Privacy Policy

What PrimDB collects, why, where it is stored, how long we keep it, and the GDPR rights you have — including self-serve erasure of your account and all associated data.

Last updated: July 20, 2026

This Privacy Policy explains how MONAFY LTD ("PrimDB", "we", "us") collects and processes personal data when you use the platform. We aim to collect little and keep it briefly. Data is hosted in the EU (Hetzner, Germany).

Honest note. This policy covers the personal data of PrimDB account holders. Data your deployed apps collect from their own end-users is yours to control — you are the controller for that data and PrimDB acts as your processor.

1. What we collect

  • Account data — your email and authentication identifiers (used for sign-in and magic links).
  • Your Content — the code and apps you deploy and their environment variables. Env vars and secrets are stored encrypted and revealed only to the owner, and access is audited.
  • Usage and build metadata — deployment, build, and project activity used to operate the service.
  • Billing information — handled via Stripe; PrimDB does not store your full card number.
  • Request logs and IP — basic request logs and IP addresses, kept for security, abuse prevention, and rate limiting.

We process personal data on the basis of contract (to provide the service you signed up for) and legitimate interest (to secure the platform, prevent abuse, and rate-limit). Where we ever rely on consent, you can withdraw it at any time.

3. Where it is stored

PrimDB is hosted in the EU on Hetzner infrastructure in Germany. Sub-processors such as Stripe (payments) may process limited data to perform their function; we use reputable providers and limit what they receive.

4. How long we keep it (retention)

A daily automated cleanup job enforces concrete retention windows so data does not linger:

  • Expired sign-in and magic-link tokens are purged within about 7 days.
  • Resolved feedback comments are purged after about 90 days.
  • Audit logs are retained for about 365 days.
  • Backups are rotated on a rolling schedule and age out automatically.

5. Your rights (GDPR)

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate account data.
  • Erasure — you can delete your account and all associated data self-serve from the dashboard. This triggers a full teardown of your apps, databases, and account data.
  • Portability — export your audit log; your code and data remain yours and can be taken with you.
  • Objection — object to processing based on legitimate interest.

To exercise a right, use the in-dashboard controls or email privacy@primdb.com. You also have the right to lodge a complaint with your local data protection authority.

6. Security

Environment variables and connection strings are encrypted at rest and revealed only to the owner, with access recorded in an audit log. The platform enforces per-tenant isolation across databases, caches, and storage. No system is perfectly secure, so you should keep your own backups and protect your account credentials and API tokens.

7. Cookies

PrimDB uses strictly necessary cookies to keep you signed in and to secure the service. We do not use advertising trackers on the platform.

8. Changes to this policy

We may update this Privacy Policy. For material changes we will give reasonable notice before they take effect.

9. Contact

Privacy questions or requests: privacy@primdb.com. See also the Terms of Service and the Acceptable Use / Abuse Policy.