QueryWell
Product Data Loader Security Compare Guide Pricing
Back to QueryWell

Privacy Policy

Effective 26 August 2026.

Product: QueryWell Controller: Elaman Group Ltd, registered in England and Wales (company no. 15708144) ("we", "us", "our") Effective date: 26 August 2026

This policy explains what data QueryWell (the "Software") handles. QueryWell is a local desktop application and Elaman Group does not host your reporting data. Studio workflows keep query results on your device. If you use the optional AI Workbench, content needed for that run is sent directly from your device to the model provider you configure.

1. Data that stays on your device (we never receive it)

The Software runs entirely on your computer. The following are stored locally only and are never transmitted to us:

  • Credentials. Passwords and OAuth tokens for your Oracle Fusion connections, and API keys for configured AI providers, are stored in your operating system's secure keychain (macOS Keychain / Windows Credential Manager). They are not written to our servers or to plaintext files.
  • Licence keys. Your licence key is verified locally on your device using a verification key built into the Software. During first activation of a device (and only then) the key is sent over an encrypted connection to our activation service so we can confirm it and register your operator seat; we store only a SHA-256 fingerprint of the key, never the key itself, and the key is never logged. Routine startup and normal offline use do not transmit the key.
  • Studio query results and reports. Data you retrieve through Studio, and any CSV/JSON/XLSX/PDF exports, stay on your machine. Content you deliberately process through the AI Workbench is subject to the separate provider data path described below.
  • Connection metadata, saved queries, history, and logs. Stored in a local database on your device. Sensitive parameter values are masked in history and execution logs.

We do not collect product-usage analytics or telemetry from the Software. Packaged builds make update checks as described below. The AI Workbench also connects to a provider only when you configure and use it.

2. AI provider processing that you control

When you use the AI Workbench, the Software sends the conversation, relevant schema context, tool definitions and tool results needed for the run directly to the AI provider you selected. Depending on the question and tools used, tool results can include query-output rows. Elaman Group does not proxy, receive or retain that payload.

Supported choices currently include Anthropic, OpenAI, OpenRouter and compatible Ollama endpoints. A locally operated Ollama endpoint can keep model processing inside your environment. For a hosted provider, its contract, privacy policy, retention, training, residency and international-transfer settings apply. You are responsible for choosing and configuring a provider appropriate for the data you submit. The built-in demonstration report does not require a provider or a Fusion connection.

3. Data we do process

  • Update checks. Packaged builds of the Software contact querywell.app when checking for a newer version. That request sends the app version, the platform (e.g. macOS/Windows and CPU architecture), your licence identifier, and a random install identifier generated by the Software. Our infrastructure provider (Cloudflare) derives a coarse location (country and city) from the network request, which we record alongside the check; we do not store IP addresses. We use this data to deliver the right update and to monitor licence compliance (e.g. how many installations use one licence, and whether one licence is used across implausibly many locations). No hardware identifiers are collected and no usage analytics are gathered; the data is retained for no more than 400 days.
  • Licence activation and renewal. To enforce named operator seats and the two-device allowance, the Software activates and then periodically renews a technical activation lease with our activation service at querywell.app. For this we process: the operator email address assigned to your seat (used to send a one-time activation code); a random Ed25519 device public key that the Software generates on the device — this is a random key, not a hardware fingerprint, serial number, or MAC address; the platform and CPU architecture and the app version; coarse request metadata, including an HMAC (keyed hash) of the request IP address used only for rate-limiting and abuse prevention — we do not store the raw IP; activation, renewal, and release timestamps; and audit events recording activation, renewal, device release, operator reassignment, suspension, and revocation. The corresponding device private key never leaves your OS keychain and is never transmitted to us. Activation records and audit events are retained for the life of the licence relationship so we can administer renewals, device release, reassignment, and revocation; short-lived activation-code and rate-limiting data is deleted within about 24 hours.
  • What licensing never collects. Licensing does not collect any hardware serial number, MAC address, operating-system username, or deterministic hardware fingerprint, and we never receive your Oracle Fusion credentials, your Studio query text, query results or report data, or your AI Workbench prompts. The device identifier is a random key generated on the device, not derived from your hardware.
  • Licence records. When we issue a licence or trial key, we keep a record associating that licence with the requester's name, email address and organisation, so we can administer, support and renew the licence. These records are kept for the life of the licence relationship.
  • Purchase information. When you buy a licence, we collect the contact, organisation, licence-holder, billing and order details needed to issue a receipt or invoice, meet tax obligations, and deliver and manage your licence. Direct online purchases use Stripe. Stripe collects and processes payment card details, billing addresses and any tax identifiers under the Stripe Privacy Policy; Elaman Group receives order, customer and payment-status information but does not receive full card numbers.
  • Support correspondence. If you contact info@elaman-group.com, we process what you send us to help you.

4. Legal bases (where applicable, e.g. UK/EU GDPR)

We process the limited data above to perform our contract with you (provide and license the Software), to comply with legal/tax obligations, and for our legitimate interest in operating and supporting the product.

5. Sharing

We do not sell your data. We share the limited data we process only with service providers that help us operate — principally Stripe (payment processing and receipts), Resend (transactional email, including activation codes), and Cloudflare (website, update delivery, licence activation and limited install records) — and where required by law. AI-provider transmissions are initiated directly by you under your chosen provider account as described in Section 2; they do not pass through Elaman Group infrastructure.

6. Retention

We keep order and licence records for as long as needed to provide the service and to meet legal/tax obligations, then delete or anonymise them. Local data on your device is under your control; you can clear stored tokens and local data from within the Software.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict processing. Contact info@elaman-group.com to exercise them.

8. International transfers

Our service providers may process data in other countries. Where required, we rely on appropriate safeguards for such transfers.

9. Children

The Software is a business tool and is not directed to children.

10. Changes

We may update this policy; we will post the revised version with a new effective date.

11. Contact

Elaman Group Ltd — registered in England and Wales, company no. 15708144. Registered office: 62 Galloway Drive, Manchester, M12 5QQ, United Kingdom. Email: info@elaman-group.com · Web: https://querywell.app

QueryWell

The reporting workbench for Oracle Fusion Cloud ERP. Local-first, owned outright.

by Elaman Group Ltd

Product Features Data Loader Replicate Fusion Tables Security Compare Guide Free SQL queries Pricing
Legal EULA Privacy Terms Contact

Oracle and Fusion are trademarks of Oracle Corporation. QueryWell is independent and not affiliated with, endorsed by, or sponsored by Oracle. Elaman Group Ltd is registered in England and Wales (company no. 15708144), 62 Galloway Drive, Manchester, M12 5QQ, United Kingdom.