Privacy

Effective 13 September 2026

This page describes what Mycelium SQL does and does not send off the machine it runs on.

The short version

Mycelium SQL talks to exactly the bastion and the database you configured, and — only if update checks are on — to its own update feed. There is no account, no server of this app's own, and no telemetry. It does not know who is using it.

Exactly three outbound connections, all yours or user-controlled

  • Your own ssh, to the bastion you named. Mycelium SQL raises the tunnel by executing your own ssh against your own ~/.ssh/config. It never stores or reimplements a host key, a jump host, or a credential ssh already manages for you.
  • MySQL, over that tunnel. Once the forward is up, the app opens one pinned MySQL connection through it. This is the only path any statement, any query result, or any schema information ever travels.
  • Update checks, on by default. Mycelium SQL checks a fixed update feed (myceliumtools.com/sql/appcast.xml) for a newer version. This can be turned off from the app's menu. The check fetches only the feed itself — no system profile, hardware information, or usage data is sent with it. With checks off, launch makes this request zero times.

No statement, no query result, no schema name, and no credential is ever sent by any of these three connections except to the database you pointed the app at.

What is stored, and where

Everything Mycelium SQL stores lives on the machine it runs on, under~/Library/Application Support/Mycelium/sql/, outside any synced or shared folder:

  • The environments file — the targets you configured. Yours; the app rewrites it only when you add, edit or remove an account.
  • The history log — one line per executed statement, kept locally so a query you ran last week is findable. This is the one place a statement is deliberately persisted, and it never leaves the machine.
  • The runtime-state file — counts and state words only. No host, no user, no statement, no result.
  • Preferences— the two update toggles, when changed from the app's menu.
  • Passwords — one item per account per environment, in your own login Keychain, under the service com.mycelium.sql. Never in a file this app writes.

Payment

Mycelium SQL is free. There is no checkout, no account and no licence key, so there is no payment information anywhere for the app to hold.

Support

Questions about any of this can be sent through the support page, linked from the app's About window and from this site.