Last updated July 17, 2026
Privacy Policy
Stroke is built on a simple boundary: the desktop app works with your databases on your machine, and our servers only handle accounts and licenses. This policy describes what crosses that boundary, what never does, and what your choices are.
01The short version
- Your database credentials, queries, and data never leave your device. Stroke connects to your databases directly; nothing is proxied through our servers.
- We only hold personal data if you create an account to buy a license: your name, email, and license records.
- We don't run ads and we never sell data. The website uses privacy-friendly analytics only if you opt in through the cookie banner.
02What the desktop app stores locally
Connection details (hosts, ports, usernames, passwords, file paths, API tokens), saved queries, dashboards, and preferences are stored locally on your device. They are read by the app to do its job and are never uploaded to us. If you use the built-in AI chat or MCP server with a third-party AI client, data flows directly between your machine and the provider you configured, under that provider's terms, not ours.
03What we collect if you create an account
Accounts exist only for licensing. When you sign in with GitHub or Google, we receive and store:
- Your name, email address, and avatar from the provider you chose. We never see your password.
- Session data (a cookie that keeps you signed in, plus IP address and user agent for session security).
- License records: your license key, plan, and (when you activate the app on a device) a device identifier and hostname, used to enforce the 2-device limit and to let you deactivate devices from your dashboard.
- Payment records: the status and amount of payments, kept for accounting. Checkout happens on Dodo Payments; card details never touch our servers.
04What we don't collect
- No database credentials, schemas, queries, or query results.
- No usage analytics or telemetry from the desktop app.
- No advertising identifiers, and no sale or sharing of personal data for marketing.
05Cookies
Two functional cookies are always on: one to keep you signed in and one to remember your light/dark theme preference. These are essential to the site and don't require consent.
Beyond those, we use privacy-friendly product analytics (PostHog) to understand which pages are useful, but only after you accept through the cookie banner. If you decline, no analytics cookies are set and nothing is tracked; the site works exactly the same either way. Your choice is remembered locally, and you can change it by clearing this site's storage. We never use advertising cookies.
06Services we rely on
A small number of providers process data on our behalf:
- Cloudflare hosts the website, database, and licensing API. Requests to stroke.click pass through Cloudflare's network.
- Dodo Payments processes checkout as merchant of record and handles billing details under its own privacy policy.
- GitHub and Google provide sign-in. Downloads are served from GitHub Releases, so fetching an installer is a request to GitHub, not to us.
- PostHog provides privacy-friendly website analytics, loaded through a same-origin proxy and only after you opt in. It never receives your database data.
07How long we keep data
Account, license, and payment records are kept while your account exists, and payment records as long as accounting rules require. Device activations are removed when you deactivate a device. If you delete your account, we delete your personal data, keeping only what payment regulations oblige us to retain.
08Your rights
You can access and update your account details from your dashboard. You may request a copy of your data, correction, or deletion at any time. Depending on where you live, laws like the GDPR or CCPA give you these rights formally, but we honor them for everyone. Contact us and we'll handle it.
09Changes to this policy
If we ever change what we collect, for example by adding opt-in crash reporting to the app, we will update this page, change the date at the top, and call out the change in the release notes before it ships.
10Contact
Privacy questions or requests? Open an issue on GitHub or reach us through the support page in your dashboard. The terms that govern the service are in the Terms of Service.