Legal
Privacy Policy
What data TableCore processes, why it is needed, where it goes and the choices available to you.
Effective August 17, 2026
This Privacy Policy explains how Mateusz Trojański MagmaCore, ul. Kaliska 36 lok. 33, 56-500 Syców, Poland, NIP 9112047388, REGON 525165795 ("MagmaCore", "TableCore", "we", "us"), handles personal data when you use the TableCore website, account services, desktop licensing, downloads and support. MagmaCore is the controller for the processing described here unless a section says that another provider acts independently. Full contact details are also available in the Legal Notice.
1. Data we process
We process only the categories needed for the relevant feature:
| Context | Data |
|---|---|
| Website and downloads | Request metadata made available by Cloudflare, such as IP address, time, URL, user agent, security signals and download request details. |
| Website analytics | Cloudflare Web Analytics measures page views and page performance. It records the page address, the referring address, approximate country, device type, browser and operating system family, and Core Web Vitals timings. It sets no cookie, writes nothing to your browser storage, assigns you no identifier and does not follow you to other websites. TableCore sees aggregate reports, not a record of an individual visitor. |
| Account and OAuth | E-mail address, provider name, provider user identifier, verification status, account timestamps and authentication events. Provider access tokens are used transiently and are not stored by TableCore. |
| Sessions and desktop authorisation | Random-token hashes, session and authorisation identifiers, creation, use, expiry and revocation timestamps, and security metadata. Browser cookies contain random session material, not a TableCore password. |
| Plans and licensing | Plan, subscription and trial status, entitlement data, relevant period dates and Stripe customer/subscription references. TableCore does not copy full card details into its database. |
| Account settings | Preferences that you choose in the account portal. |
| Support and feedback | Category, subject, message, status, timestamps and any information you choose to include. Do not include database credentials, production records or unnecessary personal data. |
| Crash reports | Only if you send one. A crash is always written to your own computer; nothing is transmitted unless you read the report and press send. What travels is the application version and update channel, the operating system, processor architecture and .NET version, the time of the crash, the exception type, message and stack trace with its inner exceptions, the last 40 lines of the local log, and whether the application had an account signed in — never which account. Connection strings, passwords, SSH credentials and anything held in the operating system credential store are removed before the file is written, and file paths lose your account name. You may add an e-mail address and a description; both are optional, and both are shown to you in the report before you send it. |
| Billing | Stripe or Link may collect name, contact details, billing address, Tax ID, payment method and transaction data under their own notices. TableCore receives the identifiers and status information needed to provide your plan and support the transaction. |
The OAuth provider may also send an e-mail address and account identifier to us. We do not receive your provider password. If providers return the same e-mail for different identities, TableCore does not silently link them.
2. Desktop databases and local secrets
The desktop application connects to the MongoDB endpoint you configure. Your MongoDB queries, returned documents and connection credentials are not sent to TableCore merely because you use the desktop editor or translation engine. Connection secrets are designed to be stored in your operating system credential store; non-secret profile metadata and application settings may be stored locally on your device.
Data may leave your device when you deliberately use an online feature, an external service, an update/download endpoint or submit content to support. The public web converter translates the SQL you type locally in your browser using a WebAssembly build of the desktop translation engine; the queries you enter there are not transmitted to TableCore or to any third party. Before any future online feature accepts database content on our servers, this Policy and the feature's data notice must describe that processing. Do not submit production data to the current website.
3. Why we process data and our legal bases
We use personal data to:
- create and secure accounts, authenticate users and provide requested features — performance of our contract or steps requested before entering it;
- operate plans, licensing, subscriptions and customer support — performance of our contract;
- prevent abuse, protect accounts, diagnose failures and maintain service security — our legitimate interests in operating a safe and reliable service;
- measure which pages are visited, where visitors arrive from and how quickly pages render, so that documentation and articles can be corrected where they do not work — our legitimate interests in understanding and improving our own website, using cookieless measurement that does not profile you;
- keep accounting, transaction and compliance records and respond to lawful requests — compliance with legal obligations;
- establish, exercise or defend legal claims — our legitimate interests and applicable law; and
- send optional communications only where we have a valid legal basis, including consent where required.
We do not sell personal data and we do not use it for third-party behavioural advertising. The website measures traffic without cookies and without cross-site tracking, so it uses no advertising cookies and no analytics cookies. If we ever adopt measurement that stores or reads information on your device for a non-essential purpose, we will update this Policy and request consent before doing so.
