01 · IntroductionIntroduction
This Privacy Policy explains how MongoQUI ("MongoQUI", "we", "our", "us") processes Personal Data in connection with the MongoQUI desktop application, the MongoQUI web application at app.mongoqui.com, the license and billing portal at license.mongoqui.com, the shared report viewer, the documentation portal, the marketing website at mongoqui.com, and any related services (together, the "Services").
MongoQUI is a MongoDB workspace. The MongoQUI desktop app runs your queries on your own machine. Database content reaches our servers only when you use the web app, create a report or data source, or use AI features; Section 3.4 explains each case. The Services consist of a native desktop application (a Tauri shell that embeds a local Python sidecar for all MongoDB I/O), a web application whose queries run on our hosted backend, and a cloud control plane that manages identity, billing, collaboration, and shareable reports.
This policy applies to Personal Data we process as a Controller (for example, your account details, billing records, website analytics, and support correspondence). Where we process Personal Data on behalf of a paying Customer (for example, when an organisation administrator invites team members or stores shared connection metadata) we act as a Processor under that Customer's instructions, and the Customer's privacy notice governs that data in addition to this policy.
The legal entity publishing this policy is Fahid Digital Ventures LLC, a limited liability company registered with the Sharjah Media City Free Zone Authority, Sharjah, United Arab Emirates, trading as MongoQUI.
02 · DefinitionsDefinitions
The following terms have the meanings assigned below when capitalised in this policy.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under the EU General Data Protection Regulation 2016/679 ("GDPR"), the United Kingdom General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL").
- "Usage Data" means data about how you interact with the Services: website usage (pages viewed, download clicks) on
mongoqui.com, collected with Google Analytics, and the standard request data our servers log (such as IP address, user-agent, and request path). The desktop and web apps do not send usage analytics or crash reports to us. - "Cookies" means small text files stored on your device by your browser; see our Cookie Policy for the full list and controls.
- "Data Subject" means the natural person to whom Personal Data relates.
- "Controller" means the entity that determines the purposes and means of processing Personal Data.
- "Processor" means the entity that processes Personal Data on behalf of a Controller.
- "Services" has the meaning given in Section 1.
- "Customer" means an organisation or individual that enters into a paid or trial subscription to the Services.
- "Authorised User" means an employee, contractor, or agent of a Customer authorised to access the Services on the Customer's behalf.
- "Sub-processor" means a third party engaged by MongoQUI to process Personal Data on our behalf.
03 · Data we collectData we collect
We have grouped the Personal Data we process by source.
3.1 Data you provide directly
When you create an account, make a purchase, contact support, or fill in a form on our websites, we collect information you choose to give us, including:
- Account data: when you register, your name, email address, account type, and organisation name.
- Contact-form data: when you use the contact form on our website, your name, email address, company, role, and (if you give it) phone number.
- Authentication data: hashed password (salted PBKDF2-SHA256; we do not store your plaintext password) and, if you enable two-factor authentication, the TOTP secret and backup codes are stored in our authentication database, which our cloud provider encrypts at rest.
- Billing data: your Stripe subscription ID, plan, amounts, payment status, and invoice links. We do not store payment card numbers. Card details, and the billing country and postal code Stripe needs, are collected by our payment processor Stripe, Inc.; we receive billing status and invoice details from Stripe.
- Support correspondence: the content of messages you send to
support@mongoqui.com, including any attachments or screenshots, and the metadata of those messages (subject, timestamps, message IDs). - Connection settings: in the desktop app, the connection form defaults to "Cloud Storage", which sends the full connection settings, including the database username and password, to our control plane, where they are stored encrypted with AES-256-GCM. If you choose "Local Storage", the connection settings stay encrypted on your device only and are not sent to us.
- User-generated content you choose to cloud-sync: saved query names, report definitions, and shared team connections (connection name, host, port, database name, and credentials; never stored in plaintext; credentials are encrypted at rest with AES-256-GCM in our authentication service and are never shown to other team members).
3.2 Data we collect automatically
When you use the Services, we (and our Sub-processors) automatically collect:
- Device and connection data: IP address, approximate location derived from IP (country or region only, never precise geolocation), user-agent string, browser and operating-system version, screen resolution, device type, and language preference.
- Website usage: pages viewed and download clicks on
mongoqui.com, collected with Google Analytics. Our website also loads a Google Ads tag, through Google Tag Manager, that sends page views and download clicks to Google Ads to measure ad conversions. The desktop and web apps do not send usage analytics or crash reports to us; our servers log standard request data. - Audit-log entries: records of account and organisation actions (registration, two-factor changes, team, role, seat and shared-connection changes, sign-in method links, and device registration and release).
