Privacy Policy

Last updated: August 5, 2026

1. Introduction

At Datadef, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered technical diagram generator service.

Important: Datadef operates with a no-cookie policy for tracking purposes. We only use essential session cookies required for authentication and service functionality. We do not use advertising cookies, analytics cookies, or any third-party tracking technologies.

2. Information We Collect

2.1 Account Information

When you create an account using email/password or authenticate through OAuth providers (Google, GitHub), we collect:

  • Email address
  • Name (as provided by the OAuth provider)
  • Profile picture URL (optional, from OAuth provider)
  • Unique identifier from the OAuth provider

2.2 Content and Project Data

We store the content you create using our Service, including:

  • Technical diagrams and canvases
  • Project metadata and settings
  • Data lineage relationships
  • Wiki documentation
  • Exported images and files

2.3 Usage Information

We collect minimal usage data necessary for service operation:

  • AI credit usage tracking
  • Subscription plan and status
  • Project creation and modification dates
  • Account activity (login timestamps)

2.4 Payment Information

Payment processing is handled by Polar.sh and Stripe. We do not directly store payment card information. We receive and store:

  • Polar.sh customer ID
  • Subscription ID and status
  • Billing period information
  • Payment success/failure notifications

3. How We Use Your Information

We use collected information exclusively for:

  • Providing and maintaining the Service
  • Managing your account and authentication
  • Processing AI diagram generation requests
  • Managing subscription billing and access
  • Enforcing AI credit limits (2 total for free users)
  • Storing and retrieving your projects and diagrams
  • Sending essential service notifications (subscription changes, billing issues)
  • Responding to support requests
  • Preventing fraud and abuse

We do not use your information for: advertising, marketing to third parties, behavioral tracking, or any purposes beyond service delivery.

4. Third-Party Services

4.1 Authentication Providers

We use OAuth 2.0 authentication through Google and GitHub, or email/password authentication. OAuth providers handle your login credentials directly. For email/password accounts, passwords are securely hashed and never stored in plain text.

4.2 AI Processing (OpenAI)

When you use AI diagram generation features, your text prompts are sent to OpenAI's API for processing. OpenAI's data processing is governed by their privacy policy. We implement the following protections:

  • Only user-provided prompts are sent to OpenAI
  • No personal identification data is included in AI requests
  • API communications are encrypted in transit
  • We do not opt into OpenAI model training with your data

4.3 Payment Processing (Polar.sh & Stripe)

Subscription payments are processed by Polar.sh, which uses Stripe for payment processing. Payment card information is handled entirely by these PCI-compliant providers and never touches our servers. We receive webhook notifications about subscription status changes.

4.4 Database Hosting

Your data is stored in a PostgreSQL database. All data is encrypted at rest and in transit.

5. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information. We share information only in these limited circumstances:

  • With your consent: When you explicitly authorize sharing (e.g., team collaboration)
  • Service providers: OpenAI (AI processing), Polar.sh/Stripe (payments), hosting providers (under strict confidentiality)
  • Legal compliance: When required by law, court order, or government regulation
  • Security and fraud prevention: To protect our rights, users, or the public from harm
  • Business transfers: In the event of a merger or acquisition (users will be notified)

6. Cookies and Tracking Technologies

No-Cookie Policy for Tracking: Datadef does not use cookies for advertising, analytics, or user tracking purposes.

Essential Cookies Only: We use only essential session cookies required for:

  • Maintaining your authenticated session (NextAuth.js)
  • CSRF protection
  • Service functionality

These cookies are automatically deleted when you log out or close your browser. We do not use any third-party analytics tools, advertising networks, or tracking pixels.

7. Data Security

We implement industry-standard security measures:

  • Data encryption in transit (HTTPS/TLS) and at rest
  • OAuth 2.0 authentication (no password storage)
  • Regular security updates and monitoring
  • Access controls and principle of least privilege
  • Secure API key management

However, no method of transmission over the internet is 100% secure. You are responsible for maintaining the security of your OAuth provider account.

8. Data Retention

We retain your information as follows:

  • Active accounts: Data retained while your account is active
  • Deleted accounts: Personal information deleted within 30 days; projects may be anonymized for 90 days
  • Subscription data: Billing records retained for 7 years for tax compliance
  • Logs: Server logs retained for 90 days maximum

9. Your Privacy Rights

You have the following rights regarding your data:

  • Access: View your profile and account information at any time
  • Correction: Update your name and settings through your profile
  • Deletion: Delete your account and personal data through profile settings
  • Export: Export your projects and diagrams as PNG/JPEG
  • Portability: Request a copy of your data in machine-readable format
  • Withdrawal: Cancel subscriptions or stop using the Service at any time

To exercise these rights, use the settings in your profile or contact us at [email protected].

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your jurisdiction. We ensure appropriate safeguards are in place for such transfers.

11. Children's Privacy

Datadef is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated via:

  • Email notification to registered users
  • Prominent notice on our website
  • Updated "Last updated" date at the top of this policy

Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: [email protected]
Website: https://datadef.io