Privacy

This describes what SchemaWright collects, who else receives it, and how to have it removed. It is written against what the code does, in the plainest language the subject allows.

Last updated: 29 August 2026

Who runs this

SchemaWright is operated by Gabriel Marcondes, an individual developer based in Brazil. There is no company behind it and no team. One person receives every message sent to the address at the bottom of this page.

What is collected

Five things, and nothing else.

Your account

You sign in with GitHub or Google. From that provider SchemaWright receives and stores your email address, your name, your username and your avatar URL. No password is ever created, sent or stored, because there is no password to create. Authentication happens entirely at GitHub or Google.

What you submit

Every time you run the tests, the SQL you wrote is stored, along with any assumptions you typed, which exercise it was for, which tests passed, and the design review that came back. This is what makes your progress and your best score possible, and what lets a result from today still be explainable after an exercise changes.

Submissions are append-only by design: the database has no policy permitting anyone, including the operator through the application, to edit or delete an individual attempt. An attempt is a fact. Deleting your account removes all of them at once, which is described further down.

Your subscription

If you subscribe, SchemaWright stores your Stripe customer id, your subscription id, its status, and the date the paid period ends. That is the entire record.

Your card details never reach this server. Checkout and cancellation are both hosted by Stripe on their own pages, so there is nothing here to leak.

What stopped you

On a subscribers-only exercise you can answer one optional question about why you are not subscribing. What is stored is which exercise you were looking at, the answer you picked, anything you typed, and the date.

It is not linked to your account, even if you are signed in. There is no user id on that record, because feedback that can be traced back to a person is feedback people soften.

The mailing list

That question ends with an optional email address. If you give one, it is stored lower-cased with a note of where it came from, and used only to reply to you and to say when a new exercise ships. Ask and it is removed.

What is not collected

SchemaWright has no analytics, no tracking pixels, no advertising, no session recording and no third-party scripts of any kind. Nobody is profiled, nothing is sold, and nothing is shared with anyone not listed on this page.

Web fonts are served from this domain rather than from a font CDN, so loading a page does not hand your IP address to a third party.

Who else receives it

Four providers, each doing one job. They process this data on SchemaWright's behalf and are not permitted to use it for their own purposes.

SupabaseDatabase and authentication
Holds your account, your submissions, your progress and your subscription record.
StripePayments
Receives your payment details directly, on their own hosted pages, and tells this server only whether a subscription is active.
Fly.ioHosting
Runs the application servers, in the United States.
opencode zenThe design review
Receives your submission so a language model can comment on it. See the next section, because this one deserves its own.

Because these providers operate internationally, your data may be processed outside the country you live in, including in the United States.

The design review, specifically

After the battery runs, the second half of grading sends your submission to a language model through an external API in order to comment on naming, types and trade-offs.

What is sent: the exercise text, the SQL you wrote, any assumptions you typed, the test results, and the exercise's own reference solution and marking guide.

What is not sent: your name, your email address, your account id, or anything else that identifies you. The request carries the work, not the person.

If you would rather no third-party model ever see your SQL, do not use the design review. The battery is the graded, verifiable half and it runs entirely on SchemaWright's own servers.

Cookies

One kind: the session cookie that keeps you signed in, set when you sign in and cleared when you sign out. It is necessary for the site to work and it is not used to track you anywhere. There are no advertising or analytics cookies, which is also why there is no consent banner: there is nothing to consent to.

How long it is kept

Your account, submissions and progress are kept while your account exists, because they are the product: your history is what you came back for.

Subscription records are kept while the subscription exists and afterwards for as long as tax and accounting rules require the record of a payment to survive.

Waiting-list addresses are kept until the list is retired or you ask to leave.

Your rights

Wherever you live, and specifically under the GDPR and Brazil's LGPD, you may ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, and object to how it is used. Write to the address below and expect an answer within 30 days.

Deletion is not partial. Removing your account removes your submissions, your progress and your subscription record with it, in the same operation, because they are tied to your account at the database level. It cannot be undone, and it will not be done by accident. It happens only when you ask.

Security, honestly stated

Every table enforces row-level security, so a query can only ever return your own rows. Payment details never reach this server. The service-role key that can bypass those rules is never sent to a browser.

No system is beyond compromise, and anyone claiming otherwise is selling something. If a breach affects you, you will be told what happened and what to do about it.

Age

SchemaWright never asks your age and has no way to verify it. Signing in with GitHub or Google tells this service nothing about how old you are, and it would be dishonest to pretend otherwise.

The service is built for working developers and is not directed at children. If you are a parent or guardian and believe an account belongs to a child in your care, write to the address below and it will be deleted along with everything attached to it.

Changes

When this policy changes, the date at the top changes with it. If a change affects what is collected or who receives it, everyone with an account is emailed before it takes effect, not after.

Contact

Questions about anything on this page, or a request to see or delete your data: devgabmasantos@gmail.com.