Access & credentials
Your Airtable token, database connection, and storage keys are encrypted at rest. They are unlocked in memory when needed to run or configure a migration, and you can delete them from the dashboard at any time.
Security
AT Migrator reads your Airtable base, transforms it in memory, and writes it into the PostgreSQL database and storage you connect. We are not a host for your records.
Processed in memory
Records pass through working memory on the way into your database. We do not keep a standing copy of cell values.
Your infrastructure
PostgreSQL and attachments live where you host them. You hold the credentials.
Read-only Airtable
We never create, edit, or delete anything in your base. It can stay live as a rollback during cutover.
Data path
Out of Airtable, through working memory, into infrastructure you own. That is the whole path.
Source
Your Airtable base
Read-only. Nothing is written back.
Processing
AT Migrator
Linked records become foreign keys. Formulas become SQL.
Destination
Infrastructure you own
What we keep
We keep the setup and metrics needed to run and support a migration — not the contents of your records.
Never stored
Cell values from your base
Text, numbers, dates, and the rest pass through in memory on the way into your PostgreSQL database.
Computed formula results
We recreate formula, rollup, and lookup logic as SQL. We do not keep a copy of the outputs.
A copy of your database
AT Migrator is not a host. When a job finishes, the working data is gone.
Attachment files
They land in your storage, not on our systems.
What we keep
Account identity
Sign-in is handled by our authentication provider — typically your email and session.
Migration setup
Encrypted credentials, the tables and fields you choose, and the formula-to-SQL translations you accept so a run is repeatable.
Operational metrics
Counts of records, fields, and attachments, plus duration and success or failure. Not the values themselves.
Progress logs
Table names, counts, and errors. A failed row can mention the field and the value that could not be transformed.
How we handle it
What happens to your credentials, and the controls around every migration. Deeper diligence is a conversation, not a dump.
Your Airtable token, database connection, and storage keys are encrypted at rest. They are unlocked in memory when needed to run or configure a migration, and you can delete them from the dashboard at any time.
Sub-processors
Named at purpose level. The canonical list, including any changes, is provided with our Data Processing Addendum.
| Provider | Purpose | What it sees |
|---|---|---|
| Airtable | Source access during a migration | Reads your schema and records with the token you connect. Nothing is written back. |
| Authentication provider | Sign-in | Verifies your login and session. No migration records pass through it. |
| LLM provider | Formula Studio | Formula text and field names. Not your rows. |
| Microsoft Clarity | Usage analytics | Session and usage analytics on the marketing site and in the migration app. Not migration cell values. |
| PostHog | Product analytics | Pageviews, CTAs, and identified product events on the marketing site and migration app, plus operational API and job events. Not migrated cell values. |
| Cloud hosting and email | Running the service and transactional email | The application and support messages. Not a standing copy of your records. |
Compliance
You own the data in your Airtable base, your PostgreSQL database, and the storage you configure. AT Migrator is a limited processor of the metadata described above.
DPA
Available on request. It applies once both parties have signed it.
SOC 2
Not yet certified. We complete questionnaires and walk through how migrations work. On request we can run the migration in your environment.
Data residency
Your PostgreSQL database and storage are wherever you host them.
Report a vulnerability to security@atmigrator.com. We investigate every good-faith report and will not pursue researchers who act in good faith and avoid privacy violations, data destruction, or service disruption.
FAQ
The questions buyers ask most about how AT Migrator handles data.
Yes. It sends formula text and field names to an LLM provider to help translate formulas to SQL. It does not send your records.
Yes, available on request. It applies once both parties have signed it. Until then, the Privacy Policy and Terms describe how data is handled.
Not yet. For an enterprise review we complete your security questionnaire and walk through how migrations work. On request we can run the migration in your environment, so data stays on infrastructure you control.
Email security@atmigrator.com with details and steps to reproduce. We investigate every good-faith report and will not pursue researchers who act in good faith and avoid privacy violations or service disruption.
We will answer your questionnaire, share architecture detail, sign a DPA, and scope a migration you can verify in a sandbox before cutover.
See also our Privacy Policy and Terms of Service. Those are the binding documents.