Legal

Privacy Policy

Last updated August 2026.

1. Who this policy covers, and who to contact

This Privacy Policy explains how HirioDB ("we", "us") collects, uses, and protects personal data when you visit this site, create an account, or use the Service. For any privacy question or to exercise the rights described below, contact us at payments@hirio.ro.

2. What we collect

To create and run your account, we store your name, email address, and a hashed password — never a plain-text password. When you subscribe to a plan, our payment processor (Stripe) collects and stores your payment details directly; we never see or store your full card number. The desktop app stores your account credentials locally, encrypted using your operating system's own keychain (Windows DPAPI, macOS Keychain, or libsecret on Linux) — never as plain text on disk. We also keep a limited operational audit log (account and billing events, timestamps, and the IP address associated with certain security-sensitive actions) to detect abuse and support you if something goes wrong.

3. Legal basis for processing

We process your account and billing data because it's necessary to perform our contract with you (running your account, provisioning your databases, billing your subscription). We process limited security and abuse-prevention data (such as an IP address tied to a free-trial claim or a suspicious login) on the basis of our legitimate interest in keeping the Service secure and fairly available to everyone. Where we're required to retain billing records for tax or accounting purposes, we do so to comply with that legal obligation.

4. What we don't collect

This site doesn't use advertising cookies, tracking pixels, or third-party analytics. We're not in the business of profiling visitors. The only cookie the site sets is a strictly necessary session cookie used to keep you signed in, which doesn't require separate consent under applicable e-privacy rules because the Service cannot function without it.

5. Who we share data with

We share the minimum necessary data with the processors that make the Service work: Stripe (payment processing and billing), Resend (transactional email delivery), and our hosting and database infrastructure providers. These providers may process data outside Romania or the European Economic Area; where that's the case, transfers rely on the safeguards recognized under applicable data protection law (such as the European Commission's Standard Contractual Clauses). We don't sell or rent your personal data to anyone, for any reason.

6. Your database contents

Documents you store in your own HirioDB databases are yours. We don't inspect, scan, or use their contents for any purpose other than operating the Service (for example, backups or investigating abuse you report) — access is limited to what's strictly necessary. If you store personal data belonging to third parties in your databases, you act as the data controller for that data and are responsible for having a lawful basis to process it; we act only as your processor for that content.

7. How long we keep data

We keep account data for as long as your account is active, and for a reasonable period afterward to handle disputes, comply with legal or tax obligations, and prevent abuse (typically no longer than necessary for those purposes). If you delete your account, we delete or anonymize personal data that we're not otherwise required to retain.

8. Your rights

Under applicable data protection law, you have the right to access the personal data we hold about you, request its correction or deletion, restrict or object to certain processing, and receive a copy of it in a portable format. You also have the right to lodge a complaint with your national data protection supervisory authority — in Romania, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — though we'd appreciate the chance to resolve any concern directly first at payments@hirio.ro. Deleting your account also removes the workspaces and databases only you had access to.

9. Security

We take reasonable technical and organizational measures to protect your data, including encrypting database credentials at rest and hashing passwords with a strong, salted algorithm. No system is perfectly secure, and we encourage you to use a strong, unique password and to keep your connection strings confidential.

10. Changes to this policy

If this policy changes in a meaningful way, we'll update the date below and, where appropriate, let existing account holders know by email before the change takes effect.

11. Contact

Questions about this policy, or requests to exercise your rights, can be sent to payments@hirio.ro.