Whether you must provide data
Providing the data required for authentication, account creation and licensing is a contractual requirement or is necessary to enter into and perform the relevant TableCore contract. You are not legally required to create an account, but if you do not provide the required data, we cannot create or maintain the account or provide account-based features.
Information required during checkout is necessary to purchase a paid plan and some information may also be required by applicable tax or accounting law. If required billing, payment, address or tax information is not provided, Stripe or Link may be unable to complete the transaction and TableCore cannot activate the paid plan.
Providing information in a support or feedback request is voluntary. We may be unable to investigate the issue or respond meaningfully if you do not provide the contact information and details reasonably necessary to handle the request. Fields marked optional may be omitted without preventing submission.
4. Cookies and similar storage
TableCore uses strictly necessary cookies for OAuth security and authenticated web sessions. The OAuth cookie is Secure, HttpOnly, SameSite=Lax and expires after about 10 minutes. The web-session cookie uses the same protections and expires after up to 30 days. Logging out revokes the server-side session and clears the cookie.
The site may also use essential browser storage needed for interface preferences and reliable operation. Blocking essential storage may prevent sign-in or account features from working.
Website analytics is deliberately outside this. Cloudflare Web Analytics runs from a script loaded from static.cloudflareinsights.com and reports to cloudflareinsights.com. It stores no cookie and no other identifier on your device and cannot recognise you on a later visit or on another site, which is why the site asks for no analytics consent and shows no cookie banner. Blocking the script, or a browser setting that blocks it for you, does not affect any feature of the site.
5. Service providers and other recipients
We disclose data only as needed to operate the Service, comply with law or protect rights. Recipients may include:
- Cloudflare, for website and Worker hosting, D1 database, security, rate limiting, release delivery, cookieless Web Analytics and related infrastructure;
- Resend, for delivering transactional e-mail such as one-time sign-in links and internal operational notifications;
- Google, GitHub and Microsoft, when you choose their OAuth sign-in;
- Stripe and Link, for checkout, payment, tax, subscription, invoice, fraud and transaction support functions; and
- professional advisers, authorities or a successor to the business where disclosure is lawful and necessary.
These organisations may act as our processors or as independent controllers, depending on the service. In particular, the entity identified during checkout may act as merchant of record and independent controller for payment and transaction processing. Review the provider's notice before using it, including Stripe's Privacy Policy, Google's Privacy Policy, GitHub's Privacy Statement and Microsoft's Privacy Statement.
6. International transfers
Providers may process data outside Poland or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. You may contact us for information about safeguards relevant to your data.
7. Retention
We keep personal data only for the periods below and then delete or anonymise it, unless a longer period is required for a specific legal obligation, regulatory inquiry or identified legal claim. Where a provider controls its own copy, its published retention rules also apply.
- OAuth attempts expire after about 10 minutes, magic-link attempts after about 15 minutes and web sessions after up to 30 days. Revocation may make a session unusable earlier. A daily cleanup removes these expired authentication rows from the active D1 database, normally within 24 hours after expiry.
- Account, provider identity, preferences and licensing records remain in the active database while the account exists. You can erase the account yourself, from Settings in the account panel: the session you are already signed in with is the verification, you type your own e-mail address to confirm, and the deletion runs immediately. It removes the account and its e-mail address, the connected provider identities, every browser session, every authorised desktop installation, your account preferences, your support requests together with the internal notes on them, any manual licence grant, any one-time sign-in link still pending for your address, and the subscription record we keep. The pending sign-in link is deleted by the same request rather than waiting for the daily cleanup described below, because that row holds your address and nothing else needs it. If you would rather write to us, the address in section 13 reaches an administrator who can run the same operation for you.
- An active subscription must be cancelled before the account can be erased, in Billing or through the Stripe Customer Portal. Erasing an account while the payment provider is still running a subscription would leave a paying customer this service can no longer recognise, so the request is refused with that reason rather than partly performed.
