Last Updated: September 8, 2026
Evokoa Inc. ("we," "us," or "our") operates the Polygres database platform, including the website at polygres.com, the application console at db.polygres.com, the API endpoints, and related developer SDKs (collectively, the "Service").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We are committed to protecting your privacy and ensuring you have control over your data.
1. Information We Collect
We collect information to provide, maintain, and improve our database platform:
- Account Information: When you create an account, we collect your email address, password hash (for password-based accounts), and organization name. We may also receive a display name from an identity provider or invitation when one is supplied.
- Billing Information: We use Stripe for payment processing. We do not store your credit card or financial details on our servers; this information is collected and processed directly by Stripe under their privacy policy.
- Service Telemetry and Log Data: To keep the database hosting stable and secure, we collect metadata about API requests, query duration, resource usage (CPU, memory, storage), and server errors. This includes IP addresses, browser types, and timestamp data.
- Product and Website Analytics: We use PostHog and Microsoft Clarity to understand use of the Service and improve usability. Analytics may include account and organization identifiers, account email, account status, feature usage, interaction events, device and browser information, and session replay data. Section 4 explains these tools in more detail.
- Database Data (Your Content): We host and automatically process the database records, graph relationships, and vector embeddings you store in Polygres to carry out your requests and provide the Service. Our personnel do not read your database contents as part of routine operations, updates, or maintenance. We review database contents only when you explicitly request that review, limited to the scope of your request, subject to the legally required access or disclosure described in Section 3.
2. How We Use Your Information
We process your information for the following purposes:
- To set up, configure, and maintain your database instances.
- To process payments and subscription billing.
- To monitor infrastructure performance, protect against abuse (such as denial-of-service attacks), and diagnose bugs.
- To understand feature usage, identify usability issues, and improve the website and application console.
- To send you critical system notifications, security alerts, and billing receipts.
- To comply with our legal obligations.
3. Data Privacy and Confidentiality
Your databases are isolated and private.
- No Data Selling: We do not sell, rent, or lease your personal information or database contents to third parties.
- Maintenance Access: Administrative access to database infrastructure is restricted to authorized personnel for updates and maintenance. This access does not authorize personnel to read your database contents.
- Support at Your Request: If you explicitly ask us to examine database contents for support, our review is limited to the information and assistance you request. Using the Service or asking a general support question does not by itself authorize a review of your database contents.
- Legally Required Access or Disclosure: We may be required to preserve, access, or disclose information to comply with applicable law or binding legal process. Any such access or disclosure is limited to what is legally required. This exception does not authorize routine review of your database contents.
- Encryption: Database data is encrypted in transit using TLS 1.3/1.2 and encrypted at rest on our storage systems.
4. Cookies, Analytics, and Session Replay
- Essential Cookies: We use session cookies to keep you logged into the Polygres console and support account security.
- PostHog: We use PostHog for product analytics and session replay in the application console, and for service usage events sent by our servers. We associate analytics with account email and user, organization, and project identifiers to understand feature adoption, workflow outcomes, and errors. Session replay helps us understand interactions with the interface. See the PostHog Privacy Policy for information about PostHog's data handling.
- Microsoft Clarity: We use Microsoft Clarity on the website and application console for interaction analytics, heatmaps, and session replay to identify usability issues and improve the Service. Clarity collects interaction and device information using cookies and similar technologies. Microsoft receives this information and processes it as described in the Microsoft Privacy Statement, including for its own purposes described there.
- Session Replay and Database Privacy: Session replay reconstructs interactions with web pages; it is separate from database infrastructure access. Our use of analytics does not authorize personnel to review your database contents. The confidentiality and customer-requested access limits in Section 3 continue to apply.
- Your Choices: You can manage or block cookies through your browser settings, although blocking essential cookies may affect sign-in and other functions. Blocking browser cookies does not necessarily stop service usage events sent by our servers. To ask about analytics processing or exercise applicable privacy rights, contact team@evokoa.com. This policy does not replace any consent required by applicable law.
5. Third-Party Service Providers (Subprocessors)
We rely on trusted third-party partners to provide specific infrastructure services:
- Cloud Infrastructure Providers: To host and run the physical servers and storage.
- Stripe: For billing, invoicing, and subscription payments.
- Cloudflare: For edge routing, security protection, and DNS.
- PostHog: For product analytics, service usage analysis, and application session replay, as described in Section 4.
- Microsoft Clarity: For website and application interaction analytics, heatmaps, and session replay, as described in Section 4 and the linked Microsoft Privacy Statement.
All subprocessors are vetted for compliance with industry-standard security regulations (such as SOC 2 and ISO 27001).
6. Your Rights and Data Control
In accordance with global data protection laws (including GDPR and CCPA), you have the following rights:
- Access and Portability: You can download or export your databases at any time using standard PostgreSQL backup tools (
pg_dump) or our APIs. - Correction: You can update your account profile details directly inside the console.
- Deletion (Right to be Forgotten): You may delete your databases and your account at any time from the settings dashboard. Deleting your account will immediately terminate database instances and queue any existing associated backups for hard deletion within 30 days, except where retention is legally required. This retention statement does not mean that backups are included with your account. Backup commitments require a separate written agreement as described in our Terms of Service.
7. Children's and Minors' Privacy
Our Service is strictly intended for and directed to individuals who are at least 18 years of age. We do not target our Service at minors, and we do not knowingly collect personal information from individuals under the age of 18. If you are under 18, please do not use our Service or send any personal information to us.
If we learn that we have collected or received personal information from a minor under 18 without verifiable parental consent, we will delete that information immediately. If you believe we might have any information from or about a minor under 18, please contact us at team@evokoa.com.
8. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Email: team@evokoa.com