locksoupgithub

Privacy

Last updated 1 October 2026

Locksoup is operated by Paarth Jha, who decides how the personal data described here is used. This page says what is collected, where it goes, and what you can do about it.

What we store

  • Account: your email, a password hash, when you signed up, and the promo code if you used a signup link.
  • Projects: the name you gave, the database host, your schedule and alert settings, and the connection details you entered (connection string, and the project URL and anon key if you added them). The connection details are encrypted before they are saved.
  • Audit results: score, findings (the kind of issue, the table or function it is about, a short evidence note), the written report, suggested fix SQL, and fingerprints of your schema used to keep results stable between checks.
  • Plan and usage: your plan and its dates, whether you asked to upgrade, how many checks you ran, and the AI cost of each check.

What we never store

Locksoup does not store or send the rows in your tables. The login you create for it is read-only, and it is used to read how the database is configured, not what is in it.

How we use it

  • To run the checks you ask for or schedule, and to show you the results.
  • To email you about scheduled checks if you turned alerts on, and about your account.
  • To enforce plan limits and prevent abuse.
  • To let you know when Pro opens, if you asked.

We don’t sell your data, and we don’t use it for advertising. The site has no advertising or analytics trackers. Your sign-in session is kept in your browser’s storage.

AI processing

To analyze a project, Locksoup sends its schema metadata to an AI model through OpenRouter, which passes it to the company hosting the model. Schema metadata means the names of tables, columns and functions, your access policies, function bodies and grants. Function bodies are sent as you wrote them, so anything you put inside one is included.

You agree to this each time you connect a project. To stop it, delete the project.

Who else handles it

  • Supabase: sign-in and our database (EU).
  • Render: the server that runs checks (US).
  • Cloudflare: the website.
  • OpenRouter and the model provider it routes to: AI analysis of schema metadata.
  • Resend: sending email.
  • A payments provider, once billing opens.

This means your data can be processed outside your country, including in the EU and the US.

How long we keep it

We keep your data until you delete it. Deleting a project removes it with its saved login and reports. Deleting your account removes everything at once. Copies in our providers’ backups can remain for a short time before they expire.

Security

Connection details are encrypted at rest with a key held outside the database. Locksoup connects with a read-only role and a short query timeout. Each account can read only its own projects and reports. Traffic is encrypted in transit. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.

Your choices and rights

  • See and export: “Download my data” on your profile.
  • Correct: change your password on your profile; contact us to change your email.
  • Delete: “Delete project” or “Delete account” in the app.
  • Withdraw consent to AI processing: delete the project.
  • Complain: contact us first; you can also go to your data protection authority, or the Data Protection Board of India.

These apply under laws such as the GDPR and India’s Digital Personal Data Protection Act, where they cover you.

Children

Locksoup is for adults. We don’t knowingly collect data from anyone under 18.

Changes to this policy

When this policy changes, the date at the top changes. For changes that matter, we will tell you in the app or by email first.

Contact

Questions or requests: hello@locksoup.com.