This policy explains what Datrov (“we”, “us”) collects when you use the service, why we collect it, who we share it with, and what control you have over it. We have tried to write it in plain language rather than legalese.
1. Data we collect
Account data
When you create an account we collect your email address and store an authentication record. If you sign in with a third-party provider, we receive your email and a provider account identifier. We do not store your password — authentication is handled by our authentication provider (see sub-processors below).
Content you provide
This is the substantive category. It includes:
- Datasets you upload — CSV, Excel, JSON, SQLite and image files, and their contents.
- Database connections — when you connect a database, we use the credentials you supply to read the tables you select. Sampled rows are stored as part of your session so the assistant can work with them.
- Chat messages — everything you type to the assistant, plus the code it generates and the output that code produces.
- Models you train — trained model weights, metrics and configuration.
Usage and diagnostic data
We collect product analytics (which features are used, page views, and events such as “a training job was submitted”) and error diagnostics (stack traces when something breaks). Both are tied to your account identifier so we can debug a problem you report. Our error reports are configured to exclude request bodies, cookies and credentials.
2. How we use it
- To operate the service — running your analyses, training your models, serving your endpoints.
- To maintain your session history so you can return to earlier work.
- To enforce plan limits and, on paid plans, to bill you.
- To diagnose failures and improve reliability.
- To understand which features are used, in aggregate, so we know what to build next.
We do not sell your data. We do not use the contents of your datasets or chats to train our own models.
3. Processing by AI providers
Datrov is built on large language models that we do not host ourselves. To answer your questions, the contents of your chat — including dataset column names, sample rows and code output that the assistant needs in order to reason about your data — are sent to our model provider for processing. Please do not paste secrets, credentials or personal data you are not permitted to share into the chat.
4. Sub-processors
We use the following third-party services to run Datrov. Each processes some portion of your data on our behalf:
| Purpose | What it processes |
|---|---|
| Authentication & database storage | Email, account records, sessions, datasets, chat history |
| AI model inference | Chat messages and the data context needed to answer them |
| Sandboxed code execution | Datasets and the analysis code run against them |
| GPU training & model hosting | Training datasets, trained model weights, inference requests |
| Application hosting | Requests to the service, IP addresses |
| Product analytics | Account identifier, feature usage events |
| Error monitoring | Account identifier, stack traces |
| Payment processing | Email, transaction records (card details go to the processor, never to us) |
A current list of the specific providers behind each of these functions is available on request at support@datrov.com. We will update this policy when we add or change a sub-processor category.
5. Retention
Sessions, datasets and models are kept until you delete them or close your account. Deleting a session removes its datasets and chat history. When you close your account we delete your content; backups and logs may persist for a short period afterwards before being overwritten. Analytics and error records are retained in aggregate.
6. Your rights
You can access and export your sessions from within the app at any time, and delete any session or dataset yourself. To request a full export or deletion of your account and all associated data, email support@datrov.com. Depending on where you live you may have additional rights over your personal data — including access, correction, deletion, portability and objection to processing — and you may exercise them through the same address.
7. Security
Traffic is encrypted in transit. Credentials and API keys are stored encrypted and are never returned to the browser after being saved. Code you run executes in an isolated sandbox. No system is perfectly secure, and we cannot guarantee absolute security — but if we become aware of a breach affecting your data, we will notify you.
8. Children
Datrov is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We may update this policy. If a change materially affects how we handle your data, we will notify you by email or in the app before it takes effect.
10. Contact
Questions about this policy, or about your data: support@datrov.com.