Privacy Policy
Effective date: September 13, 2026
Condit Technologies LLC (“Condit,” “we,” “us”) built this product around a specific promise: your database schema, queries, and results stay on your machine unless you explicitly choose otherwise. This policy explains exactly what that means in practice — what we collect, what we never see, and why.
1. The short version
- Free tier, using your own API key or a local model: your schema, questions, SQL, and query results are never sent to Condit’s servers.
- Optional telemetry (off by default for free tier): three levels you choose yourself — none, aggregate metrics only, or Full I/O — changeable anytime in Settings.
- Advanced diagnostics (paid, off by default, only available on top of Full I/O): also sends internal pipeline steps, including table/column names and — in some cases — actual sample values from your database. Don’t enable this with data you’re not authorized to disclose, or where doing so would violate your organization’s privacy, security, regulatory, or contractual obligations. A separate, explicit opt-in beyond the three levels above, described in §14.
- Condit Hosted (paid): your questions and generated SQL are sent to Condit’s backend, which proxies them to the underlying LLM provider to get a response. We do not store the content of these requests — only aggregate cost and token counts, for billing.
- The website (condit.dev) uses no cookies and no analytics.
- We never sell your personal information.
2. Information we collect
Account information (created only if you sign up for Condit Hosted): email address; either a password (stored as a bcrypt hash, never in plain text) or an OAuth identity from Google, GitHub, or Microsoft (we receive your email and provider account ID, not your password on those services); subscription tier and status.
Billing information. Payment card details are collected and stored by Stripe, our payment processor — Condit never receives or stores your card number. We store your Stripe customer/subscription IDs, subscription status, and aggregate usage totals (cost and token counts per billing period) for the purpose of enforcing your usage allowance and billing overage if you’ve opted into it. We do not store the content of your questions, generated SQL, or results in this billing data.
Optional telemetry — a setting you control (Settings → Privacy), three levels:
- None (default for free-tier accounts): nothing is sent to Condit.
- Metrics only: LLM provider type, model name, database type, success/failure, retry count, response latency, and cost estimate. Never your queries, chat text, schema/table/column names, connection details, or row data.
- Full I/O (default for paid accounts, changeable anytime — including back down to none): everything in Metrics only, plus your question text, the generated SQL, and the answer text. Still never table/column names, connection details, or row data.
Condit Hosted request content. If you use Condit Hosted, your question and generated SQL are transmitted to Condit’s backend and proxied to the underlying LLM provider (currently Anthropic; see §4) to produce a response. This content passes through Condit’s infrastructure but is not written to Condit’s database — only the resulting cost and token counts are recorded, for billing.
Information we never collect, under any tier or setting, except Advanced diagnostics (§14) if you separately turn it on: your database credentials, your database schema (beyond what a full-I/O telemetry choice or a Condit Hosted request necessarily includes in the prompt itself), row-level data returned by your queries, or the API keys you configure for your own LLM providers. These are encrypted at rest on your own machine (see §7) and never transmitted to Condit.
3. Data that never leaves your machine
Regardless of tier: your saved database connection credentials, your own configured LLM API keys, your local chat history (including full question/SQL/result content), and your semantic-layer annotations are stored only in a local, encrypted file on your device. Condit’s servers have no access to this data and no copy of it exists anywhere else, unless you choose full-I/O telemetry (see §2) or separately turn on Advanced diagnostics (see §14).
4. Third parties we work with
We share data with the following service providers, each acting as our data processor for the specific purpose described — we don’t sell your data to any of them or anyone else:
- Stripe — payment processing and subscription billing.
- Resend — transactional email (verification, password reset).
- Google, GitHub, Microsoft — only if you choose to sign in via that provider’s OAuth.
- Anthropic (or another provider we configure) — receives your prompt content only for Condit Hosted requests, to generate the response. Subject to that provider’s own API data-use terms, which (as of this writing) do not use API-submitted data for model training.
- Railway, Supabase — infrastructure hosting for our backend and database.
- Niitaka — Condit operates its own internal observability infrastructure using Niitaka, a product we also built. Telemetry you’ve opted into (§2) is processed there by Condit, for the purposes described in this policy, and is not used for any independent commercial purpose of Niitaka’s own.
