Last updated July 17, 2026.
The controller for data processing described here (Art. 4(7) GDPR) is Joshua Knauber, c/o POSTFLEX PFX-992-066, Emsdettener Straße 10, 48268 Greven, Germany. Reach us at [email protected]. We are not required to appoint a data protection officer.
For your account, this website, billing, support, and analytics, we are the controller and this policy applies. For personal data inside the databases you connect to valv, your organization is the controller and we process that data only on its instructions as a processor under Art. 28 GDPR. Contact us for a data processing agreement.
Your account (name, email, GitHub identity), your workspaces and their settings, the database connections you add, chat threads, and what the assistant learns about your data. Connection credentials are encrypted with a key that is unique to each workspace. We need this data to provide the service (Art. 6(1)(b) GDPR); without it, you cannot use valv. It is kept as long as your account exists, except where the law requires longer retention of billing records (§ 147 AO: up to ten years).
The site and service run on Cloudflare's global network, so requests are handled by the data center nearest to you, which can be outside the EU. When you visit, technical data (IP address, time, requested URL, referrer, browser) is processed to deliver the pages and kept in short-lived logs for security and abuse prevention. Legal basis: our legitimate interest in operating the service securely (Art. 6(1)(f) GDPR).
Queries against your connected databases run when you (or the assistant, on your behalf) ask them to. To generate answers, chat content (your messages, relevant schema, and query results) is sent through OpenRouter (US) to the model provider serving your request, as necessary to provide the assistant (Art. 6(1)(b) GDPR). It is not used for anything else, and never to train models. The assistant makes no automated decisions about you with legal or similarly significant effect (Art. 22 GDPR).
You sign in through GitHub, which shares your public profile and email with us to create and secure your account (Art. 6(1)(b) GDPR). Paid plans are billed through Polar (US) as merchant of record: Polar handles your payment details under its own privacy policy, and we receive your subscription status, not your card data (Art. 6(1)(b), tax records Art. 6(1)(c) GDPR).
We keep marketing and product analytics separate, and you control each one independently on this device. Both are processed in the EU with PostHog and never sold.
Site analytics on valv.sh sets a cookie only if you accept it (Art. 6(1)(a) GDPR, § 25(1) TDDDG), and only then do we record your session (the pages you view and how you interact with them) to see how the site is used. If you decline, we keep only a cookieless, aggregate count of visits based on our legitimate interest in knowing our reach (Art. 6(1)(f) GDPR): no cookie, no recording, and no way to identify you. Product analytics in the app runs on the basis of our legitimate interest to improve the product (Art. 6(1)(f) GDPR), and you can opt out at any time. Turning one off does not affect the other, and you can change either choice here whenever you like. Withdrawing consent does not affect processing that happened before.
If you email us, we process your address and message to answer you (Art. 6(1)(b) or (f) GDPR) and keep the exchange as long as needed to handle the request.
We use infrastructure and model providers to run the service, each bound by a data processing agreement where they act on our behalf. We do not sell your data. The subprocessors we rely on:
The region above is where each provider stores and processes your data. Where a provider processes data outside the EU, or is a company subject to non-EU jurisdiction, those transfers rely on an EU adequacy decision such as the EU-US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses (Art. 46 GDPR) otherwise or as a fallback. You can request a copy of these safeguards. We give notice before adding or replacing a subprocessor.
Deleting a connection, thread, or workspace deletes the data scoped to it. Contact us to delete your account entirely; we then erase your data unless a statutory retention period (for example § 147 AO for billing records) requires us to keep it, in which case it is blocked and deleted once that period ends. Server logs and analytics follow the shorter periods described above.
You can ask us at any time for access to your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and a portable copy of data you gave us (Art. 20). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7(3)).
You also have the right to object (Art. 21 GDPR): where we process your data based on legitimate interest, you can object for reasons arising from your particular situation, and to direct marketing you can object at any time.
To exercise any of these rights, email [email protected]. You can also complain to a data protection supervisory authority, in particular in the EU member state where you live or work; the authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (datenschutz-berlin.de).
We protect your data with technical and organizational measures appropriate to the risk (Art. 32 GDPR), including encryption in transit, encrypted connection credentials with per-workspace keys, and access controls.
We update this policy when our practices or the law change and will note the date above. Questions about this policy: [email protected].