Last updated: August 5, 2026
At Datadef, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered technical diagram generator service.
Important: Datadef operates with a no-cookie policy for tracking purposes. We only use essential session cookies required for authentication and service functionality. We do not use advertising cookies, analytics cookies, or any third-party tracking technologies.
When you create an account using email/password or authenticate through OAuth providers (Google, GitHub), we collect:
We store the content you create using our Service, including:
We collect minimal usage data necessary for service operation:
Payment processing is handled by Polar.sh and Stripe. We do not directly store payment card information. We receive and store:
We use collected information exclusively for:
We do not use your information for: advertising, marketing to third parties, behavioral tracking, or any purposes beyond service delivery.
We use OAuth 2.0 authentication through Google and GitHub, or email/password authentication. OAuth providers handle your login credentials directly. For email/password accounts, passwords are securely hashed and never stored in plain text.
When you use AI diagram generation features, your text prompts are sent to OpenAI's API for processing. OpenAI's data processing is governed by their privacy policy. We implement the following protections:
Subscription payments are processed by Polar.sh, which uses Stripe for payment processing. Payment card information is handled entirely by these PCI-compliant providers and never touches our servers. We receive webhook notifications about subscription status changes.
Your data is stored in a PostgreSQL database. All data is encrypted at rest and in transit.
We do not sell, rent, or trade your personal information. We share information only in these limited circumstances:
No-Cookie Policy for Tracking: Datadef does not use cookies for advertising, analytics, or user tracking purposes.
Essential Cookies Only: We use only essential session cookies required for:
These cookies are automatically deleted when you log out or close your browser. We do not use any third-party analytics tools, advertising networks, or tracking pixels.
We implement industry-standard security measures:
However, no method of transmission over the internet is 100% secure. You are responsible for maintaining the security of your OAuth provider account.
We retain your information as follows:
You have the following rights regarding your data:
To exercise these rights, use the settings in your profile or contact us at [email protected].
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your jurisdiction. We ensure appropriate safeguards are in place for such transfers.
Datadef is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated via:
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Website: https://datadef.io