Privacy Policy
Updated 2026-09-09
The short version
Pasting, rendering, switching themes and exporting to PNG / SVG / PDF / Word / PowerPoint all happen inside your browser. That content is not uploaded. Data leaves your device only when you choose to do one of these: sign in, save to the cloud, run an AI fix / tidy, create a share link, or buy something.
Diagramate is run by its individual developer. Contact: support@diagramate.com. The site and database run on servers outside mainland China.
When you are not signed in
Not collected: the code you paste, the diagram it renders, the files you export. They never reach our server.
Collected:
- Product analytics: an event name (such as "render succeeded" or "export PNG") plus small pieces of metadata (diagram type, theme, error type, duration), your browser's user-agent string and a timestamp. No diagram content and no IP address. We use it to see which features get used and where people hit errors.
- Access logs: as on any website, our server and content-delivery provider log IP address, time and requested path for security and troubleshooting.
- Free AI allowance counting: for anonymous AI fix / tidy calls we count the day's usage against a salted hash of your IP address (not reversible, the raw IP is not stored). Cleared after 30 days.
Accounts
- Email code sign-in: we store your email address. The code itself is stored only as a hash and is cleared after one day. Sending is rate-limited per address and per IP to prevent abuse.
- Google sign-in: we request the
openid email profilescopes and store your email address plus the display name and avatar URL Google returns (used in the interface). Both sign-in methods with the same address resolve to one account. - Sessions: your signed-in state lives in the
dgz-sessioncookie (HttpOnly). A session record holds its creation time, user-agent and a hash of the IP address, and is cleared 30 days after it expires or you sign out.
Diagrams saved to the cloud
- Uploaded only when you choose "save to cloud": the diagram's Mermaid code, its name, theme settings and version history.
- Your diagrams are yours. We use them only to give you cloud storage and cross-device access — never to train models and never for content analysis.
- Deleting moves a diagram to the trash; after 30 days it is physically deleted from the database, versions included.
- The admin pages are built so that no diagram code is ever displayed — only counts and timestamps.
- Share links exist only if you create one. You can set a password (stored as a hash), an expiry and revoke it at any time; the link follows the current cloud version.
AI fix and AI tidy
- Your current code (plus the error message when fixing) is sent to a third-party AI inference provider once, and only when you press the button. Nothing is sent on page load.
- We do not store the code that is sent. Server logs hold only length, duration and mode; the usage ledger records time, mode, success, credits spent and a hash of the IP address.
- What is sent is not used to train models.
- This site uses no image or video generation model of any kind. The AI reads text code and returns text code; every diagram you see is drawn by the Mermaid rendering engine inside your browser.
Payments
- International payments are handled by Creem as Merchant of Record, and Creem is what appears on your statement. Card numbers and payment account details go straight to Creem — they never pass through our server and we never see them.
- What we store: order number, product, amount and currency, order status, Creem's order and subscription identifiers, membership start and end dates, and your AI credit balance with its transaction history.
- Refund rules are in the Refund Policy.
Sign-in codes and necessary account notices are delivered through a third-party email provider and contain your address and the code. We do not send marketing email.
Cookies and local storage
Cookies (none are advertising cookies; there is no cross-site tracking):
dgz-session: signed-in state, HttpOnly.dgz-signed-in: lets a page know you are signed in so anonymous visitors never call the API for nothing.dgz-plan: plan hint, used to show membership-related entry points.dgz-oauth: a one-time verification value during Google sign-in, deleted as soon as it is used.
Browser local storage (stays on your device, never uploaded): the code and theme in the editor, interface preferences, the contents of the free canvas, and whether you have seen the feature tour. Clearing your browser data clears all of it.
How long we keep things
| Data | Retention |
|---|---|
| Cloud diagrams and versions | Trash on delete, physically deleted after 30 days |
| Sign-in codes | 1 day |
| Sessions | 30 days after expiry or sign-out |
| Anonymous AI allowance (IP hash) | 30 days |
| Unpaid orders | Marked expired after 24 hours |
| Order and accounting records | Kept as long as tax and accounting rules require |
| Product analytics (no personal identifiers) | Kept long-term for product statistics |
| Access logs | Per our server's and the CDN provider's own policies |
Your rights
- See and export: the account page shows your plan, credits, usage and orders; cloud diagrams can be opened in the editor and exported to your device at any time.
- Delete: delete a single diagram in the editor. To delete your whole account and its data, write to support@diagramate.com — we action it and reply within 7 business days.
- Object or complain: same address; we normally reply within 2 business days.
Children
Diagramate is not directed at children under 13 and we do not knowingly collect their information.
Changes
Changes update the date at the top of this page, and significant ones are announced in the product. Continuing to use the site means you accept the updated version.