Privacy policy

Last updated 27 September 2026. Draft for legal review: items in [brackets] must be completed before publication.

Who we are

ApexDiagram is operated by [legal entity name], [registered address]. Contact: [privacy@…]. We are the data controller for account data and the data processor for the network documentation you store.

What we collect

  • Account data: your email address, display name and a salted hash of your password. We never store the password itself.
  • Organisation data: organisation name, plan, and the roles of its members.
  • Diagram data: everything you put in a diagram: device names, hostnames, IP addresses, serial numbers, asset tags, locations, cables, documentation text, attachments and uploaded symbols. This can include personal data if you enter it (for example a workstation named after a person). You decide what goes in.
  • Audit trail: who changed what and when, including changes made through API keys. This is part of the product and is visible to every member of the organisation.
  • Session data: a signed session cookie so you stay logged in. We do not use tracking cookies or third-party analytics on the application.
  • Server logs: request logs with IP address and user agent, kept for [30] days for security and debugging.

How we use it

To provide the service: rendering your diagrams, enforcing roles and plan limits, keeping version history and the audit trail, and sending transactional email such as password resets. We do not sell data and do not use your diagrams to train models.

Third parties that may receive data

  • Hosting and database: [provider, region]. Diagram data is stored in PostgreSQL in that region.
  • AI architect (optional): when you use the architect, a summary of the current diagram (device names, types, addresses, cables) and your message are sent to Anthropic to generate the response. Anthropic’s API terms apply. Do not use the architect on diagrams you cannot share with a processor.
  • NetBox pull (optional): the NetBox URL and token you enter are used for that request only and are not stored.
  • Email: [provider] for transactional mail.

Share links

A share link makes one diagram readable by anyone holding the link, without an account. Links can be given an expiry and revoked at any time from the diagram menu. Treat them like a password to that diagram.

Retention

Diagrams, versions, attachments and the audit trail are kept while the organisation exists. Deleting a diagram deletes its versions, attachments, share links and drafts. Deleting an organisation deletes everything in it. Backups are retained for [30] days and then overwritten. You can export any diagram as JSON or YAML at any time.

Your rights

Depending on where you live you may have rights to access, correct, export, restrict or delete your personal data, and to complain to a supervisory authority. Write to [privacy@…] and we will respond within [30] days. Owners can delete their organisation from Settings.

Security

Passwords are hashed with bcrypt, API keys are stored only as SHA-256 hashes, all traffic is over TLS, and every database query is scoped to your organisation. Uploaded SVG symbols are sanitised before display. Report security issues to [security@…].

Children

The service is not directed at children under 16 and we do not knowingly collect their data. Student use is expected to be through an institution or with a guardian.

Changes

We will post changes here and update the date above. Material changes will be announced in the app or by email.