A new universe for your graph data.Meet Galactus DB
YOUR INFORMATION

A clear view of your data.

This describes the implemented service. The final privacy notice, retention policy and controller contact details must be supplied before public launch.

Contact form

We store your name, email address, optional company, topic and message to handle your enquiry. A notification containing these details is queued for the Galactus DB team. We use your email address to reply to you; submitting the form does not subscribe you to marketing emails.

Accounts and licences

We store your email address, a salted Argon2 password hash, account verification status, hashed session and recovery tokens, orders and licences in Galactus DB. Licence records include the licensee, instance ID, CPU count and expiry. Password resets invalidate existing sessions.

Essential cookies

galactus_session keeps you signed in for up to 24 hours. galactus_csrf protects forms for up to 24 hours. Both use HttpOnly and SameSite=Lax; production cookies also require HTTPS. Signing out revokes the current session.

Payments and email

Stripe hosts checkout and receives your email and order information when enabled. This site does not receive card details. SendGrid receives contact enquiries and account and licence notification emails when enabled. Local development defaults to simulated checkout and a file outbox; Stripe test checkout and SendGrid delivery can be selected independently.

Assets and analytics

Styles, scripts and illustrations are served by this site. There are no third-party trackers, external fonts or analytics integrations in this application. It does not log form bodies. Any hosting-provider or reverse-proxy logging must be reviewed before a public launch.

Retention

Contact enquiries, account, order and licence records persist until an operator removes them under the final retention policy. Queued emails are removed from the database after the email provider accepts them; development file emails remain in the local outbox until removed. Recovery links expire after one hour. Payment records and issuer audit records need an agreed retention period before public launch.