- Cookies and similar technologies: see the Cookie Policy for names, purposes, and retention.
3.3 Data we collect through integrations
Where you enable an optional integration or cloud feature, we process data flowing through that integration:
- Stripe (billing): billing status, subscription state, and invoice events. Stripe collects your card details and the billing country and postal code it needs at checkout. Stripe's own privacy notice applies to its processing of payment-card data.
- Google and GitHub sign-in (optional): if you choose to sign in with Google or GitHub, we receive the profile fields that provider releases to us (typically name, email, subject identifier, and avatar URL).
- Email service (transactional email): the email address of the recipient, message content, delivery status, bounce and spam-complaint events. We send mail from
noreply@cz.mongoqui.com. - Cloud platform (CDN, WAF, edge compute): standard edge-network metadata including IP address, request path, response code, and rate-limit counters. Acts as our Sub-processor across its CDN, database, object storage, serverless functions, and AI inference products.
- Serverless analytics with in-memory SQL engine (reports): when a report is executed or re-run, the Parquet dataset the report operates on is processed in a serverless function. The function has access only to the specific Parquet object identified by the report and returns aggregated results; it does not retain source data beyond the request lifetime.
- AI providers (optional): when you use the AI query assistant, the natural-language prompt you type and a redacted schema context are sent to an AI provider listed in the sub-processor table below for completion. The schema context can include field statistics (for example minimum and maximum values) and includes sample documents only if you turn that option on; fields that look sensitive are masked in samples. When AI report suggestions are generated, column names, data types and up to ten sample rows of the report's data are processed by AI inference hosted by our cloud platform provider.
- Desktop auto-update: the desktop app periodically checks our release manifest at downloads.mongoqui.com for a newer version. That request carries your IP address, user-agent and installed version; it is served from our own infrastructure and is not shared with a third-party release host.
- Other desktop app downloads: the desktop app loads its code editor (Monaco) from the jsDelivr CDN and fonts from Google Fonts, and downloads the MongoDB Shell (
mongosh) from MongoDB, Inc. atdownloads.mongodb.com. These requests carry your IP address and user-agent to those providers. By its own default,mongoshmay send anonymous usage data to MongoDB, Inc.; MongoDB's privacy notice applies to that data.
3.4 Data we explicitly do NOT collect
We want to be unambiguous about what leaves your machine:
- The contents of your MongoDB documents. When you run queries in the desktop app, document payloads, field values, and query results stay inside the local Python sidecar bundled with the desktop app and are not transmitted to MongoQUI servers, except in the cases listed below.
- The results of your queries. In the desktop app, aggregation outputs, find results, and
$explainplans are rendered locally. - Your MongoDB connection credentials in plaintext. For connections saved with "Local Storage", credentials are encrypted at rest on your device and the app is locked behind an Argon2id-hashed master password. For connections saved with "Cloud Storage" (the default in the connection form) and for shared team connections, credentials are sent to our control plane, stored encrypted with AES-256-GCM, and never shown to other team members in plaintext.
- Precise geolocation. We derive only country- or region-level geography from IP.
- Special category data. The Services are not intended for the processing of special categories of Personal Data under GDPR Article 9.
Database content does reach MongoQUI servers in these four cases:
- Web app. When you use the web app at
app.mongoqui.com, your queries run on our hosted backend, and web shell commands run in a serverless function on Amazon Web Services. - Reports and data sources. When you create a report or data source, the query results are uploaded as Parquet files to our cloud storage by default.
- AI query assistant. When you use it, your prompt and a schema summary with field statistics (which can include minimum and maximum values) are sent to OpenAI. Masked sample documents are included only if you turn that option on.
- AI report suggestions. Up to ten sample rows of the report's data are processed by our cloud platform provider's AI inference.
04 · How we use dataHow we use data
We use Personal Data for the following purposes.
4.1 To provide and operate the Services
- Authenticate you and your devices, maintain your session, and keep you signed in.
- Sync your saved queries, report definitions, and team resources across devices where you have chosen to enable cloud sync.
- Route requests across our cloud control plane (
mqui-gateway,mqui-auth,mqui-mongocor,mqui-ai,mqui-email,mqui-file-reports,mqui-py-backend,mqui-report-suggestions). - Deliver the Report Builder, including re-run, shareable links with expiry, and password-protected shares.
- Deliver the shared-report viewer at the chosen URL.
