Youssef Al-Tai

Privacy Policy

Effective 2026-10-05.

Caracal collects no data. There is no analytics and no account.

Connections to your databases

When you connect, Caracal talks directly from your device to the database server, or to the SSH host in front of it, that you entered. Nothing passes through a server of mine. Apart from Apple's own services (purchases and iCloud), Caracal makes no other network connections.

Your connection list

The list holds what you enter for each connection: its name and group, host, port, database and user, the TLS mode and CA certificate, the SSH host, port and user, the saved host-key fingerprint, and settings such as production and read-only. For a SQLite file it holds the file's path and the bookmark that lets Caracal reopen it. The list is kept in Caracal's iCloud Drive container, so your devices share it. If iCloud isn't available, it stays on the device. I never see it.

Passwords and keys

Database passwords, SSH passwords, SSH private keys and their passphrases are stored in your Keychain, never in the connection list, and synced across your devices by iCloud Keychain if you have it turned on. I never see them.

Saved queries

A query you save is a .sql file in the same place as the connection list: Caracal's iCloud Drive container, or the device if iCloud isn't available.

History

Caracal keeps the last 1,000 statements you ran on each connection, on this device only. Each entry has the statement, its start time and duration, how many rows it returned, and whether it completed, failed or was cancelled. It never holds the rows a statement returned. History is never synced, and you can clear it for a connection at any time.

Before a statement is stored, Caracal hides the text after PASSWORD or CONNECTION, as in CREATE ROLE … PASSWORD '…'. That is all it can see: a password set any other way, such as in an UPDATE of your own table or a string built at run time, is kept as you typed it.

Purchases

Purchases are handled entirely by Apple through the App Store. I don't receive your payment details.

Contact

Questions about this policy: [email protected].