Q: Data Privacy Framework and privacy
I have a bunch of regulatory questions:
Do you plan to join the Data privacy framework (https://www.dataprivacyframework.gov)? Do you have timeline for that?
Do you provide a DPA?
What log files are collected if I publish an app under my own domain and a user visits the teable hosted site and interact with it (like IP-Adress , timestamp, etc.) and how long are they retained for which purposes?
If you set cookies on the teable hosted sites under my domains what are they and what are their purpose and lifetime?
Can I disable the long retention of change history?
I would be happy to get answers as I am fan of a lot of aspects of teable.
Leo_Teable
Apr 14, 2026A: Hi ts123appsumo! 👋
Great questions — we genuinely appreciate you thinking carefully about data privacy.
Data Privacy Framework: We definitely want to support frameworks like the DPF — it's on our radar. That said, over the next few months we don't expect to have enough resources to complete the related compliance work, and we're not able to provide a confirmed timeline yet since we're taking things step by step.
DPA: We don't currently offer a formal DPA. This is something we want to provide eventually, but it's in the same boat as the DPF — not on our near-term roadmap given current engineering priorities.
Log data collected: When a user visits a Teable-hosted site, we collect IP address, approximate geolocation (derived from IP), browser type, device info, operating system, language preferences, system configuration, and performance data. Retention follows a minimum-necessary principle — we retain data for the shortest period needed to fulfill legal and contractual obligations, though we don't currently specify an exact number of days.
Cookies: Teable-hosted sites use three categories of cookies: essential cookies (authentication and session management), functional cookies (user preferences), and analytics cookies (Google Analytics).
Change history retention: There's no option to disable or shorten change history retention at this time.
Our recommendation for privacy-sensitive use cases: If you need full control over logging, cookies, data retention, and compliance policies, our self-hosted deployment (Docker) is the strongest path. You own the database, manage your own infrastructure, and control all privacy-related configurations directly. Please note that the self-hosted license is purchased separately via our website and isn't included in the AppSumo deal.
We're taking these compliance topics seriously and will factor them into our longer-term planning. Thanks for your patience — and glad to hear you're a fan of what we're building! 🙏
Verified purchaser
I would be happy to get a solution as your deal expires soon. You don't have to make a promise - I just want to know what are your current thoughts about it.
Also need to know if our data is shared, viewed by them or AI but I think since its cloud and servers are in US most likely data not private
One more thing — we've been going back and forth for a while now, and it's clear you genuinely care about how products like Teable are built and how they handle things like data privacy. That kind of thoughtful, detail-oriented perspective is honestly rare and incredibly valuable to the broader community.
Verified purchaser
I think teable has great features and I would say it is probably one the of the most intuitive no code databases. Configuring lookups, rollups and conditional things - done very nice.
What I miss is an no-AI-app-builder and as an EU user it seems too complicated to comply with GDPR if personal data is involved - making it only usable for non-personal data.A DPF certificate would probably fix that.
If you'd ever be interested in our Affiliate Program — not as a sales thing, but as a way to help other users who are navigating the same questions you are make more informed decisions — we'd love to have you involved. Happy to share more details if that sounds interesting!
Verified purchaser
Yeah I’m interested to get involved. You can find contact details on tilschmidt.de.
Verified purchaser
I sent an invitation on LinkedIn.
Verified purchaser
is there at least a way to have the possibility to be hosted in EU + have the access to the data if a customer would like to make it removed . in order to try to comply to gdpr as possible
+1 for GDPR. Really hope this is something this can be added when you guys can. But for now keep up the amazing engineering, you guys are doing amazing!
Go with their self-hosted solution. That's what I have done, based in France. It removes all limits, so you have the équivalent of their highest tier for $24/monrh for 1 user. Not bad at all if you don't need more users. Else, it's too expensive, sure..