Legal
Privacy Policy
Last updated September 27, 2026
Who we are
OpenDiagram is an AI diagramming workspace available at opendiagram.ink. This policy covers the hosted service. OpenDiagram is also open source; if you run your own copy, you are the operator of that copy and this policy does not apply to it.
What we collect
- Account details. Your name and email address. If you sign up with a password, we store only a hash of it. If you sign in with GitHub, we request only your public profile and email address (
read:user,user:email); we never get write access to your repositories. - Your content. The prompts and chat messages you send, the diagrams and projects you create, files you upload, and public GitHub repositories you import.
- Your AI provider keys. If you bring your own key, we store it encrypted and use it only to call that provider on your behalf.
- Billing status. Payments are handled by Dodo Payments. We receive your plan and subscription status, never your card number.
- Usage and technical data. How many diagrams you create (to apply plan limits), IP address and request data for rate limiting and security, and product analytics and error reports described below.
How we use it
To run the service: generate and store your diagrams, keep you signed in, apply plan limits, process payments, send account emails (verification and password reset), prevent abuse, and fix bugs. We use aggregated analytics to understand which features work.
We do not sell your data. We do not use your content to train our own models, and we do not show you ads.
AI processing
To generate a diagram, your prompt, chat history, and relevant project content are sent to an AI model provider. By default that is Google (Gemini). If you add your own key, requests go to the provider you chose (for example OpenAI, Anthropic, or Google) under that provider's terms.
Our monitoring records only metadata about AI calls, such as the model, token counts, and latency. The text of your prompts and the model's responses is not sent to our analytics or error tracking tools.
Service providers
We share data only with the providers that run parts of the service:
- Vercel: website hosting and privacy-friendly traffic analytics
- Google Cloud: API hosting and the Gemini models
- Supabase: database
- GitHub: sign in with GitHub and importing public repositories
- Resend: account emails
- Dodo Payments: checkout, billing, and tax as merchant of record
- PostHog: product analytics
- Sentry: error monitoring
Your account and content are stored in the United States (our database is in Ohio and our API runs in Iowa). Some providers, such as the content delivery network, may process data in other countries. We may also disclose data if the law requires it.
Cookies
We use a session cookie to keep you signed in; the service does not work without it. Our analytics tools use their own cookies or local storage to count visits and feature usage.
Retention and deletion
We keep your account and content while your account is active. To delete your account and everything in it, email admin@opendiagram.ink from the address on the account and we will confirm once it is done. Billing records may be kept longer where tax law requires.
You can also ask us for a copy of your data or to correct it, using the same address.
Security
Data is encrypted in transit, provider keys are encrypted at rest, and access to production systems is limited. No system is perfectly secure, so please use a strong, unique password.
Children
OpenDiagram is not intended for children under 13, or under 16 where local law sets that age. We do not knowingly collect their data.
Changes
If we change this policy, we will update the date above. For significant changes we will also let you know by email or in the app.
Contact
Email admin@opendiagram.ink for privacy requests. For general questions you can also open an issue on GitHub; please do not post personal data there.