Security and data handling
DataLens AI is built to read your data, not to hold it or change it. Generated SQL is restricted to read-only queries in code, credentials are encrypted at rest, tables are queried live rather than copied, and your data is never used to train a model. The short version:
- Read-only: only SELECT queries reach your warehouse; the Google Ads integration has no write path.
- Encrypted: warehouse and ad-platform credentials are encrypted at rest (AES-256-GCM) and never sent back to the browser once saved.
- No replica: queries run live; only the conversation and up to 50 result rows per message are saved.
- No training: DataLens trains no model on your data; you choose the provider, or a local model.
- Optional pseudonymisation: hide names, emails and IDs from the AI provider entirely.
Does DataLens require write or delete access to my database?
No, and it is enforced in code rather than by policy: before any generated query reaches BigQuery, DataLens rejects it unless it is a plain SELECT (or a WITH … SELECT), and it blocks INSERT, UPDATE, DELETE, MERGE, DROP, TRUNCATE, ALTER, CREATE, GRANT and EXECUTE IMMEDIATE outright. For least privilege on your side too, connect via a service account scoped to BigQuery Data Viewer + Job User — signing in with Google instead grants DataLens the broader OAuth scope BigQuery requires to start a query job at all.
Does DataLens store or copy my database rows?
DataLens does not replicate your database. Every query runs live against your connected warehouse or ad accounts — there is no background sync and no copy of your tables. What is persisted is the conversation itself: your questions, the answers, the generated SQL, your visualization settings, and up to 50 rows per message of the result behind an answer, so a past analysis still renders when you reopen it. Deleting a conversation removes it. The Privacy page has the full retention disclosure.
Where and how are my API keys and database credentials stored?
All credentials (database service account keys, OAuth tokens, and LLM API keys) are encrypted at rest using industry-standard AES-256-GCM encryption. Credentials are only decrypted temporarily in memory during server-side query execution and are never logged, exposed to client browsers, or shared with third parties.
Is our proprietary company data used to train AI models?
DataLens does not train any model on your data, and does not share it with anyone but the AI provider you pick. That provider receives the messages in the turn you send — that is what generates the answer — and its own API terms govern retention and training from there. Rather than ask you to take a vendor contract on trust, DataLens gives you a switch that removes the question: turn on Hide identifying values (Settings → Privacy) and the identifying text never reaches the provider at all. You can also bring your own provider key, or point DataLens at a local OpenAI-compatible endpoint, so your data only goes where you have already contracted for it.
Can I stop the AI provider from seeing customer names, emails and IDs at all?
Yes — Settings → Privacy → "Hide identifying values from the model". With it on, DataLens swaps every identifying value for a stable placeholder on this server, just before the request leaves for the provider, and swaps it back the moment the answer returns. The provider sees DLX_A_7K2M9QRTVX where your data says a customer name; you keep seeing the real name on screen, in charts, and in CSV/Excel exports. Because each value maps to the same placeholder every time, the model can still group, rank, join and filter on it normally — which is why this is pseudonymization rather than encryption. Numbers, dates and platform vocabulary (status, country, device, and so on) are sent unchanged, so every figure stays exact. It is off by default and applies from the moment you switch it on; you can also force any individual column to plain or hidden.
Can I run a local open-source LLM (like Ollama or vLLM)?
Yes. For teams with strict air-gapped security or compliance requirements, DataLens supports connecting to custom OpenAI-compatible local endpoints (such as Ollama or vLLM running on your private VPC hardware).
How does DataLens prevent unexpected cloud database bills?
Cloud warehouses (like BigQuery) bill by bytes scanned. DataLens performs dry-run estimations before executing queries to surface the exact data volume and estimated cost in advance. You can also configure hard byte-scan limits to prevent accidental full-table scans.
Can DataLens change my ad campaigns?
Not when it is answering questions. The Google Ads integration only sends read-only GAQL search queries and contains no mutate call, so it cannot change bids, budgets, keywords or ads. Meta Ads analysis tools only read. A separate Ads Launcher, available to allow-listed accounts only, can create or edit Meta ads — and every change it makes must first be approved by a person who sees exactly what will be written.
Who can see a shared analysis?
Share links are read-only snapshots of a conversation. API keys and credentials are stripped from the snapshot, viewers cannot run new queries, and shared pages are excluded from search engines.
The full retention disclosure is in the privacy policy. Security questions or a responsible-disclosure report: contact.datalensai@gmail.com.
Try it on your own data
Sign in with Google to start a 7-day free trial in your own private project — no credit card. Bring your own model key (or request managed models), connect a source, and every answer arrives with its SQL.
Last updated October 3, 2026.