Effective date: [Complete before launch]
1. Controller and contact
Controller: [Complete before launch]. Privacy contact: [Complete before launch] at [Complete before launch]. Business address: [Complete before launch]. Replace the launch placeholders with the legally accurate operator information before release.
2. Information we process
- Account and authentication data managed through Clerk, such as account identifiers and configured contact details.
- Project data, including titles, Mermaid code, diagram type, theme, configuration, revisions, comments, members, and invite records.
- Technical and security information generated when the service is used, such as request logs, device information, IP address, and browser data where collected by the deployed infrastructure.
- Limited aggregate product analytics, such as diagram landing page views and clicks to editors, diagrams, or templates. These events do not include account identifiers, visitor IDs, diagram code, or private project content.
- Guest draft and feature usage data stored in browser localStorage.
- AI prompts, current Mermaid code, diagram type, and theme when AI generation is requested.
- Correspondence and contact details included in support emails.
3. Purposes
We process information to authenticate users, provide and secure the editor, save and restore projects, operate collaboration and sharing, enforce feature limits, understand aggregate public-page usage, respond to support requests, diagnose failures, comply with legal obligations, and provide AI-assisted generation when you choose to use it.
4. Providers and international transfers
The deployed service may use the providers listed below. Complete each provider's country, exact data categories, transfer mechanism, and retention period before launch.
| Provider | Purpose | Data | Country | Retention |
|---|---|---|---|---|
| Clerk | Authentication and account management | Account identifiers and authentication data | [Complete before launch] | According to the service agreement and provider policy |
| OpenRouter and selected model providers | AI-assisted Mermaid generation | AI prompts, current Mermaid code, diagram type, and theme | [Complete before launch] | [Complete before launch] |
| Web hosting and API/database infrastructure | Hosting, storage, security, and service operation | Account, project, revision, comment, invite, and technical log data | [Complete before launch] | [Complete before launch] |
5. Retention and deletion
Account and project data is retained while needed to provide the service or until deletion is requested, subject to legal, security, backup, and dispute-retention requirements. Define exact periods for accounts, projects, revisions, comments, invites, logs, support correspondence, and AI provider records before launch. Guest drafts remain in the user's browser until cleared or removed by the user.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, or information about processing. Contact [Complete before launch]and provide enough information for us to verify and handle the request.
7. Cookies and local storage
Authentication and service features may use cookies or similar browser storage. The editor also uses localStorage for guest drafts, feature usage limits, and AI disclosure acknowledgement. Public pages send limited aggregate analytics events to measure page views and navigation choices; this implementation does not use an analytics cookie or send a visitor identifier, diagram code, or private project content. We do not use advertising technology in this build.
8. Security and changes
We use reasonable technical and organizational safeguards appropriate to the service. No online service can guarantee absolute security. We may update this policy when processing changes and will publish the revised effective date.