Privacy Policy

HeapDeck is an iPhone app for monitoring PostgreSQL servers, made by an independent developer. It has no account and no server of its own. This policy covers what the app stores, what it sends and where, and what this website collects.

In short

  • HeapDeck connects from your iPhone to the PostgreSQL servers and SSH bastions you set up. Your connections, queries and data never pass through a HeapDeck server, because there isn't one.
  • Passwords, SSH keys, pinned fingerprints and your AI API key stay in the iOS Keychain on your device.
  • Crash reports go to Sentry and usage counts to our own analytics server, only while their switches are on. They never contain your SQL, database, schema, table or column names, hostnames, field values or credentials.
  • The AI assistant (Pro) sends a redacted snapshot to the provider you choose, only when you ask it something.
  • We don't sell data, show ads, or track you across apps and websites.

What the app connects to

  • Your PostgreSQL server, directly or through the SSH bastion you configure. There, HeapDeck shows up as application_name = HeapDeck.
  • The AI provider or model server you set up for the assistant, only when you ask it something (Pro).
  • Sentry for crash and error reports, and our own analytics server for usage counts, each only while its switch is on.
  • Apple's App Store for the in-app purchase.

Nothing else. The demo connection and the onboarding screens work offline.

What stays on your iPhone

  • iOS Keychain, this device only (WhenUnlockedThisDeviceOnly), never synced to iCloud or moved to another device: database and SSH passwords, SSH private keys, pinned TLS and SSH fingerprints, your AI API key and the cached Pro status.
  • The app's protected files: connection settings without secrets (name, host, port, database, user, TLS mode, SSH host and user) and saved column layouts.
  • App settings: theme, language, the privacy switches and the assistant provider.
  • Memory only: SQL history and assistant conversations. They are gone when the app closes.

An exported page goes to the iOS share sheet or the clipboard, and where it goes from there is your choice. Deleting a connection removes its password, private key and pinned fingerprints from the device; your server is not touched.

AI assistant

The assistant is part of Pro. It sends nothing until you set up a provider and ask a question.

Requests go directly from your iPhone to the provider you choose (Anthropic, OpenAI, OpenRouter or Z.ai, with your own API key) or to your own Ollama or OpenAI-compatible server. That provider's privacy policy applies to what it receives.

  • Sent: your question and a snapshot of the screen you asked about, read with read-only queries.
  • Never sent: host, port, client addresses, the connection name, passwords, SSH keys and certificates.
  • Values are replaced in every mode: literals in SQL become $1, $2, values in error messages become <value>, and numbers, emails and dates in your question become placeholders.
  • Names: with “Names hidden”, the default for cloud providers, database, schema, table, column, index, role and slot names are replaced with placeholders like table_1 and restored on your phone. With “Real names”, the default for Ollama on your network, they are sent as they are.

“What the model sees” shows the exact text before it is sent. On the demo connection the assistant answers from a built-in script and calls no model.

Crash reports and usage counts

The first launch ends on a screen with two switches, Crash & error reporting and Usage analytics. Both start on. You can turn either off there or later in Settings › Privacy.

  • Crash & error reporting sends technical details of crashes and failed operations to Sentry (Functional Software, Inc.): what failed and where in the app.
  • Usage analytics sends counts of which screens and steps are used to an analytics server we run ourselves. It is not shared with anyone.
  • Your choice is sent once, as a single note, whichever way it goes. With usage analytics off, nothing follows that note. With crash reporting off, crash reports stop at once.

Neither ever contains your SQL, database, schema, table or column names, hostnames, field values or credentials, and neither uses an advertising identifier. The app also keeps a short technical log on the device (error categories, counters, durations) that doesn't leave it. Crash reports and usage counts are kept only as long as they help us fix and improve the app. To ask about data already sent, write to support@heapdeck.app.

Permissions

  • Face ID unlocks the app while App Lock is on, which it is by default. Touch ID and your passcode work too. Face ID data stays with iOS; HeapDeck only learns whether unlocking succeeded.
  • Local Network is requested only when a server, bastion or Ollama is on your local network.

HeapDeck doesn't ask for your location, contacts, photos, camera or microphone.

Purchases

HeapDeck Pro is sold through Apple. We never receive your payment details. The app checks Apple's signed transaction on the device to unlock Pro.

This website

heapdeck.app is a static website hosted on Cloudflare, which processes technical request data such as IP addresses to deliver and protect it.

We use Google Analytics 4 to see which pages are read and which buttons are used, such as the App Store badge. It sets cookies and loads after your first interaction or a few seconds after the page opens. Advertising features are off. Google's privacy policy applies to that data.

If you email us, we use your address and message only to reply.

Children

HeapDeck is a developer tool rated 4+ and isn't directed at children. We don't knowingly collect personal information from children.

Your choices and changes

Everything the app stores lives on your device, so you can see, change or delete it there. For anything about this website or your emails, write to support@heapdeck.app.

If this policy changes, the new version is published on this page with a new date.

Contact

HeapDeck is developed by Vladimir Chemeris. Privacy questions: support@heapdeck.app.