4.2 To administer accounts and billing
- Process trial activation, seat assignments, subscription upgrades, downgrades, renewals, and cancellations.
- Generate invoices and receipts via Stripe.
- Send service-critical transactional email (email verification, billing confirmations, password resets, team invitations, report shares) via email service.
4.3 To provide support
- Respond to your questions, troubleshoot reported issues, and reproduce bugs using the information you voluntarily share.
- Escalate bugs internally using redacted error reports and logs.
4.4 To monitor security and prevent abuse
- Apply rate limiting and a Cloudflare Turnstile bot check on sign-in and registration.
- Operate our Web Application Firewall and per-endpoint rate limits.
- Investigate audit-log events.
- Enforce our Acceptable Use policy under the Terms of Service.
4.5 To measure and improve the Services
- Measure aggregate website traffic and download clicks on
mongoqui.comwith Google Analytics, and measure download conversions from our Google Ads with the Google Ads tag. - Use standard server request logs to monitor error rates and fix problems. The desktop and web apps do not send usage analytics or crash reports to us.
4.6 To communicate with you (only with your consent where required)
- Send you product updates, release notes, and company announcements only if you sign up to receive them.
- Run occasional user research (for example, interviews, surveys, or beta programme invitations) on an opt-in basis.
4.7 To comply with legal obligations
- Retain tax-relevant billing records for the period required by applicable tax law.
- Respond to lawful requests from competent authorities where we are legally required to do so.
- Defend ourselves in legal proceedings.
05 · Legal bases for processingLegal bases for processing
For Data Subjects within the European Economic Area, the United Kingdom, and other jurisdictions that require a specific lawful basis, we rely on the following bases under GDPR Article 6 (and equivalent provisions of UK GDPR and UAE PDPL):
- Performance of a contract (Art. 6(1)(b)): processing that is necessary to deliver the Services you have signed up for: account creation, authentication, sync, report delivery, billing, support.
- Legitimate interests (Art. 6(1)(f)): operating security monitoring, preventing abuse, maintaining product analytics in aggregate form, improving and securing the Services, and enforcing our Terms. Where we rely on this basis, we have conducted a balancing test and offer you an opt-out where reasonably possible.
- Consent (Art. 6(1)(a)): non-essential cookies (performance, functional), marketing email, voluntary participation in research and beta programmes. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)): retention of tax, accounting, and anti-money-laundering records; responding to lawful authority requests.
- Vital interests (Art. 6(1)(d)): not routinely relied on; reserved for genuine emergencies.
- Public interest / official authority (Art. 6(1)(e)): not relied on.
For Data Subjects in the United Kingdom, we rely on the equivalent bases under the UK GDPR and the Data Protection Act 2018. For Data Subjects in the United Arab Emirates, we rely on the equivalent bases under the UAE PDPL. For Data Subjects in California, we do not sell or share Personal Data within the meaning of the CCPA/CPRA; see Section 9 for your specific rights.
06 · Sharing and sub-processorsSharing and sub-processors
We do not sell Personal Data. We share it only with the parties below, each engaged under a written contract containing appropriate confidentiality and data-protection obligations.
6.1 Sub-processor table
| Sub-processor | Purpose | Region(s) | Transfer mechanism |
|---|---|---|---|
| Cloud platform provider | CDN, WAF, edge compute, database, object storage, rate-limit store, serverless functions, AI inference | Global edge with primary metadata residency as configured in our account | Standard Contractual Clauses (SCCs) and/or UK International Data Transfer Addendum ("IDTA"), as applicable |
| Analytics platform provider | Serverless analytics for report execution against Parquet objects stored in object storage (accessed via S3-compatible API) | AP-South (Mumbai) and US regions (counsel to confirm final selection) | SCCs / IDTA |
| Email service provider | Transactional email delivery (sign-in, verification, receipts, notifications) from noreply@cz.mongoqui.com | Global | SCCs / IDTA |
| Stripe, Inc. and Stripe Payments Europe, Ltd. | Payment processing, subscription billing, invoice generation, tax handling | Ireland and United States | SCCs / IDTA |
| OpenAI, L.L.C. | Optional AI query assistance | United States | SCCs |
| Google LLC | Optional Sign in with Google; website analytics (Google Analytics via Google Tag Manager) | United States | SCCs |
| GitHub, Inc. | Optional sign-in with GitHub (OAuth identity handshake only, and only if you choose it) | United States | SCCs |
An up-to-date list of Sub-processors is maintained and will be made available at security.mongoqui.com/subprocessors once that portal is live. Customers with a signed Data Processing Addendum will receive notice of material changes to this list in accordance with the notice mechanism set out in the DPA.