5. How we use your information
To provide and maintain the Service; process payments and enforce usage allowances; send transactional emails (verification, password reset, billing receipts); respond to support requests; and, only for telemetry you’ve opted into, improve Condit’s SQL-generation quality.
Telemetry data, at any level you’ve opted into — including Advanced diagnostics (§14) — is reviewed only to diagnose failure patterns and evaluate pipeline or prompt changes, including in aggregate across users. It is never sold, never shared with any party outside Condit, and never used to train a model for any purpose beyond serving Condit users.
6. Data retention
Account data is retained while your account is active. If you delete your account, we retain a minimal record for 30 days as needed for fraud prevention, legal compliance, and dispute resolution, then delete it. Usage records (cost/token aggregates, not request content) are retained for the period needed for billing accuracy and financial recordkeeping. Locally-stored data (§3) remains on your device until you delete it yourself — uninstalling the application does not automatically delete it, so that reinstalling doesn’t lose your saved connections and settings. Condit has no remote copy to separately retain regardless.
7. Security
Locally: database credentials and your own LLM API keys are encrypted at rest using Fernet symmetric encryption. The encryption key is stored in a separate file in the same local settings directory, restricted to your operating-system user account via file permissions — this protects against another local account or casual access, but not against someone with full access to your user account or a complete backup of your home directory. Passwords are hashed with bcrypt, never stored in plain text. Data in transit uses TLS. No security measure is perfect; we can’t guarantee absolute security, but we don’t collect what we don’t need to reduce what there is to protect.
8. Your rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, applicable data protection law may give you rights including access, correction, deletion, restriction of processing, data portability, and objection to certain processing. To exercise these rights, contact issue@condit.dev. We will respond within the time required by applicable law.
Legal bases. We process account and billing information as necessary to provide the Service and perform our contract with you. Where we rely on consent, such as for optional telemetry where applicable, you may withdraw your consent at any time. We may process information for security and fraud prevention where necessary for our legitimate interests or as otherwise permitted by law.
International transfers. Condit Technologies LLC is based in the United States, and personal data may be processed in the United States and other countries by Condit and our service providers. Where required by applicable law, we use appropriate safeguards for international transfers of personal data.
You also have the right to lodge a complaint with the data protection authority in the country where you live, work, or believe a violation has occurred.
9. Your rights (California / CCPA)
California residents have the right to know what personal information we collect and why, to request deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information — we do not sell or share your personal information as those terms are defined under the CCPA, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
To exercise these rights, contact issue@condit.dev. We aim to respond within 45 days. We may need to verify your identity before fulfilling a request.
10. Children's privacy
The Service is not directed at anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we’ll delete it.
11. Breach notification
In the event of a data breach affecting your personal information, we will notify affected users without undue delay, and relevant supervisory authorities where legally required (GDPR, for example, generally requires notifying supervisory authorities within 72 hours of becoming aware of a qualifying breach). We maintain procedures for responding to security incidents and will provide the notices required by applicable law.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced via the app or by email to account holders before they take effect.
13. Contact
Questions about this policy, or to exercise any of the rights above: issue@condit.dev.
See also our Terms of Service.
14. Advanced diagnostics
Read this before turning it on: Advanced Diagnostics can transmit database content — including table and column names and, in some cases, actual sample values from your database — to Condit. Do not enable it if your data includes anything you’re not authorized to disclose to Condit, or if doing so would violate your organization’s privacy, security, regulatory, or contractual obligations.
A separate, explicit opt-in available only to paid accounts already on Full I/O telemetry (§2) — off by default even then, and changeable anytime in Settings. Turning Full I/O back down to Metrics only or Off disables this automatically.
What it includes, beyond Full I/O: the rendered prompts and outputs for key pipeline steps (e.g. how your question was interpreted into a query plan), the inputs and outputs of internal tool calls (schema lookups, SQL execution), and — where the pipeline samples your data to resolve an ambiguous query — the actual sample values involved. This is the one setting under which table/column names and row-level content can reach Condit.
What it’s for: engineering diagnosis of pipeline failures, and evaluating changes (e.g. a different prompt or model for one step) before and during controlled experiments. It is not displayed to any other user, not sold, not shared outside Condit, and not used to train a model for any purpose beyond serving Condit users — the same commitment as §5, repeated here because this is the one tier worth reading closely before turning on.