Every password, token and key you add to a QueryFlow connection is stored by macOS itself, not by QueryFlow, and not on any server.
No credit card. 14 days. Cancel in one click.
Quick answer: QueryFlow stores connection credentials, passwords, tokens, service account keys, in the macOS Keychain on your own Mac. They never go to a QueryFlow server. Deleting a connection removes its credentials from the Keychain immediately, not just from the sidebar.
When you add a connection, whatever credential it needs, a Postgres password, a Snowflake personal access token, a BigQuery service account's JSON key, a Databricks token or service principal secret, is handed to the macOS Keychain, the same system service that already holds your Wi-Fi passwords and your Safari-saved logins. QueryFlow asks the Keychain for the credential each time it needs to connect; it doesn't keep its own separate copy sitting in a file, and it doesn't send that credential anywhere except the database it's for.
This is a structural fact about where the credential lives, not a claim about a specific encryption scheme. The Keychain is Apple's own secure storage, built into macOS, and QueryFlow relies on it rather than building or maintaining a competing vault of its own.
You won't see the Keychain directly in QueryFlow's interface; it works quietly underneath the Connections screen. The one place it becomes visible is deletion: right-click a connection, choose Delete Connection, confirm, and its stored credentials are removed from the Keychain at that moment, along with the connection itself. There's no separate "also delete my saved password" step, because the two are handled together.
Your database credentials never leave your Mac to reach a QueryFlow server, on a one-off query or on a scheduled job that fires overnight with nobody watching. If you use macOS's own Keychain Access app, you can see entries there for your QueryFlow connections the same way you'd see one for any other app that stores a credential through the system Keychain.
This also means moving to a new Mac, or reinstalling QueryFlow, doesn't carry connections over automatically unless your Keychain itself is restored (through Migration Assistant or an iCloud Keychain sync, if you use one). A fresh install with no restored Keychain means re-adding connections, the same as the migration note on switching from another SQL client.
Storing credentials in the OS-level Keychain instead of a QueryFlow-managed store or a remote server is a deliberate choice about where trust sits. It means QueryFlow itself never becomes a target worth attacking for your database passwords in bulk, because there's no central QueryFlow store of them to breach; each credential sits in the Keychain of the specific Mac that added it. It also means QueryFlow's own outage or downtime, if it ever had one, wouldn't affect your ability to reach your database directly, since the connection doesn't depend on anything beyond your Mac and the database itself.
This page is about where credentials are stored, not about what happens to your query results once you run something. Query results pass through your Mac to wherever you send them, a result view, a scheduled job's destination, or the Ask panel if you've chosen to include row data in its context. That's a separate topic from credential storage, covered on the destinations and Ask panel pages.
No. Credentials are stored in the macOS Keychain on your Mac and used locally to connect directly to your database.
They're removed from the Keychain at the same time the connection is deleted, not left behind.
Only if your Keychain itself is restored, through Migration Assistant or iCloud Keychain. A fresh install with no restored Keychain means adding connections again.
Yes, QueryFlow's stored credentials appear there like any other app's Keychain entries, since it's the same system service.
Your Mac holds the credentials. QueryFlow just asks for them when it needs to connect. Get QueryFlow →