← Mermaid Studio

LEGAL

Privacy policy

This policy describes the information Mermaid Studio processes to provide accounts, projects, collaboration, support, and AI-assisted features.

Draft notice: this document contains launch placeholders. Replace all bracketed values and complete the provider, retention, and transfer details before publishing the service.

Effective date: [Complete before launch]

1. Controller and contact

Controller: [Complete before launch]. Privacy contact: [Complete before launch] at [Complete before launch]. Business address: [Complete before launch]. Replace the launch placeholders with the legally accurate operator information before release.

2. Information we process

  • Account and authentication data managed through Clerk, such as account identifiers and configured contact details.
  • Project data, including titles, Mermaid code, diagram type, theme, configuration, revisions, comments, members, and invite records.
  • Technical and security information generated when the service is used, such as request logs, device information, IP address, and browser data where collected by the deployed infrastructure.
  • Limited aggregate product analytics, such as diagram landing page views and clicks to editors, diagrams, or templates. These events do not include account identifiers, visitor IDs, diagram code, or private project content.
  • Guest draft and feature usage data stored in browser localStorage.
  • AI prompts, current Mermaid code, diagram type, and theme when AI generation is requested.
  • Correspondence and contact details included in support emails.

3. Purposes

We process information to authenticate users, provide and secure the editor, save and restore projects, operate collaboration and sharing, enforce feature limits, understand aggregate public-page usage, respond to support requests, diagnose failures, comply with legal obligations, and provide AI-assisted generation when you choose to use it.

4. Providers and international transfers

The deployed service may use the providers listed below. Complete each provider's country, exact data categories, transfer mechanism, and retention period before launch.

ProviderPurposeDataCountryRetention
ClerkAuthentication and account managementAccount identifiers and authentication data[Complete before launch]According to the service agreement and provider policy
OpenRouter and selected model providersAI-assisted Mermaid generationAI prompts, current Mermaid code, diagram type, and theme[Complete before launch][Complete before launch]
Web hosting and API/database infrastructureHosting, storage, security, and service operationAccount, project, revision, comment, invite, and technical log data[Complete before launch][Complete before launch]

5. Retention and deletion

Account and project data is retained while needed to provide the service or until deletion is requested, subject to legal, security, backup, and dispute-retention requirements. Define exact periods for accounts, projects, revisions, comments, invites, logs, support correspondence, and AI provider records before launch. Guest drafts remain in the user's browser until cleared or removed by the user.

6. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, or information about processing. Contact [Complete before launch]and provide enough information for us to verify and handle the request.

7. Cookies and local storage

Authentication and service features may use cookies or similar browser storage. The editor also uses localStorage for guest drafts, feature usage limits, and AI disclosure acknowledgement. Public pages send limited aggregate analytics events to measure page views and navigation choices; this implementation does not use an analytics cookie or send a visitor identifier, diagram code, or private project content. We do not use advertising technology in this build.

8. Security and changes

We use reasonable technical and organizational safeguards appropriate to the service. No online service can guarantee absolute security. We may update this policy when processing changes and will publish the revised effective date.