6.2 Other disclosures
Beyond the Sub-processors listed above, we may disclose Personal Data:
- To professional advisers (lawyers, auditors, accountants, insurers) under obligations of confidentiality.
- In connection with a corporate transaction: a merger, acquisition, or sale of assets. In such a case we will notify affected Data Subjects and, where required, provide a mechanism to object.
- To competent authorities, only where compelled by a valid legal instrument and after reviewing the instrument for scope and lawfulness. Where we are permitted to do so, we will notify the affected Data Subject before disclosing.
- To protect rights and safety: to investigate suspected fraud or abuse, to enforce our Terms, or to protect the rights, property, or safety of MongoQUI, our users, or the public.
security.mongoqui.com is operational before launch.07 · International data transfersInternational data transfers
Because our Sub-processors operate globally, your Personal Data may be transferred to, stored in, and processed in countries other than your own, including the United States, the United Kingdom, the European Union, India, and the United Arab Emirates.
Where Personal Data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on one or more of the following safeguards:
- European Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers originating in the EEA.
- UK International Data Transfer Addendum or the UK International Data Transfer Agreement for transfers originating in the United Kingdom.
- Supplementary measures including TLS encryption in transit, encryption at rest, access controls, short retention windows, and documented transfer-impact assessments where appropriate.
For Personal Data subject to the UAE PDPL, cross-border transfers are made either to jurisdictions recognised by the UAE Data Office as providing an adequate level of protection or under appropriate safeguards as permitted by the PDPL.
We do not rely on the EU–US Privacy Shield framework. The Privacy Shield was invalidated by the Court of Justice of the European Union in the Schrems II decision (Case C-311/18, 16 July 2020).
You may request a copy of the relevant transfer mechanism or its summary by writing to privacy@mongoqui.com.
08 · Data retentionData retention
We retain Personal Data only as long as necessary for the purposes set out in this policy, or as required by applicable law.
| Category | Retention (default) | Rationale |
|---|---|---|
| Active account Personal Data (name, email, role, organisation membership) | Retained for the life of the account | Necessary to operate the account |
| Account Personal Data after subscription cancellation | Up to 24 months post cancellation, unless you request earlier deletion | Supports reactivation, invoice access, and dispute resolution |
| Billing and tax records (invoices, subscription events, tax identifiers) | 7 years after the end of the tax year to which the record relates | Tax, accounting, and anti-fraud obligations |
| Security-event and sign-in logs | 90 days | Security investigation window |
| Application and error logs | 90 days | Debugging and incident response |
| Encrypted database backups | 30 days (rolling) | Disaster recovery |
| Support-ticket correspondence | 36 months from case closure | Service continuity and pattern analysis |
| Marketing-consent records | For the duration of the consent plus a reasonable proof-of-consent window | Demonstrating lawful basis |
| Aggregated / de-identified analytics | Indefinite, as the data no longer constitutes Personal Data | Product improvement |
When a retention period ends, Personal Data is either deleted or irreversibly anonymised. Backups are encrypted, access-controlled, and overwritten on the 30-day rolling cycle.
You may request deletion at any time; see Section 9. Where law requires us to retain a record (for example, a tax record), we will isolate that record from general processing until the statutory retention window expires, and then delete it.
09 · Your rightsYour rights
Depending on where you live and the applicable law, you have some or all of the rights below. We will not discriminate against you for exercising these rights.
9.1 Rights under GDPR and UK GDPR
- Right of access (Art. 15): obtain confirmation that we process your Personal Data and a copy of that data.
- Right to rectification (Art. 16): correct inaccurate or incomplete data.
- Right to erasure (Art. 17): ask us to delete your data where one of the statutory grounds applies.
- Right to restriction (Art. 18): ask us to limit processing in defined circumstances.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another Controller where technically feasible.
- Right to object (Art. 21): object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent (Art. 7(3)): at any time, without affecting prior lawful processing.
- Right not to be subject to solely automated decisions (Art. 22): we do not engage in solely automated decision-making that produces legal or similarly significant effects on you.
- Right to lodge a complaint with a supervisory authority: you have the right to complain to the supervisory authority in your country of residence, your place of work, or the place of the alleged infringement. A directory of EU authorities is available from the European Data Protection Board. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO).
9.2 Rights under UAE PDPL
Data Subjects in the United Arab Emirates have the rights set out in the UAE PDPL, including the right to access, rectify, erase, restrict, object, and file a complaint with the UAE Data Office.
