Privacy Policy

Last updated: May 2026

What we collect

Account data: Email address, name, and hashed password when you sign up. OAuth profile data if you sign in with Google or GitHub.

Architecture data: The entities, relationships, and models you create or import. This is your data and we do not share it.

Usage data: Page views, feature usage, and session duration via PostHog analytics (opt-in). No architecture data is sent to PostHog.

BYOK keys: If you provide an Anthropic API key, it is encrypted at rest (AES-256-GCM) and never logged, shared, or transmitted to third parties beyond Anthropic's API.

How we use your data

To provide the Service: run queries, generate AI classifications, store your architecture models.

To improve the Service: aggregate, anonymized usage analytics (with your consent).

We do not sell your data. We do not use your architecture data to train AI models.

Where your data is stored

Account and project metadata: Neon Postgres (US or EU region, based on your selection).

Architecture graphs: Oxigraph server (hosted alongside the application).

All data is encrypted in transit (TLS) and at rest.

Your rights

Access: You can export your architecture data at any time as RDF Turtle files.

Deletion: You can delete your account and all associated data. Deletion is permanent and completed within 30 days.

Portability: Your data is stored in open standards (RDF, ArchiMate). You can export and use it in any compatible tool.

Objection: You can opt out of analytics at any time via the cookie consent banner.

Third parties

Anthropic: AI classifications are processed by Anthropic Claude. Your architecture descriptions are sent to Anthropic for classification. Anthropic does not use API inputs for training.

Stripe: Payment processing. We do not store credit card numbers.

PostHog: Analytics (opt-in). No architecture data is shared with PostHog.

Resend: Transactional emails (verification, password reset).

Contact

Privacy questions? Email [email protected].