1. When AI processing happens
AI processing happens only when you request diagram generation, revision, or an AI chat response. The request may include your prompt, relevant current Mermaid code, diagram type, theme, and the limited conversation history needed for a follow-up request.
2. External provider
Requests are sent through OpenRouter and approved model providers. OpenRouter routes requests to the selected model provider. The model and provider can change as the service evolves, so we use only production endpoints whose current policy supports the safeguards described here.
Production requests require OpenRouter Zero Data Retention (ZDR) routing. If no eligible endpoint is available, the request fails rather than being routed to an endpoint that does not meet this requirement. OpenRouter may retain request metadata such as token counts and latency even when prompt and response content is not retained.
3. Retention and training
Mermaid Studio does not intentionally retain raw prompts, conversation history, or generated responses in its application database or routine application logs. Requests are handled temporarily to complete the generation. OpenRouter request metadata, such as token counts and latency, may be retained for operations; production requests are restricted to ZDR endpoints.
Mermaid Studio does not use prompts or outputs to train its own models. Production requests use OpenRouter ZDR routing, and OpenRouter input/output logging and product-improvement use must remain disabled. Model-provider training follows the selected endpoint's current policy; requests are not sent when ZDR or no-training cannot be verified.
We do not use AI prompts or outputs to improve or train Mermaid Studio's own models. We also do not intentionally put raw prompt or response content into application logs, Sentry events, analytics, quota records, or billing records. Limited metadata may be retained for quota enforcement, abuse prevention, reliability, and billing operations under the retention periods in the Privacy policy.
4. User responsibilities
Do not submit passwords, API keys, access tokens, personal secrets, confidential business information, regulated data, or information you are not authorized to send to an external AI provider. AI output can be inaccurate, incomplete, or unsafe. Review and test it before relying on it or sharing it with others.
5. AI-assisted output label
The service uses the label “AI-assisted output; review before use” in the editor and, where the project metadata is retained, in saved projects, public shares, and SVG/PNG exports. Editing an AI result does not guarantee that every downstream copy will retain the label, so users should preserve the disclosure when distributing an AI-assisted diagram.
6. Questions and rights
For access, deletion, or questions about AI processing, use the privacy request form. This notice is part of the Privacy policy and should be read with the Terms of service.