Privacy Policy
Last updated: September 17, 2026
This policy explains how [LEGAL NAME], the operator of NativeDiagram (“we”, “us”), collects and uses personal data when you use our website, dashboard, MCP server and APIs (the “Service”). We are the data controller for this data. Contact: support@dsoou.com.
1. Data we collect
- Account data — your email address, optional display name and a securely hashed password. If you sign in with Google, we receive your Google account identifier, email address, name and profile picture URL.
- Connection data — the names of AI assistants and clients you authorize, the access tokens they use, and for API keys a hashed value, a short key prefix and when the key was last used. We never store API keys in readable form.
- Diagram content — the structure and labels your AI assistant or API client sends to create a diagram, and the generated document and preview image.
- Billing data — Paddle processes payments as our Merchant of Record. We receive your Paddle customer and subscription identifiers, plan, subscription status and billing period. We do not receive or store card or bank details.
- Technical data — IP address, browser or client type, request times and error information recorded in server logs.
- Website analytics — if you allow analytics cookies, Google Analytics collects pages visited, referring sites, approximate location, device and browser information, and events such as sign-up and checkout.
We do not receive your conversations with AI assistants — only the content the assistant sends to our tools.
2. How we use data and our legal bases
- To create and manage your account, generate diagrams, show your usage and provide support — necessary to perform our contract with you.
- To process subscriptions and enforce plan limits — performance of contract and, for records, legal obligations.
- To send service emails such as address verification, password resets and important changes — performance of contract.
- To secure the Service, prevent abuse and fix problems — our legitimate interests in operating a safe, reliable service.
- To understand aggregate usage (for example how many diagrams are created per layout) to improve the Service — our legitimate interests.
- To measure website traffic and sign-up and checkout conversion with Google Analytics — your consent where required by law (including in the EEA, UK and Switzerland), otherwise our legitimate interests. You can decline or withdraw at any time.
We do not sell personal data, do not use it for advertising, and do not use your diagram content to train machine-learning models.
3. Who we share data with
- Paddle — checkout, payments, invoicing, tax and refunds as Merchant of Record, under Paddle’s privacy notice.
- Google — if you choose to sign in with Google, and as the provider of Google Analytics, under Google’s privacy policy. Google Signals and advertising features are not enabled.
- Infrastructure providers — our hosting and email delivery providers, who process data on our behalf under data processing agreements.
- AI assistants you connect — diagram results (preview image and download link) are returned to the assistant that requested them and are handled under that provider’s terms.
- Authorities — where required by law or to protect our rights and users.
4. International transfers
We and our providers may process data in countries other than where you live. Where required, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
5. Retention
- Account, connection and diagram data are kept while your account is active. When you ask us to delete your account, we delete this data within 30 days, except where we must keep it for legal reasons.
- Download links for diagrams expire after 7 days; the files remain available in your dashboard until your account is deleted.
- Server logs are rotated automatically and kept only for a limited period for security and troubleshooting.
- Google Analytics event data is retained for 2 months.
- Billing records are kept as long as tax and accounting laws require; Paddle keeps its own records as Merchant of Record.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise these rights, email support@dsoou.com; we respond within 30 days. You can also complain to your local data protection authority. California residents: we do not sell or share personal information for cross-context behavioural advertising.
7. Cookies and local storage
- Strictly necessary — cookies that keep you signed in, protect forms against cross-site request forgery and show one-time messages, and browser local storage for interface preferences and your cookie choice.
- Analytics — Google Analytics cookies (
_ga,_ga_*). In the EEA, UK and Switzerland they are only set after you accept; elsewhere they are set by default and you can decline. Change your choice anytime with Cookie settings in the site footer.
We do not use advertising cookies. Paddle’s checkout may set its own cookies when you open it.
8. Security
We use HTTPS, hash passwords and API keys, scope access tokens to the Service, and serve generated files only through expiring signed links. No method of transmission or storage is completely secure, but we work to protect your data and will notify you of a breach where required by law.
9. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their personal data.
10. Changes
We may update this policy. For material changes we will notify you by email or in the dashboard before they take effect.