1. Controller and scope
Controller: Youjin SaaS. Representative: Youjin Jung. Privacy contact: Youjin Jung at [email protected]. Business address: 58-5, Yangjae-daero 87-gil (Seongnae-dong), Gangdong-gu, Seoul, Republic of Korea. Registration/tax identifier: 3110978060. Supported regions: Worldwide, except where applicable law, sanctions, provider availability, or technical restrictions limit access.
This policy applies to the Mermaid Studio website, editor, account features, saved projects, collaboration, public sharing, support requests, and AI-assisted generation worldwide, subject to applicable law, provider availability, and any future regional restrictions. If a regional notice gives a person greater rights, that regional notice controls for that person.
2. Information we process
- Account and authentication data managed through Clerk, such as account identifiers and configured contact details.
- Project data, including titles, Mermaid code, diagram type, theme, configuration, revisions, comments, members, and invite records.
- Technical and security information, such as request logs, device information, IP address, browser data, challenge results, and abuse-prevention fingerprints where collected.
- Limited aggregate product analytics, such as public-page views and navigation events. These events are designed not to include account identifiers, visitor IDs, diagram code, or private project content.
- Guest drafts, theme choices, feature usage limits, and AI disclosure state stored in browser storage.
- AI prompts, relevant Mermaid code, diagram type, and theme when AI generation is requested.
- Names, email addresses, messages, and related metadata submitted through support or privacy-request forms.
- Billing and transaction metadata if paid plans are enabled.
3. Purposes and legal bases
We process information to authenticate users, provide and secure the editor, save and restore projects, operate collaboration and sharing, enforce feature limits, prevent abuse, measure aggregate product usage, answer support and privacy requests, diagnose failures, comply with legal obligations, and provide AI-assisted generation when a user requests it.
Where a regional law requires a legal basis, the applicable basis may include performance of a contract for accounts, projects, collaboration, and requested AI features; compliance with a legal obligation; legitimate interests for security, abuse prevention, support, and service reliability; or consent for non-essential analytics and similar technologies. Where consent is used, it can be withdrawn through the available preference controls.
4. Providers and international transfers
We use the providers listed below for the purposes shown. Some providers may act as an independent controller for their own account, payment, tax, or security records in addition to processing information for us. Current vendor terms and subprocessor lists may change; material changes will be reflected in this notice or the linked vendor information.
| Provider | Role | Purpose | Data | Country | Transfer | Subprocessors | Retention |
|---|---|---|---|---|---|---|---|
| Clerk | Processor for service data; independent controller for its own account information where stated in its terms | Authentication and account management | Account identifiers and authentication data | United States and other countries in Clerk's current processing and subprocessor locations | Clerk DPA, applicable Standard Contractual Clauses or adequacy decision, and other lawful safeguards where required | Clerk's current list: https://clerk.com/legal/subprocessors | While the account is active and for the period needed for security, legal obligations, and deletion/recovery procedures under the Clerk DPA and policy |
| OpenRouter and approved model providers | processor | AI-assisted Mermaid generation | AI prompts, current Mermaid code, diagram type, and theme | United States and the countries used by the selected OpenRouter model endpoints | OpenRouter and selected provider terms/DPA, applicable Standard Contractual Clauses or adequacy decision, and endpoint-level ZDR controls | OpenRouter's routed model providers; only endpoints with a documented ZDR/no-training policy are approved for production | No application retention of raw request content. OpenRouter metadata may be retained for reporting and operations; model endpoints are selected with ZDR routing and their current provider policy controls any temporary processing |
| Cloudflare Pages/R2, Dokploy, Litestream, and database infrastructure | processor | Hosting, storage, security, and service operation | Account, project, revision, comment, invite, and technical log data | Cloudflare's global network and the operator-configured API, database, and backup locations | Cloudflare DPA and applicable contractual or statutory transfer safeguards; operator-controlled hosting and backup access controls | Cloudflare subprocessors: https://www.cloudflare.com/cloudflare-subprocessors/; other infrastructure providers are limited to the configured deployment and backup services | Account and project data until deletion; security/access logs up to 30 days; rolling backups up to 30 days, subject to legal, dispute, and recovery exceptions |
| Sentry | processor | Error monitoring and service reliability | Scrubbed error events, technical metadata, and diagnostic context | United States and other Sentry processing locations selected or used for the account | Sentry DPA, applicable Standard Contractual Clauses or adequacy decision, and configured data-residency controls where available | Sentry's current list: https://sentry.io/legal/subprocessors/ | Scrubbed diagnostic events are targeted for deletion within 30 days in the service configuration; provider system and backup retention may apply according to the Sentry plan and terms |
| Cloudflare Turnstile | processor | Bot and abuse prevention | Challenge response and technical request metadata | Cloudflare's global network and processing locations used for Turnstile | Cloudflare DPA and applicable contractual or statutory transfer safeguards | Cloudflare subprocessors: https://www.cloudflare.com/cloudflare-subprocessors/ | Used for challenge validation and abuse prevention only; not copied into the application database, and otherwise retained according to Cloudflare's Turnstile and security service terms |
| Polar and payment providers (when enabled) | Merchant of Record and independent controller for payment/tax records; processor where applicable | Subscription checkout, billing, and tax administration | Billing identifiers, transaction status, and payment-related metadata | Polar and its payment providers' current processing locations, including the United States and European Union where applicable | Polar terms/DPA and applicable Standard Contractual Clauses or adequacy decision | Polar's current provider and subprocessor list: https://polar.sh/docs/merchant-of-record/introduction | Subscription and webhook metadata while needed to operate the account, resolve disputes, and administer billing; transaction and tax records for the period required by applicable law and Polar's policy |
We may transfer information to countries outside the country where a user is located. We will use an applicable adequacy decision, contractual safeguard, consent, or another lawful mechanism and will provide the information required by applicable law. Subprocessor changes will be handled as described in the final provider list and applicable contracts.
