Privacy
CH Query analyzes your query, plan, statistics, and settings in your browser. Ordinary analysis does not upload that bundle. You can share a URL-only link or explicitly choose an encrypted stored link as described below.
URL-only share links
A share link stores the analysis bundle in the URL fragment, the part after #. Browsers do not send that fragment to the website server. The bundle leaves your browser only when you copy the link and send it to someone.
Comparison URL-only links contain the exact comparison snapshot you reviewed and confirmed. CH Query warns when a URL is about 16 KiB because other apps may truncate it. Offline downloads and reports remain available as fallbacks.
Default redaction
By default, before CH Query creates a single-analysis share link—or while it prepares a comparison for review—it replaces:
- string literals with placeholders such as
'<str_1>'; - numeric literals longer than four digits with placeholders such as
<num_1>; - literal values in the SQL, plan descriptions, and settings.
The mapping is consistent within one bundle, so repeated values use the same placeholder. Database, table, and column names are not changed.
This is partial redaction, not complete sanitization. Numeric values with four or fewer digits remain. Supported text fields are SQL, plan Description fields, pipeline and syntax text, plus setting values. Other fields, including plan filter strings, may retain sensitive values.
Agent handoffs
Continue with your agent uses only your current personal result, never the homepage demo, comparison workspace, or saved investigations. It prepares the selected finding, evidence limitations, your question, and a partially redacted evidence JSON in your browser. Review judgments stay out unless you explicitly choose to include them, and are labeled as author judgments rather than evidence.
Nothing is saved, uploaded, shared, or executed when you prepare a handoff. Review the exact instructions and evidence before confirming copy or download. Identifiers, small numbers, DDL, provenance, unsupported fields, and your question can remain sensitive. Clipboard content and downloaded files cannot be revoked after you give them to an agent or recipient.
Sharing literal values
You can explicitly select “Include literal values” before copying a link. Anyone who receives that link can read those values. Exported bundle files are also not redacted automatically.
Saved investigations on this device
In Investigations, you can name a problem, keep private notes and retain a single bundle or baseline/candidate pair. Each Save requires your consent. CH Query opens its IndexedDB store only after you choose Save or Saved on this device. It does not save on import, ordinary analysis, page exit or reload. Imported investigation files start as unsaved copies.
Device saves contain plaintext SQL, evidence and private notes. Anyone with access to the same browser profile, or scripts running on this origin, may read them. Saves remain until you delete them, clear site data or the browser evicts them. They do not sync and are not backups. Delete one or all saves from Investigations. Clear current workspace removes only the in-memory draft; it does not delete saved records.
Durable investigation handoffs
Prepare investigation review excludes private notes and known capability fields, applies your chosen omissions and partial redaction, then derives reports from that outgoing evidence. Review the exact JSON and Markdown pages before confirming an export. Identifiers, small numbers, unsupported fields and author text may remain sensitive. CH Query does not scan for every possible secret.
Original private source export includes private notes and original literals without redaction or encryption. Keep it separate from reviewed handoffs. Portable JSON and Markdown files have no CH Query expiry; recipients can retain them beyond the seven-day stored-link lifetime. Local deletion cannot revoke downloaded files, clipboard content, backups, recipient copies or stored links. Investigation handoffs do not upload automatically.
Comparison links
Compare primarily opens baseline and candidate CH Query links, including URL-only #b=/#j= and encrypted #s= links. It can also reopen a whole chquery_comparison: 1 pair from one supported link. A current personal result can seed baseline; files remain an offline fallback. Opening or comparing links does not upload them.
Review comparison for sharing applies your selected omissions and optional partial literal redaction locally with prepareComparison. You may explicitly disable redaction. Review and confirm the exact full snapshot before sharing. It includes baseline, candidate, included labels, hypothesis, and correctness, but excludes private investigation notes, capabilities, and unknown optional metadata. Sample-group selection remains page-local and must be selected again after reopening when the evidence is ambiguous.
Save & share comparison then asks for separate explicit upload consent. CH Query compresses and encrypts the exact reviewed JSON bytes without applying redaction again. There is no account, cloud sync, or automatic upload.
Save & share: encrypted seven-day links
Choose Save & share and confirm an encrypted upload to save an analysis link. Ordinary analysis does not upload anything. Your browser applies the partial redaction described above, compresses the bundle, and encrypts it before sending ciphertext to CH Query's private Cloudflare R2 bucket. Identifiers, small numbers, and sensitive values in unsupported fields may remain in the encrypted bundle. Review your inputs before sharing. The server cannot inspect plaintext or verify redaction.
For a comparison, redaction and omissions happen only in the preceding comparison review. The stored-share step encrypts the exact confirmed bytes and does not redact again, including when you explicitly disabled redaction.
The stored link contains an opaque object ID and an encryption key after #. Browsers do not send the fragment or key in the API request. Anyone with the complete link can decrypt the bundle, and anyone you send it to can keep a copy. Keep the separate deletion token private; it is not part of the share link.
No file is needed to save or reopen a link. You can delete a share from the page that created it. To delete after leaving, expand Optional: delete before expiry and save a private deletion receipt. CH Query does not persist the receipt in browser storage. To use a saved receipt, open Save & share, choose Delete a stored share, and load the receipt file. The receipt can delete that share but cannot decrypt it. If you lose it, wait for expiry.
Stored links expire after seven days. The API then refuses reads, even if Cloudflare has not yet physically deleted the object. Bucket lifecycle deletion is eventual, typically within 24 hours after storage expiry and sometimes longer. A successful delete removes the stored object from service, but cannot erase copies already downloaded, browser history, or links you sent elsewhere. Without the deletion token, you cannot use the self-service delete control. Outages or an asset-only rollback can temporarily make both retrieval and deletion unavailable; the bucket lifecycle still applies.
Sharing accepts at most 8 MiB of plaintext and the R2 API accepts at most 128 KiB of encrypted data. Larger snapshots require an offline copy or additional omissions and a new review.
Request metadata and abuse checks
Cloudflare processes IP addresses and request metadata to deliver the site and API. In stored-sharing mode, CH Query uses client IP information for rate limiting, and Cloudflare Turnstile processes challenge information before accepting an upload. Encryption protects the bundle content, not request timing, object IDs, ciphertext size, or network metadata. Application observability is disabled; this does not disable Cloudflare's platform security processing or account-level analytics settings.
CH Query is an independent EXPLAIN visualizer. It is not affiliated with or endorsed by ClickHouse, Inc.