FAQ
Answers to common questions about where your data is held, who can see it, AI and privacy, the trial, billing, and closing a workspace.
Where an answer depends on a policy, this page says what sanda's privacy policy and terms of service say, and links to them. If the two ever differ from this page, the policy and the terms are the ones that apply.
Your data
Where is my data held?
Your warehouse and the data you sync or upload into it are held in your workspace's data region, which you choose when you sign up and which does not change afterwards. Workspaces can be created in Australia (Sydney). sanda's own database (your definitions, reports, schedules, settings and chat history) is held in Sydney, Australia.
Some work happens outside Australia: AI features send the part of your data a question needs to an AI model, and sanda search, if you switch it on, sends indexed text to an embedding model in the United States. How sanda works lists exactly what leaves and when.
What kind of database is my warehouse?
A dedicated PostgreSQL database that belongs to your workspace alone, provisioned, tuned and run for you. PostgreSQL is an open standard, so nothing in your warehouse is proprietary. See warehouse.
Can I take my data with me?
Yes. Because your warehouse is standard PostgreSQL, a full copy is a database rather than a proprietary file. Email hello@sanda-os.com.au and sanda will hand you a PostgreSQL dump of the whole workspace. Ask before a closed workspace's read-only period ends, because the data is destroyed after it.
You can also read your data in Excel or Power BI through the feed under Settings · Integrations, and export a report as a PDF from its more menu. See export.
Who can see my data?
- People in your workspace, according to their role. Owners and admins can do everything the console offers. Read-only members can open every page and ask every question but change nothing. Readers see only the reports published to them on the reports portal, and can be limited to their own rows.
- Anyone you share a link with. A public report link is the whole credential, so anyone holding it can read that report. You can set an expiry and revoke it.
- Other workspaces cannot. Each workspace has its own database and its own credentials.
- sanda's team, within limits. The privacy policy says access to production is limited to the people who operate it, and is logged. It also says sanda's admin tools sit behind a separate sign-in, cannot read your chat history or query your warehouse, and that there is no feature that lets staff sign in as you.
Does sanda sell or share my data?
No. Nobody buys it and nobody is sold it. Your data reaches a third party only through the service providers that run parts of sanda, who do not use it for anything of their own, and in a few limited cases: professional advisers under a duty of confidence, a sale of the business, or a valid legal demand. See the privacy policy.
AI and privacy
Does sanda use my data to train AI?
No. The privacy policy says sanda does not mine your data or use it to train anything. It also says every AI model sanda uses is called on a zero-data-retention basis: what is sent is used to answer the request and then discarded, and it is not stored by the provider or used to train anything. Your chat history is never mined or used for training either.
What does an AI model see?
Depending on the feature, a request can carry your question and recent messages, the names of your tables and columns, your definitions, a small sample of real values from your columns, the rows a query returns, and your name, role and workspace name.
Columns whose names suggest secrets, such as passwords, tokens, tax file numbers and card numbers, are never sampled or returned. Other columns are not filtered by content, so if a column holds personal information such as email addresses, a sample of it can be sent.
What does sanda keep from my conversations with cherry?
sanda keeps your chat history, including your questions, cherry's answers and the rows behind each answer, in its own database so you can come back to it. It belongs to your workspace, and it is deleted when you delete the conversation or close the workspace.
Can I stop sanda using AI?
Yes. An owner or admin can set the daily AI limit to 0 under Settings · Plan & budget, in Budget & alerts. sanda then makes no AI calls for the workspace. Syncs, reports and your data keep working. Raise the limit again to switch AI back on.
The trial and billing
What happens when the trial ends?
A trial runs for 7 days and comes with A$10 of free credit, and the top bar shows both. Nothing is billed during a trial, and nothing renews into a paid subscription on its own.
When the days are over, or sooner if the credit runs out first, the workspace freezes. Queries, reports, AI, syncs and scheduled runs wait, and everything in the workspace is kept. To carry on, an owner or admin presses Ask to move to an edition under Settings · Plan & budget, and the workspace continues where it stopped. If you plan to carry on, ask before the day count reaches zero. See the trial.
How much does sanda cost?
Each edition has a flat monthly platform fee: A$20, A$50 and A$200 a month for Basic, Standard and Enterprise. On top of that you pay for what you use: storage by the gigabyte-month, compute by the hour, AI by the token, and managed sync by the run. Nothing is priced per seat, report, schedule or connector. Prices are in Australian dollars. See editions.
How do I change edition?
An owner or admin opens Settings · Plan & budget. Between Basic and Standard, they press Move to Basic or Move to Standard, check what changes and confirm, and the move is made at once. A move up bills the higher fee for that whole month, and a move down bills the lower fee from the next month. For anything else (leaving a trial, Enterprise, or a fee agreed with sanda), they press Ask to move to the edition they want. That sends a request to sanda's team, who make the change, and it appears under System · Support with its status. See editions.
How do I pay?
sanda invoices monthly in arrears, by email, and you pay by direct bank transfer. It does not take card payments, so it never holds card details. See invoices.
Is there an uptime guarantee?
Not unless one is written into a separate agreement with you. The terms say sanda is not offered with one by default, and that maintenance needing downtime is announced in advance where sanda can foresee it.
Your workspace
How do I close a workspace?
Only an owner can. You can close it, which keeps it readable for a while, or delete it at once.
-
Open the section. Go to Settings · Workspace and scroll to the foot of the tab. The heading reads Close this workspace.
-
Close it. Optionally say why you are leaving, type the workspace's short name to confirm, and press Close workspace.
The workspace becomes read-only for 90 days. Every page still opens, every question can still be asked, and you can take an export. After that, the warehouse and everything in it are destroyed, and backups are overwritten within a further 30 days. An owner can reopen it at any point before then, and everything comes back exactly as it was.
-
Or delete it now. In the same section, type the short name again and press Delete workspace now. This skips the 90 days: the warehouse, connections, semantic fluid and reports are destroyed at once, every member loses access, and nothing can be exported afterwards. Anyone whose only workspace it was loses their sanda account too, so their email can sign up again. Anything used since your last invoice is still billed, and nothing is billed on a trial.
Invoices and the record that you accepted the terms are kept after closing, because the law requires it. They hold no business data. See close or delete a workspace.
Can I have more than one workspace?
An email address belongs to one workspace. A second trial for the same address is not created, and an address that already has a workspace cannot be invited into another.
How do I add my team?
Go to Settings · Team and press Invite someone. You choose a role for each person: admin, read-only, or reader for the reports portal only. See members and roles.
Why am I asked to accept the privacy policy again?
Every person reads and accepts the privacy policy once, and again whenever it changes. sanda tells you in the console and asks you to accept the new version before you carry on.
Using sanda
Do I need to write SQL?
No. cherry composes and runs the queries, and shows you the query behind each answer. Owners and admins can also run their own SQL in the SQL shell if they want to. See ask cherry.
How do I know an answer is right?
Check the query cherry shows, and compare one or two answers with a figure you already trust. The terms say it plainly: sanda is a very good analyst and it is not a person. The numbers come from your data, but a figure that will be relied on for a decision should be one somebody has looked at.
Which systems can I connect?
See the connector catalogue. You can also load a CSV file directly, which is covered in upload a CSV.
Can my own AI assistant use sanda?
Yes. MCP lets assistants such as Claude read your semantic fluid with the permissions you grant, and it is included on every edition. The Excel and Power BI feed works on every edition. See MCP and OData.
Related pages
Something unclear or out of date? Tell us, and we will fix the page.