LEGAL

PRIVACY POLICY

LAST UPDATED: JULY 25, 2026

1. The most important fact

Your data never comes to us. DVT runs on your machines. Your database credentials live in your local profiles.yml; your query results move between your engines and your machine; AI prompts flow through a gateway you run with model subscriptions you own. None of it touches MetaThinking servers. What does reach us is listed in section 2 — account, licensing, and metadata-only usage records, never the data itself. Air-gapped deployments make no network calls at all.

2. What we do collect

Account data — when you sign in (required for free individual use): name, email, and authentication identifiers, processed via Clerk, our sign-in provider.

License checks — the CLI verifies your API key with getdvt.net and records per-machine activations (a hashed key, a machine identifier, timestamps) so seats can be managed and abuse prevented.

Forms and leads — what you submit through the enterprise assessment, contact, or newsletter forms: contact details and the engineering answers you provide (engines, data volume brackets, deployment posture, machine specs).

Website analytics — getdvt.net uses PostHog for usage analytics (pages viewed, approximate location, device class).

Product usage telemetry — when you use DVT signed in, the software reports usage metadata to getdvt.net so we can see how the product behaves in the field: which command ran, how long it took, how it ended (success or an error class), which engine types were involved, which suite apps were opened, DVT Martin ask counts and which tools it triggered with their accept/reject outcomes, error codes, the DVT version, the operating system, and a hashed machine identifier. It is metadata only — never your SQL, prompts, data, schema, table or column names, connection names, credentials, or file paths. You can turn it off per project by setting telemetry_enabled: falsein dvt_project.yml; signed-out and air-gapped machines send nothing at all. DVT also disables dbt's own anonymous usage statistics in the projects it manages, so this disclosed, controllable channel is the only telemetry in play.

3. How we use it

To operate accounts and licensing; to respond to assessments and support requests; to improve the product and the site; and — only where you ticked the consent box — to contact you about DVT and related MetaThinking products (such as AI-Proxy). We do not sell your personal data to third parties. MetaThinking is the data controller for all of the above.

4. Processors we rely on

Clerk (authentication), Supabase (database hosting), Vercel (site hosting), PostHog (analytics), and our email provider for replies. Each processes data on our instructions.

5. Retention and your rights

Account and activation records are kept while your account exists; leads are kept until the conversation concludes or you ask us to delete them. You can request access, correction, export, or deletion of your personal data, and withdraw marketing consent at any time — contact us and we will act within 30 days.

6. Cookies

getdvt.net sets cookies for sign-in sessions (Clerk) and analytics (PostHog). The DVT app suite sets one functional cookie on your own localhost (theme preference). No advertising cookies.

7. Changes

Material changes to this policy are announced on getdvt.net with an updated date above.

DVT and getdvt.net are operated by MetaThinking (meta-thinking.net). Questions about these terms: use the contact page.