9.3 Rights under CCPA/CPRA (California residents)
- Right to know what Personal Information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to delete Personal Information we have collected, subject to statutory exceptions.
- Right to correct inaccurate Personal Information.
- Right to opt out of sale or sharing of Personal Information. We do not sell or share Personal Information for cross-context behavioural advertising.
- Right to limit use of sensitive Personal Information . We do not collect sensitive Personal Information for inferring characteristics.
- Right to non-discrimination for exercising your rights.
9.4 How to exercise your rights
Write to privacy@mongoqui.com from the email address on your MongoQUI account, or submit a request via the in-app "Privacy" panel once it is generally available. We will respond within the statutory timeframe applicable to your jurisdiction (one month under GDPR and UK GDPR, extendable by two further months where permitted; forty-five days under CCPA/CPRA, extendable by a further forty-five days; as applicable under UAE PDPL).
To protect your account, we may need to verify your identity before actioning a request. Where a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee or refuse to act, and we will explain our reasoning to you in writing.
10 · SecuritySecurity
We operate a defence-in-depth programme. Implemented controls include:
- Argon2id-hashed master password locking the desktop app; locally stored credentials are encrypted at rest on the device.
- Signed JWTs on every API call, with the active organisation (sent in an
x-organization-idheader) checked against your membership. - TOTP-based two-factor authentication (Pro and Ultimate plans) using
otplibin the authentication service. - Rate limiting and a Cloudflare Turnstile bot check on sign-in and registration.
- Per-endpoint rate limiting using rate limit buckets.
- AES-256-GCM encryption at rest for connection credentials saved with Cloud Storage and for shared team connections; credentials travel only over TLS.
- TLS encryption in transit across our edge and analytics layer.
- Internal service authentication using a shared secret header between our cloud services.
- Audit log (
/api/v1/audit-logs) capturing account and organisation actions (registration, two-factor changes, team, role, seat and shared-connection changes, sign-in method links). - Password-protected share links for reports, with salted PBKDF2-SHA256 password hashes, expiry timestamps, and instant revoke.
- Elevated-permission gating for sensitive actions (export, delete, re-run).
- CORS allow-listing per origin, per service.
No system is ever perfectly secure. If you believe you have found a vulnerability, please write to security@mongoqui.com. We do not yet operate a paid bug-bounty programme; responsible disclosures are acknowledged.
security.mongoqui.com, whether a formal vulnerability-disclosure policy should be linked, and whether to include a commitment timeline for SOC 2 Type II (which is in progress but not complete; we explicitly do not claim SOC 2 certification).11 · Children's privacyChildren's privacy
The Services are intended for use by professionals. They are not directed at children under the age of 16 (or the applicable minimum age of digital consent in your jurisdiction). We do not knowingly collect Personal Data from children under that age. If we learn that we have collected such data without verified parental consent where required, we will delete it.
If you believe that a child has provided Personal Data to us, please contact privacy@mongoqui.com so that we can take corrective action.
12 · Changes to this policyChanges to this policy
We may update this Privacy Policy from time to time to reflect changes to our Services, applicable law, or Sub-processors. When we make a material change, we will:
- Update the "Last updated" date at the top of this document.
- Post the updated policy at this URL.
- Send email notice to the address associated with your account, for material changes that affect your rights or the categories of data we process.
For non-material changes (for example, typographical corrections or clarifications), we will update the "Last updated" date without separate notice.
Archived versions of this policy are available on request from privacy@mongoqui.com.
13 · ContactContact
Questions, requests, or complaints about this policy may be directed to the contacts below.
13.1 Privacy and Data Protection Officer
- Email:
privacy@mongoqui.com - This address is monitored by our privacy function. Please do not use any
@mongodb.comaddress. MongoQUI is a separate, independent company.
13.2 General
- Product and sales enquiries:
hello@mongoqui.com - Customer support:
support@mongoqui.com - Security disclosures:
security@mongoqui.com - Abuse reports:
abuse@mongoqui.com
13.3 Postal address
- Registered office: Fahid Digital Ventures LLC, Sharjah Media City Free Zone, Sharjah, United Arab Emirates.
13.4 Supervisory authority
- European Economic Area: the supervisory authority of your EU member state of residence, workplace, or the place of the alleged infringement. A directory is maintained by the European Data Protection Board at
https://edpb.europa.eu. - United Kingdom: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF,
https://ico.org.uk. - United Arab Emirates: the UAE Data Office, the federal data-protection authority established under Federal Decree-Law No. 44 of 2021.