Privacy Policy
Peekeasy is a native macOS application for querying and analyzing your own databases. This policy explains what data Peekeasy handles, what stays on your Mac, and — most importantly — what leaves your device when you use the AI assistant.
The short version
- Peekeasy is local-first. Your database connections run from your Mac, and your database passwords are stored in the macOS Keychain — they are never sent to us.
- No tracking. Peekeasy contains no analytics, advertising, telemetry, or crash-reporting SDKs. We don't sell your data.
- The AI assistant is the one place your data leaves your Mac. When you use it, your chat messages — and, only if you turn on the relevant permissions, your database schema, your SQL, and sample query results — are sent through our hosted backend to the AI provider you choose.
- One provider, DeepSeek, is different. It processes and stores data in China and may use your inputs to train its models. Read AI Providers before selecting it.
1. Who we are
Peekeasy (“Peekeasy”, “we”, “us”) is operated by Peekeasy LLC, a Washington limited liability company, which provides the Peekeasy macOS app and related services. Questions about this policy: [email protected].
2. Data stored on your device (not sent to us)
Peekeasy keeps your work locally on your Mac:
- App database (
~/Library/Application Support/Peekeasy/): your notebooks and queries, chat history, query/run history, and a cached copy of your database schema (table and column names, types, row counts). Connection definitions store the host, database, port, username, and SSL mode — but not the password. - macOS Keychain (device-local): your database connection passwords and any client certificates, plus your Peekeasy account session tokens. These are stored with “this device only” protection and are never synced or transmitted to us.
Your database is queried directly from your Mac, and results are analyzed in a local engine on your machine. Except through the AI assistant (see §4), your database contents do not pass through Peekeasy’s servers.
3. Account & authentication
Features that require an account (the AI assistant and subscriptions) use a Peekeasy-hosted login page. We use Supabase as our authentication provider. We collect and store your email address and a user identifier, along with session tokens (kept in your Keychain). Sign-in options are presented on the login page.
4. The AI assistant — data sent off your device
This is the most important section. When you use the AI assistant, data is sent from your Mac to Peekeasy’s hosted backend and then relayed to the third-party AI model provider you select. Our backend authenticates you, applies rate limits and usage accounting, and relays the request.
What is sent depends on the permissions (“capabilities”) you grant, which you control in the app:
- Always: your chat messages to the assistant, and the AI model you chose.
- If you enable “Read database schema”: a summary of your database (type/version) and schema details — table and column names, types, comments, row counts, and sizes.
- If you enable editor / notebook access: the SQL and text in your query editor and notebook cells.
- If you enable “Run queries” / data access: the assistant can run SQL and receive sample result rows — actual values from your database (currently up to about 50 rows per query, plus computed statistics over the full result set).
If a capability is off, that data is withheld from the request. You can also set per-table rules (block a table, or require your approval before the assistant touches it). We do not use your assistant data for advertising, and we do not sell it.
5. AI providers (third parties who process your data)
When you use the assistant, your request is processed by the AI model provider you choose for that chat. Their handling of your data differs — please choose accordingly:
- Anthropic (Claude) — US-based. Does not train its models on data submitted through its API by default, and retains limited data only briefly for safety and abuse monitoring. See Anthropic’s privacy policy.
- OpenAI (GPT) — US/EU processing. Does not train its models on API data by default. Peekeasy sends OpenAI requests with storage disabled; OpenAI may retain limited data for up to ~30 days for abuse monitoring. See OpenAI’s API data usage policies.
- DeepSeek — operated by a China-based company. Your inputs and outputs are processed and stored in the People’s Republic of China. DeepSeek may use your inputs and outputs to improve and train its models unless you have opted out with DeepSeek, retains data for an open-ended period, and may disclose data to authorities under Chinese law. If you select DeepSeek, any schema, SQL, and sample results included in your request are subject to these terms. See DeepSeek’s privacy policy.
Choosing a provider for sensitive data. You select which provider and model to use for each chat. If your database contains confidential, personal, or regulated data, we recommend Anthropic or OpenAI and caution against DeepSeek, whose default terms allow training on your inputs and storage in China. If you never enable the schema, editor, or data capabilities, only your chat messages are shared with any provider.
6. Payments
If you subscribe, payments are handled by Stripe through Stripe-hosted checkout and billing pages in your browser. Peekeasy does not receive or store your card number or billing address. In the app we store only your plan and usage information (such as plan name, renewal date, and usage percentages).
7. Software updates
The app checks for updates from https://dl.peekeasy.ai/appcast.xml using Sparkle. A
standard check is an HTTPS request that includes your current app version. We have not enabled
Sparkle’s optional system-profiling, so no system profile is sent.
8. Feedback forms
If you send feedback or a bug report from the app’s Help menu, the form opens in your browser and is hosted by Tally. Information you enter (such as your name, email, and message) is processed by Tally and by us so we can respond.
9. Analytics & tracking
Peekeasy contains no third-party analytics, telemetry, advertising, or crash-reporting SDKs. We do not track your use of the app.
10. How we share data
We do not sell your personal data. We share data only with the service providers needed to run Peekeasy: the AI model providers you select (Anthropic, OpenAI, DeepSeek); our hosting, authentication, and infrastructure providers (such as Supabase and Cloudflare); our payment processor (Stripe); and our feedback-form provider (Tally). We may disclose data where required by law.
11. Data retention & deletion
Your local data stays on your Mac until you delete it (in the app, or by removing the app’s data). Account data is retained while your account is active — email [email protected] to delete your account. Data processed by AI providers is retained under their policies (see §5).
12. Your rights
Depending on where you live (for example, the EEA/UK under GDPR, or California under CCPA), you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. Contact [email protected] to exercise these rights.
13. Children
Peekeasy is not directed to children under 13 (or the age of digital consent in your country), and we do not knowingly collect their personal data.
14. International transfers
If you use the assistant, your data may be transferred to and processed in the United States, the European Union, and — if you select DeepSeek — the People’s Republic of China.
15. Changes to this policy
We’ll update this policy as Peekeasy evolves (for example, if cloud sync ships) and revise the “last updated” date. We’ll communicate material changes in-app or on our website.
16. Contact
Privacy questions and requests: [email protected]. General support: [email protected].
Peekeasy is early-stage software; this policy will continue to evolve as features change.