- Erasure does not reach five things, and the confirmation we show you names all five. Stripe's own payment, invoice and tax records stay under Stripe's control and its published retention; the Stripe Customer carries our account identifier in its own metadata, which is why we keep no Stripe identifier after erasure. Administrator audit entries and the record of the erasure itself are append-only by database rule and keep only the opaque account identifier, the action and the reason — never your e-mail address, your provider identity or the content of a request; once every row that mapped that identifier to a person is gone, it identifies nobody. Crash reports you chose to send arrive without an account and record only whether somebody was signed in, never which account, so there is no link by which a request could find them: they are deleted 180 days after they arrive, as stated below. A licence file already issued to a device is a signed file on your own machine and keeps working until it expires, after which the application returns to the Free plan; erasure removes the credentials that would issue a new one. Cloudflare's recovery history and request logs are covered by the two bullets at the end of this section.
- Ordinary support and feedback records stored in the TableCore D1 queue are removed 730 days after their last update. Formal complaints delivered by e-mail, records connected with an identified dispute and legally required correspondence follow the relevant complaint or claims limitation period instead.
- Processed Stripe webhook identifiers and their minimal processing status are removed after 90 days. Payment, transaction, invoice and tax records controlled by Stripe or Link follow their notices. Accounting or settlement records held by MagmaCore are retained for the statutory period applicable to the particular record.
- Crash reports that you chose to send, including any e-mail address and description you added to them, are removed 180 days after they arrive. A daily cleanup enforces that window, and a hard ceiling on stored reports applies whatever the window says. The crash files on your own computer are yours: TableCore keeps the most recent 20 and prunes the rest, and you can delete them at any time.
- Cloudflare Web Analytics reports are held by Cloudflare under its own published retention for the account's plan and are visible to us only as aggregates. TableCore stores no copy of them, keeps no raw analytics events and holds nothing that would let it single out one visitor from them.
- Cloudflare Workers Logs enabled for the website and License API are retained for 3 days under the current Workers Free plan. If the account is moved to Workers Paid, Cloudflare's standard retention may be up to 7 days. TableCore currently has no separate Workers Logpush archive.
- Deletion from active D1 does not immediately erase Cloudflare's point-in-time recovery history. Under the current Workers Free plan, D1 Time Travel can retain a recoverable earlier database state for up to 7 days; the provider limit may be up to 30 days on Workers Paid. TableCore currently has no separate long-term D1 export backup.
Expired credentials cannot be used during the interval before daily cleanup. Data may be retained beyond the ordinary periods only where the specific record is subject to a legal hold, statutory retention duty or ongoing claim; it is then restricted to that purpose and removed when the exception ends.
8. Security
We use measures appropriate to the nature of the Service, including hashed authentication tokens, short-lived OAuth attempts, one-time flows, secure cookies, rate limits, restricted service bindings and private data stores. No system is completely secure. You are responsible for securing your OAuth account, device, database credentials, backups and local environment and for notifying us promptly of suspected account misuse.
9. Your rights
Subject to the GDPR and applicable law, you may request access to your personal data, correction, deletion, restriction of processing and data portability. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.
Erasure is a control, not a request queue. Sign in and use Erase this account in Settings; it runs at once, and the confirmation names what was deleted, what was kept and why, together with a reference for the record of the request. The account panel session is the verification, because TableCore accounts are passwordless and we do not ask you to prove your identity a second way we would then have to store. An administrator can run exactly the same operation for a request that arrives by e-mail, with a stated reason recorded in the append-only audit log. Section 7 lists precisely what erasure removes, what it does not reach, and the one thing that blocks it.
Some requests may be limited where data must be retained by law, is needed to complete a transaction, protect another person or establish, exercise or defend legal claims. We may need to verify your identity before acting on a request that does not come from a signed-in account. You also have the right to complain to the supervisory authority in your country. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
10. Automated processing
The SQL-to-MongoDB translation engine processes query text to produce technical output. It is not used to profile you or make decisions about you that produce legal or similarly significant effects. Subscription access may be updated automatically from signed payment-provider events; you can contact us if you believe the status is incorrect.
11. Children
TableCore is intended for adults and professional software users, not children. We do not knowingly offer accounts to people under 18. Contact us if you believe a child has provided personal data.
12. Changes to this Policy
We may update this Policy when processing, providers or law changes. We will publish the effective date and give additional notice where a material change requires it. A future feature will not be treated as authorised to collect new categories of sensitive or database content merely because it appears in a product roadmap.
13. Contact
For privacy requests, questions or complaints, contact tablecore.dev@gmail.com or write to Mateusz Trojański MagmaCore, ul. Kaliska 36 lok. 33, 56-500 Syców, Poland. We will respond within the period required by applicable law.