OINO.cloud

Privacy and GDPR compliance

Your data stays in your database

OINO.cloud is a gateway to databases that you own and operate. The data in your databases passes through our services only while a request is being processed; we do not store the contents of your databases. Our account database holds only the configuration needed to run the service for you (databases, APIs, tokens, pages, apps, roles and users) and billing information.

In addition, records in the account database carry necessary technical identities and references (record identifiers and links between records, such as which customer a database or token belongs to), internal random security keys (randomly generated access keys for your APIs and MCP servers, shown to you in the app) and necessary authentication tokens (credentials in a protected form, for example password hashes, authenticator secrets and reset codes, which are never returned through the account APIs). These are required for the service to function and carry no information beyond associating records with your account and authenticating access to it. They are not listed separately in the account data summary below.

The only exception is functionality you invoke explicitly to take copies of your data, such as MCP state snapshots and capture sessions, which store the requested table contents so that they can be compared and exported later. These copies are deleted automatically 30 days after they were taken, or sooner if a shorter retention was set for the capture session or webhook (for example to meet your company's policy).

Personal data you add

Email addresses and names you enter for your users and access roles are personal data of the people concerned. Only add people and information you are entitled to process, within the scope of your own data processing agreement and privacy policy towards them. The same applies to anything you store in pages, templates and prompts.

Database credentials

Database passwords you give us are not stored in the account database. They are kept in a separate secret vault that is protected by multiple defensive layers: network controls restrict which services can reach the vault, role-based access control limits which service identities may read which secrets, and cryptographic controls keep the secrets encrypted at rest and in transit.

Logging

Our operational logs do not record the data in your databases. Logs record request parameters (such as which API, method and record was called) and the outcome of the request. Access tokens and other credentials appearing in request parameters are concealed before they are logged.

Disclaimer: in some situations customer data can end up in the logs, for example when your database returns an error message that quotes the value that caused the error. To limit the impact, operational logs are deleted according to our 30 day data retention policy.

Data we store about your account

Log in to see a list of the information we store about your account.

External services

We use the following external services to run OINO.cloud. Each processes personal data only as needed for the purpose listed; see their own GDPR and privacy declarations for details.

ServicePurposePrivacy / GDPR
Microsoft AzureHosting, account database, secret vault, storage, operational logs and email deliveryMicrosoft Trust Center: GDPR
PolarSubscription billing, payments and invoices (merchant of record)Polar Privacy Policy
WorkOSSingle sign-on (SSO) and OAuth login for apps and MCP servers that use themWorkOS Privacy Policy
Google reCAPTCHABot protection on the signup formGoogle Privacy Policy
MixpanelVisitor analytics on the oino.cloud websiteMixpanel and the GDPR

Questions and requests

For questions about your data or to exercise your rights under the GDPR (access, rectification, erasure), contact us at support@oino.cloud.