Privacy¶
pgNimbus is a desktop PostgreSQL client. It has no account, no cloud service and no telemetry. It sends nothing to the developer or to any third party. Everything it keeps stays on your computer, and this page lists all of it.
Last updated: 29 September 2026.
What goes over the network¶
pgNimbus opens network connections to two kinds of host, both of which you configure:
- Your PostgreSQL servers. The queries you run, the rows they return, and the catalog reads that fill the schema tree and completion.
- Your SSH jump hosts, when a profile uses an SSH tunnel.
It makes no other connection. There is no update check, no usage analytics, no automatic crash report, no remote configuration, and nothing is downloaded at run time: fonts, icons and themes are built into the app.
Two buttons open a page in your web browser, and only when you click them:
- pgNimbus on GitHub in the About box (and the macOS app menu) opens the project page.
- Report on GitHub in the crash window opens a new GitHub issue form, filled
in with the error type and message (passwords masked), the pgNimbus version,
the operating system version, and the crash log's path with your home folder
shortened to
~. Your browser sends that text to GitHub as part of the page address. Nothing is published until you submit the form yourself, and you can edit it first.
The app also talks to programs on your own computer: the OS password store, and the SSH agent when a profile signs in with it.
What your PostgreSQL server sees¶
- Your IP address, or the SSH jump host's when you use a tunnel.
- The user name and database you connect with, and your password or a proof of it, depending on the server's authentication method.
- The application name
pgNimbus, for connections made from the connection dialog. It carries no version number or other identifier. - Every statement you run.
- The statements pgNimbus runs for itself (the schema tree, completion, the
monitoring windows). Each starts with the comment
/* pgNimbus */, so it can be told apart inpg_stat_activity,pg_stat_statementsand server logs.
What an SSH jump host sees¶
Your IP address, your SSH user name and sign-in (password, key or agent
signature), the database host and port you forward to, and the SSH library's
identification string, SSH-2.0-Renci.SshNet.SshClient with its version.
What is stored on your computer¶
Everything lives in one folder:
| System | Folder |
|---|---|
| Windows | %AppData%\pgNimbus |
| macOS and Linux | ~/.config/pgNimbus, or $XDG_CONFIG_HOME/pgNimbus when that is set |
The version from the Microsoft Store can instead keep the folder in
%LocalAppData%\Packages\DmitriiShmanev.pgNimbus_5cjm84wd2pj14\LocalCache\Roaming\pgNimbus.
Which one Windows uses depends on how it runs packaged apps, so check both.
On macOS and Linux the folder and its files can be read only by your user account. On Windows they have the normal permissions of your profile folder.
| File | What it holds | Encrypted |
|---|---|---|
connections.json |
Your connection profiles: name, host, port, database, user name, SSL mode, root certificate path, colour, read-only flag, and SSH host, port, user name, sign-in method and key file path. No password. | No |
credentials/*.dpapi (Windows only) |
Saved database passwords, SSH passwords and key passphrases. See passwords. | Yes, DPAPI |
history.json |
Up to 200 statements you ran (the oldest go first, pinned ones stay): the SQL, when it ran, how long it took, the result line (row count, or the server's error message; none for a statement that held a password), and the host/database it ran on. |
No |
saved-queries.json |
The queries you saved, as you saved them. | No |
workspace.json |
The text of your open tabs, per host/database, so the next session can reopen them. |
No |
settings.json |
Your preferences, the last connection used, the paths of up to 10 recently opened .sql files, and per-database lists of excluded schemas and LISTEN channels. |
No |
completion-usage.json |
The table, column and other names you picked from completion, with counts, per host/database, so they rank higher next time. |
No |
window.json, connection-window.json |
Window size and position. | No |
known_hosts |
SSH host keys you accepted, in OpenSSH's format. | No |
logs/pgnimbus.log |
Unexpected errors: the time, the error type and message (passwords masked), and the stack trace. Kept to 1 MiB, then moved to pgnimbus.log.old. |
No |
A file that pgNimbus can't parse is renamed to <name>.corrupt-<date> and kept,
so you don't lose its contents.
Passwords¶
The passwords you save in the connection dialog never go into
connections.json or any other file in the table above.
- Windows: each password is encrypted with DPAPI for your Windows account and
written to its own file in
credentials\. pgNimbus does not use Windows Credential Manager. - macOS: the Keychain, as a password item with the service name
pgNimbus. - Linux: the Secret Service (for example GNOME Keyring) through
libsecret-1.so.0, labelled "pgNimbus connection password".
If the password store is unavailable, the connection dialog warns you and keeps the password in memory only, until the last window using that connection closes. SSH agent sign-in stores nothing.
Versions before 0.13.0 kept passwords on macOS and Linux in credentials/*.cred
files, base64-encoded but not encrypted. pgNimbus moves them into the Keychain or
the Secret Service the first time the connection dialog opens, and deletes each
file only after it has read the password back from the store. A file it could
not move stays, and the dialog shows a warning with the count.
Masking of passwords in SQL¶
Before a statement goes into history.json or workspace.json, pgNimbus
replaces passwords it recognizes with '<redacted>'::redacted: PASSWORD '…'
in CREATE ROLE and ALTER ROLE (also inside a DO block, an EXECUTE string
or a comment), password=… in a connection string, and user:password@ in a
URI. The crash log masks error messages the same way. When a statement held a
password, its history entry keeps no result line, because the server's error
message can quote part of the statement where masking can't find it. Masking
misses a secret that is not labelled as one, such as a key passed to
pgp_sym_encrypt, and it does not apply to saved queries. Everything else in
your SQL, such as an email address in a WHERE clause, is stored as you
typed it. Where your password goes
has the details.
Files you create yourself¶
Exports, saved plans and .sql files go only where you choose in the save
dialog.
Clipboard¶
Copying puts text on the system clipboard, where clipboard history and clipboard managers can keep it. The connection dialog's copy button leaves the password out. Copy With Password (right-click that button) marks the text so that Windows clipboard history and cloud clipboard, and macOS and KDE clipboard managers that honor the markers, don't keep it, and clears the clipboard after 30 seconds if it still holds that text.
Turning off history¶
Turn off Record query history in Settings, on the General tab. Statements you run after that are not written anywhere. To remove entries already recorded, right-click the history list and choose Clear History. Pinned entries survive that, so unpin them first.
Deleting your data¶
Uninstalling pgNimbus does not remove your data. To remove it:
- In the connection dialog, right-click each profile and choose Delete. This also deletes its saved passwords from the Keychain or the Secret Service.
- Quit pgNimbus and delete the folder listed above. On Windows, the saved passwords are inside it.
Where you get pgNimbus¶
The Microsoft Store and WinGet install through Microsoft, and the other downloads come from GitHub Releases. Those services handle the download under their own privacy terms. The Microsoft Store can share aggregate install and crash numbers with the developer in Partner Center, based on your Windows diagnostic data settings. They contain nothing from your databases.
Building from source¶
When you build pgNimbus yourself, Avalonia's build tooling
(Avalonia.BuildServices) sends anonymous build statistics to Avalonia, and the
.NET SDK sends its own usage data to Microsoft unless DOTNET_CLI_TELEMETRY_OPTOUT
is set. Both run on the build machine only. Neither is part of the app.
Checking this¶
pgNimbus is open source under the MIT license. The code behind every statement on this page is at https://github.com/Shman4ik/pgNimbus.
Contact¶
Questions and concerns: https://github.com/Shman4ik/pgNimbus/issues. For a security problem, use private vulnerability reporting instead.