Questions
Does my data leave my machine?
No. The MCP server runs inside your editor and listens only on 127.0.0.1. Queries go from your machine straight to your database, and QueryMoat collects no telemetry. The only network call is Pro's licence check.
Do I need Pro to be safe?
No. The read-only guard, production lock, row and time limits, prompt-injection defence and your own hide rules are all free, for good. Pro adds control (write approval, automatic masking) and proof (the audit log).
What if I want the agent to change data?
You can turn off read-only for agents in your user settings; QueryMoat asks you to confirm in a dialog first, and production databases stay locked regardless. With Pro's write approval the agent proposes each change, you see the rows it would affect, and nothing runs until you approve.
Which editors and agents does it work with?
VS Code 1.90+, Cursor, Windsurf, Antigravity, VSCodium and other VS Code–based editors, with Claude Code, Copilot and any MCP client. It runs on macOS, Windows, Linux, WSL and Dev Containers, with no native binaries.
What happens on 3 October?
Until 3 October 2026, Pro features are free for everyone to try. After that they need a licence; everything in Free keeps working exactly as before. Audit entries you recorded stay readable either way.
Is Pro a subscription?
No. Pro for individuals is a one-time payment, and it includes updates and the Pro features we add later. If it isn't right for you, ask for a refund within 14 days. Only the Team plan is billed monthly or yearly. See the refund policy.
Was this called QueryDock?
Yes. It's the same extension under a new name. Existing .querydockrc files and AI client configs keep working after you switch.