5. Retention and deletion
We retain information only for as long as needed for the disclosed purposes, legal obligations, security, dispute handling, and backup recovery. Account and active project data is retained while the account or project exists. Expired or revoked invites are retained for up to 30 days. Security and access logs are retained for up to 30 days. Aggregate analytics are retained for up to 13 months. Support and privacy requests are retained for up to 24 months after resolution. Rolling backups are retained for up to 30 days. Guest drafts and feature-limit data remain in browser storage until the user clears them or the browser removes them.
When an account is deleted, we delete or anonymize local account-linked data through the account-deletion workflow. Backups may retain restricted copies for up to 30 days while they expire or are safely replaced. Provider-held records are deleted or retained under the applicable provider terms and legal retention obligations. Records needed for legal claims, fraud prevention, tax, or dispute handling may be retained for the period required for that purpose.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal information, withdraw consent, or opt out of certain sharing. You may submit a request viathe privacy request form. We may verify your identity and will respond within the period required by the law that applies to your request.
7. Regional notices
EU/EEA and UK users may have additional rights including portability, restriction, objection, consent withdrawal, and a right to complain to a data protection authority. California users may have rights to know, delete, correct, limit certain sensitive information, and opt out of sale or sharing where the applicable threshold and definition are met. We do not currently intend to sell personal information or use it for cross-context behavioral advertising. Brazilian users may exercise rights under applicable LGPD procedures.
8. Cookies, local storage, and analytics
Authentication and service features may use cookies or similar browser storage. The editor uses localStorage for guest drafts, feature limits, and the versioned AI disclosure state. Public pages send limited aggregate analytics events as configured. We do not use advertising technology in the current build. If non-essential analytics or similar technologies are enabled in a region that requires prior consent, we will request and record that choice and provide a withdrawal path.
9. AI-assisted features
AI prompts and relevant Mermaid code may be sent to external AI providers when you request generation or revision. Provider and model: OpenRouter and approved model providers. Prompt retention: Mermaid Studio does not intentionally retain raw prompts, conversation history, or generated responses in its application database or routine application logs. Requests are handled temporarily to complete the generation. OpenRouter request metadata, such as token counts and latency, may be retained for operations; production requests are restricted to ZDR endpoints.. Provider training use: Mermaid Studio does not use prompts or outputs to train its own models. Production requests use OpenRouter ZDR routing, and OpenRouter input/output logging and product-improvement use must remain disabled. Model-provider training follows the selected endpoint's current policy; requests are not sent when ZDR or no-training cannot be verified.. AI output label: AI-assisted output; review before use.
Production requests use OpenRouter's ZDR routing requirement. Mermaid Studio does not intentionally save raw prompts, conversation history, or generated responses in its application database or routine application logs. We retain limited request metadata needed for quotas, abuse prevention, reliability, and billing. See the AI data processing noticefor the request flow and safeguards.
Do not submit passwords, access tokens, personal secrets, confidential business information, or other data you are not authorized to send to an external AI provider. AI output may be inaccurate and must be reviewed before use.
10. Public sharing and collaboration
A project marked public can be accessed by anyone with its public link and may be indexed or copied by third parties. Collaboration exposes the project data needed by invited members and commenters. Do not place secrets or personal data in a project that you intend to share publicly.
11. Children
Minimum account age: 16 years for account creation. We do not ask for a date of birth; the sign-up flow asks the person creating an account to confirm that they meet the minimum age. We do not offer a parent or legal-representative account process at this time. If we learn that an account was created by a person below the minimum age, contact us so we can review, restrict, or delete the account and related information as required.
12. Security, incidents, and changes
We use technical and organizational safeguards appropriate to the service. No online service can guarantee absolute security. If a security incident affects personal information, we will investigate, contain, document, and notify users or regulators where required by applicable law.
We may update this policy when processing, providers, regions, or legal requirements change. The version and effective date at the top of this document will be updated for material revisions.