Skip to content
HuginnDB

Privacy policy

Your data stays
on your machine.

HuginnDB is a desktop app with no backend of its own. There is no account, no sign-in and no server we run that your data could pass through — so this policy is short, and every line of it is something the code keeps true.

Last updatedApplies to HuginnDB, the huginndb-mcp connector and its .mcpb bundle, and this website.

  • Nothing collected

    No usage data, no analytics, no crash reports, no telemetry. There is no opt-out because there is nothing to opt out of.

  • Everything local

    Profiles, preferences, query history and logs are kept on your own disk. None of them is uploaded anywhere.

  • Secrets in the keychain

    Passwords, SSH secrets and API keys go to your operating system’s keychain — never to a log, and never to the profile file.

  • No server in the middle

    The app connects straight from your computer to your database. We could not see your data if we wanted to.

What we collect

Nothing. HuginnDB sends no usage data, no analytics, no crash reports and no telemetry of any kind, and it has no account to tie anything to. We do not receive your data, so we cannot sell, share or lose it.

What stays on your machine

Everything the app writes, and where. The config directory is %APPDATA%\HuginnDB on Windows, ~/.config/HuginnDB on Linux and ~/Library/Application Support/HuginnDB on macOS.

DataWhere it livesNotes
Connection metadata — host, port, database, username, driver, TLS and SSH settingsprofiles.jsonIn the config directory.Never leaves the machine. The password is not in it.
Passwords and SSH secretsOS keychainWindows Credential Manager, macOS Keychain or libsecret on Linux.Never written to disk in plaintext, never logged, and sent only to the server you are connecting to. One exception you control: a MongoDB connection string pasted in raw form is saved as typed, so keep the password in the form field rather than inside the URI.
Preferences, open tabs and the query text in them, window state, JSON Schemas, SSH host fingerprintsprefs.json · tab_state.json · json_schemas.jsonJSON files in the config directory.Local only.
Query history and saved querieslocalStorageThe app window’s own storage, on your disk.Local only. History keeps the last 50 statements by default, with their timing and errors; the MCP connector does not add to it.
Pulse history — server metrics, only for connections you opted into samplingpulse.dbA local SQLite file in the config directory.Local only, pruned on a retention schedule you control.
MCP write audit logmcp-audit.logIn the config directory.One line per write the connector ran: when, which connection, the statement and the rows it affected — so it can contain the values that statement wrote. Reads are not logged. Never credentials. Kept until you delete it.
AI panel conversationsNowhere — memory only.Deliberately never written to disk: a transcript holds schema names and row snippets, so closing the app forgets it.
AI provider API key, if you use a cloud providerai::{origin}The OS keychain, keyed to that endpoint’s host.Never in prefs.json, never shown back in the app’s interface, never logged.

Every connection the app makes

This is the complete list. HuginnDB contacts no other host.

  1. 01

    Your database servers

    Directly, with the credentials you supplied. That is the point of the product.

  2. 02

    GitHub, for updates

    On launch and every four hours the app asks GitHub for a small release file, and downloads a newer version in the background; installing it takes your click. The request carries nothing beyond what any HTTPS request reveals — your IP address, to GitHub.

  3. 03

    Open VSX, when you browse themes

    Opening the Extensions panel in Preferences → Appearance searches the Open VSX registry and loads theme icons from it. You can switch the registry off or point it at another one.

  4. 04

    GitHub, if you file a bug report

    Only when you send one from the app. The report you review can include the app version, OS and CPU architecture. Without a token it opens your browser or mail client instead.

  5. 05

    A shared origin, if you set one up

    A file location you chose — typically a share on your own network — that a team uses to publish connection profiles. A file read, not a web request.

  6. 06

    The AI endpoint you configure, if you switch the panel on

    Exactly one base URL, and no other. Redirects are refused rather than followed. Off by default.

That is all of them. No analytics host, no crash reporter, no font or script CDN — the fonts and the Monaco editor ship inside the app.

How your access is protected

Privacy is also about what someone else could get at. Three things keep credentials and traffic out of reach.

  • The OS keychain, not a file

    Database passwords, SSH passphrases, AI keys and shared-origin passphrases are handed to the keychain the moment you save them and read back only when needed. That is also why an MCP client config holds no credentials at all.

  • Encrypted connections

    Each profile carries its own TLS setting — required or off for PostgreSQL and MySQL, encryption and certificate trust for SQL Server, tls=true in the URI for MongoDB. Note that "required" encrypts the link but does not verify the server’s certificate.

  • SSH tunnels built in

    A database that only listens on localhost is reached through an SSH tunnel on the profile itself, with password or key auth and a host-key policy, so it never has to be exposed to the network.

The MCP connector

huginndb-mcp is a local process that an AI client — Claude Desktop, Claude Code, Cursor and others — starts on your machine over stdio. It is not a remote service and signs in to nothing.

  • It reaches only the connections you explicitly expose in Preferences → MCP. Nothing is exposed by default, and un-exposing one takes effect immediately.
  • Each exposed connection is read-only unless you give it the data or full write policy.
  • Every write it runs is recorded in the local audit log. Reads are not.
  • It reads your profiles and keychain passwords only to open those connections from your own computer, as that connection’s database user — so it can never see more than that user’s grants allow.
  • It speaks stdio and opens no network port. The optional bridge to the running app is off by default and listens only on 127.0.0.1, behind a token.

Query results go to the AI client that asked for them. What that application does with them — including sending them to its model provider — is governed by its own privacy policy, not this one. If a database holds data you are not willing to send to your AI provider, do not expose that connection.

The AI panel

Off until you switch it on, and while it is off the app makes no request to any inference endpoint. Once on, every connection stays unreachable to it until you tick that connection in Preferences → AI.

  • A model on your own machine or network means nothing leaves your infrastructure. A cloud provider with your key means your prompts reach that provider, under their policy.
  • An endpoint you have not declared as your own receives metadata only — table and column names, types, indexes, EXPLAIN output — unless you also allow rows for a specific connection.
  • Anything you type or paste into the chat is sent, whatever those switches say.
  • The assistant cannot write, and each of its reads is listed in the app’s Console with a row count, never the content.

This website

huginndb.vercel.app is a set of static pages. It sets no cookies, runs no analytics and loads nothing from a third-party origin — the fonts are self-hosted.

  • It is served by Vercel, which, like any web host, processes your IP address and request details to deliver the page and keep the service secure.
  • Your browser asks the GitHub API for the latest release number to show in the version chip. With JavaScript off it shows a fallback word and makes no request.
  • Choosing the light or dark theme stores that one word in your browser’s localStorage. It never leaves your browser.
  • Links to GitHub and other sites are governed by those sites’ own policies.
Sharing and retention
We share nothing, because we receive nothing. What the app writes stays on your disk until you delete it, through the app or by removing the files in the config directory.
Children
HuginnDB is a developer tool and is not directed at children.
Changes
Material changes are noted in the app’s CHANGELOG and in the date at the top of this page.

Contact

Questions about privacy, or a security issue you would rather not report in public, go to the address below. Everything else is welcome as a GitHub issue.

The policy of record: docs/PRIVACY.md · SECURITY.md