights to opt out of sale or sharing and limit certain uses of sensitive personal information apply in the circumstances specified by law.

The categories relevant to our services include identifiers and contact information; customer and commercial records; internet or network activity; professional information; authentication information; and personal information contained in customer content. Account credentials and some customer content may qualify as sensitive personal information. Their service-related handling is described in Sections 2–6. Requests can be submitted through the contact methods above.

11. Children

Our business services are intended for adults and are not directed to people under 18. We do not knowingly solicit children’s personal information for their own Airbrx accounts. If you believe a child has supplied information directly to us, contact us so we can assess and address it. Information that a customer places in its warehouse remains subject to that customer’s responsibilities and the applicable processing arrangements.

12. Changes and contact

We will update this notice when our practices change. For material changes, we will provide appropriate additional notice, such as an email or an in-product notice, before the change takes effect where required. We will seek consent where legally required. Updating this notice does not by itself authorize incompatible new uses of previously collected information.

Contact

Airbrx, Inc.
3300 NW 185th Ave, #343
Portland, OR 97229, United States
Email: privacy@airbrx.ai

How the mechanics work. For where a query’s data goes, how credentials are used, and which protections depend on your deployment, see Security & data handling. For the shorter, plain-language version of the same story, see Trust & security.