Privacy Policy
Last updated: August 22, 2026
1. What we collect
- Account data: your email address, company name, and the records needed to operate your account (subscription tier, audit credits).
- Infrastructure metadata you upload: hostnames, OS names and versions, socket/core counts, RAM, cluster names, virtualization flags, and SQL Server instance names, editions, and versions. The complete field list is on our security page. The scanner and our parsers are designed to exclude passwords, IP addresses, file contents, user directories, and personally identifiable information.
- License documents you choose to upload (Microsoft CPS / MLS files), stored privately for your organization.
- Support content: tickets and messages you send us.
- Operational logs generated by hosting our service (standard web server logs).
2. What we do with it
One thing: provide the service to you. Your uploaded data is used to generate your reports and for nothing else. We do not sell personal or customer data, do not use your data to train models, do not build aggregate datasets from it without your separate written agreement, and — as committed in our Terms of Service — never disclose it to Microsoft, resellers, licensing partners, auditors, or any other third party except under legal compulsion.
3. Where it lives
Data is stored with our infrastructure subprocessors: Supabase (database, authentication, and file storage) and Amazon Web Services (application hosting via AWS Amplify). When payments launch, payment details are handled by Stripe and never touch our servers. Data is encrypted in transit (TLS) and at rest (AES-256). Access within our systems is scoped per organization and enforced at the database row level.
4. Retention and deletion
We retain your data while your account is active so your report history keeps working. You can request deletion of specific inventories, reports, and documents — or your entire account — at any time by opening a support ticket from your dashboard or emailing support@winsqltool.com. We delete within 7 days and send written confirmation.
5. Cookies
We use only the cookies required to keep you signed in (authentication session cookies). No advertising or cross-site tracking cookies.
6. Changes and contact
Material changes to this policy will be reflected in the “last updated” date above. Questions or requests: support@winsqltool.com.