Last updated September 10, 2026.
The controller for data processing described here (Art. 4(7) GDPR) is Joshua Knauber, c/o POSTFLEX PFX-992-066, Emsdettener Straße 10, 48268 Greven, Germany. Reach us at contact@valv.sh. We are not required to appoint a data protection officer.
valv is a desktop app that runs on your own machine. The data inside the databases you connect to it, your queries, and your chats stay on your machine and never reach us, so we are not involved in processing them. This policy covers the limited personal data we do handle: this website, buying and managing a license, support, and analytics.
We do not run user accounts. When you buy a commercial license, our payments partner Polar collects your billing details (see below) and passes us your subscription status and the email address tied to the license, so we can deliver and manage it (Art. 6(1)(b) GDPR). We also hold any messages you send us for support. We keep this for as long as your license is active or as needed to answer you, except where the law requires longer retention of billing records (§ 147 AO: up to ten years).
This website (valv.sh) runs on Cloudflare Pages, so requests are handled by the data center nearest to you, which can be outside the EU. When you visit, technical data (IP address, time, requested URL, referrer, browser) is processed to deliver the pages and kept in short-lived logs for security and abuse prevention. Legal basis: our legitimate interest in operating the site securely (Art. 6(1)(f) GDPR).
valv connects directly to your databases from your own machine and stores connection credentials in your operating system's keychain. Queries run locally. valv's AI features use the coding agent you already run (Claude Code, Codex, Cursor, opencode, or Grok): your prompts, schema, and results go to whatever provider that agent uses, under that provider's own terms, and never pass through us. We do not receive your database contents, queries, or chats.
valv has no sign-in. Paid licenses are billed through Polar (US) as merchant of record: Polar handles your payment details under its own privacy policy, and we receive your subscription status and the email address tied to your license, not your card data (Art. 6(1)(b), tax records Art. 6(1)(c) GDPR).
We keep site and product analytics separate. Both are processed in the EU with PostHog and never sold.
Site analytics on valv.sh sets a cookie only if you accept it (Art. 6(1)(a) GDPR, § 25(1) TDDDG), and only then do we record your session (the pages you view and how you interact with them) to see how the site is used. If you decline, we keep only a cookieless, aggregate count of visits based on our legitimate interest in knowing our reach (Art. 6(1)(f) GDPR): no cookie, no recording, and no way to identify you. Product analytics in the valv app is anonymous and runs on the basis of our legitimate interest to improve the product (Art. 6(1)(f) GDPR). You can turn it off at any time in the app's settings.
If you email us, we process your address and message to answer you (Art. 6(1)(b) or (f) GDPR) and keep the exchange as long as needed to handle the request.
We use a few providers to run the website and licensing, each bound by a data processing agreement where they act on our behalf. We do not sell your data. The subprocessors we rely on:
The region above is where each provider stores and processes your data. Where a provider processes data outside the EU, or is a company subject to non-EU jurisdiction, those transfers rely on an EU adequacy decision such as the EU-US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses (Art. 46 GDPR) otherwise or as a fallback. You can request a copy of these safeguards. We give notice before adding or replacing a subprocessor.
valv stores your connections, credentials, and history on your own machine; remove them in the app or uninstall valv to delete them. The data we hold is your license record and any support emails: contact us to have these deleted, unless a statutory retention period (for example § 147 AO for billing records) requires us to keep them, in which case they are blocked and deleted once that period ends. Server logs and analytics follow the shorter periods described above.
You can ask us at any time for access to your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and a portable copy of data you gave us (Art. 20). Where processing is based on consent, you can withdraw it at any time with effect for the future (Art. 7(3)).
You also have the right to object (Art. 21 GDPR): where we process your data based on legitimate interest, you can object for reasons arising from your particular situation, and to direct marketing you can object at any time.
To exercise any of these rights, email contact@valv.sh. You can also complain to a data protection supervisory authority, in particular in the EU member state where you live or work; the authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (datenschutz-berlin.de).
We protect the data we hold with technical and organizational measures appropriate to the risk (Art. 32 GDPR), including encryption in transit and access controls. On your own machine, valv stores database connection credentials in your operating system's keychain.
We update this policy when our practices or the law change and will note the date above. Questions about this policy: contact@valv.sh.