Privacy policy
Last updated 2 September 2026
Who we are
Bolvrk ("we", "us") is operated by Simon ApS, CVR DK38213458, Gersonsvej 40, 1., 2900 Hellerup, Denmark. Contact: hello@bolvrk.com for general and privacy matters, security@bolvrk.com for security. We have not appointed a data protection officer; these addresses reach the people who operate the service.
This policy covers the hosted service and the public website at bolvrk.com. The open-source CLI runs on your own machine and sends us nothing unless you pass --remote.
Controller or processor
We act in two roles, and the GDPR treats them differently.
- Controller for account, billing and operational data: your GitHub user ID and login name, the team you belong to and your role in it, subscription status, and server logs. We decide why and how this is processed, and this policy is the notice for it.
- Processor for the content your team submits: migration SQL, the findings we produce for it, schema structure read from a connected database, git metadata attached to a check, and any AI review your team requests. Your team is the controller of that content; we process it only on your instructions to run the service.
A data processing agreement covering the processor role applies by default to every customer; it is incorporated by reference into the terms of service.
What we collect
- Account data. When you sign in with GitHub, GitHub returns your public profile; we store your GitHub user ID and login name and nothing else from it — no email address, no repository access. We also record which team you belong to, your role, and when the account was created.
- Check data. The migration SQL your team submits, the findings report it produced (rule IDs, severities, messages, object names, suppressions), the migration file name, git metadata (repository, branch, commit, pull-request number) when the Action or CLI sends it, feedback you file on findings, and — only when a team on the Scale plan requests one — the AI review observations for that check. Where a migration contains a plaintext credential, the finding masks the value before anything is written.
- Database connection details. If you store a connection with us, its connection string is sealed with public-key encryption before it is written and opened only for the seconds a check runs. During a check we read catalog metadata (table names, columns, row estimates, index definitions, activity counters) inside a read-only transaction — never the rows in your tables — and retain none of it after the check. The security page documents this boundary in detail.
- Credentials we issue. Team tokens, refresh tokens and invite links are stored as SHA-256 hashes; the plaintext is shown once at creation and never stored. Notification channel secrets (webhook URLs, signing secrets) are sealed like connection strings.
- Billing data. Payment is handled by Stripe. We store your team's subscription status and its Stripe customer and subscription references. Card details, billing address and VAT number are entered on Stripe's pages and held by Stripe, not by us.
- Operational logs. Standard server logs (IP address, request path, status, time) kept briefly for security and debugging.
Why we process it, and on what legal basis
- Account and billing data — to provide the service, authenticate you, invoice your team and keep the books. Legal basis: performance of our contract with your team (GDPR art. 6(1)(b)) and, for invoices, a legal obligation under bookkeeping law (art. 6(1)(c)).
- Operational logs — to keep the service secure, detect abuse and diagnose faults. Legal basis: our legitimate interest in operating a secure service (art. 6(1)(f)).
- Check data and connection details — to run checks and keep your team's history. We process this as your team's processor on its documented instructions (art. 28); the legal basis is your team's own, as controller.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not read rows from your databases — only schema metadata, only during a check.
- We use no analytics or tracking on the website or in the product.
- We do not train AI models on your data, and our model provider's API terms exclude training on it. AI review sends a single check's migration SQL and findings to the model provider, only when your team asks for that review.
Sub-processors
These third parties handle data on our behalf, each bound by its own data-processing terms with us. We give 30 days' notice of additions or replacements by email and in the changelog; the data processing agreement sets out how to object.
| Sub-processor | Purpose | What it receives | Location |
|---|---|---|---|
| Hetzner Online GmbH | Hosting | Everything the service stores, at rest in the EU. | Germany / Finland (EU) |
| GitHub, Inc. (Microsoft) | Sign-in | The OAuth handshake; GitHub returns your user ID, login name and avatar URL, of which we keep the ID and login. | United States |
| Stripe Payments Europe, Ltd. | Billing and VAT | Team name, billing email and address, VAT number, payment details you enter on Stripe's pages, invoices. Stripe uses its United States affiliates for processing. | Ireland, with United States affiliates |
| Anthropic, PBC | AI review | Only when a team on the Scale plan requests a review: that check's migration SQL and its findings. Nothing is sent otherwise. | United States |
International transfers
The service and its database are hosted in the EU. Where a sub-processor is in the United States, transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. We do not transfer personal data anywhere else.
How long we keep it
- Checks, findings, reviews and feedback are kept as your team's history until the team is deleted. We apply no automatic expiry.
- Account data is kept until you delete your account or the team you belong to is deleted.
- Sessions. A refresh session lasts about one year unless you sign out earlier; access tokens last 15 minutes.
- Invoices and bookkeeping records are kept for five years from the end of the financial year they relate to, as the Danish Bookkeeping Act requires.
- Operational logs are kept briefly and then discarded.
- Backups. Deleted data may persist in backups for up to 30 further days before they roll over.
Security
All traffic is encrypted in transit. Connection strings and channel secrets are sealed-box encrypted at rest with a key held outside the database; tokens are stored hashed; access to production is limited to the operator. The security page is the full description. Report vulnerabilities to security@bolvrk.com.
Cookies
We set one cookie: a strictly necessary, httpOnly session cookie that keeps you signed in to the app. We use no analytics or tracking cookies, so no consent banner is shown.
Your rights
Under the GDPR you can ask us for access to your personal data, have it rectified or erased, restrict its processing, receive a copy in a portable format, and object to processing based on legitimate interest. Write to hello@bolvrk.com; we answer within one month. Where we act as your team's processor, we refer requests about check content to your team, which decides on them. You can also complain to the Danish Data Protection Agency, Datatilsynet.
Deleting your account or team
You can delete your account, and a team admin (or the sole member of a team) can delete the whole team, from the app where available, or by writing to hello@bolvrk.com. Deleting an account removes your account data. Deleting a team removes its check history, reviews, connections, tokens, notification channels and memberships within 30 days, with backups rolling over within a further 30 days. Bookkeeping records are kept for the period stated above.
Changes to this policy
We may update this policy when the service or the law changes. Material changes are announced by email and in the changelog at least 30 days before they take effect; the date at the top identifies the current version.
Contact
Simon ApS, Gersonsvej 40, 1., 2900 Hellerup, Denmark · hello@bolvrk.com · bolvrk.com/contact.