Legal
Privacy Policy
How Schema Canvas handles personal data. In short: we collect the minimum needed to run an account-based service, we set no advertising or analytics cookies, we never sell your data, and database credentials you supply are used once and never stored.
1. Who is responsible for your data
For the hosted service, the data controller is Red Castle Technology Ltd., 51 Bracken Road, Sandyford, Dublin D18 CV48, Ireland, registered in Ireland under number 693781. Contact us about privacy at hello@schemacanvas.com.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address, display name, and a salted hash of your password. We never store your password itself. | You, at registration |
| Content | Schemas, diagrams, layouts, version history, comments, change proposals, workspace and membership records. | You, as you use the service |
| Sharing data | Share link tokens, and the diagram each points to. | You, when you create a link |
| Integration data | API token names and hashes, webhook URLs and signing secrets. | You, when you configure them |
| Technical data | IP address, request times and paths, browser user-agent, and error diagnostics recorded in server logs. | Automatically, when you use the service |
| Security data | Failed sign-in counts and lockout state, and rate-limiting counters keyed to your account or IP address. | Automatically |
We do not collect special category data, and we ask you not to put it into schemas or comments. We do not knowingly collect data from children.
3. What we deliberately do not keep
- Database connection strings. When you connect the service to a database, the connection string is used for that single request and is then discarded. It is not written to our database and is deliberately excluded from our logs.
- Your password. Only a salted hash is stored, using a standard slow hashing algorithm.
- Raw API tokens and webhook secrets. Only a hash is stored for tokens, which is why a token can be shown to you exactly once.
- Advertising and analytics profiles. We run no advertising, no third-party analytics, and no cross-site tracking.
4. Cookies
We use three cookies, all strictly necessary to operate a signed-in session. We set no advertising, analytics or tracking cookies, which is why you are not asked to consent to any.
| Cookie | Purpose | Notes |
|---|---|---|
sc_at | Keeps you signed in between requests. | HttpOnly — unreadable to scripts in the page. |
sc_rt | Renews your session without making you sign in again. | HttpOnly, and limited to the sign-in endpoints. |
sc_csrf | Protects against cross-site request forgery. | Readable by the app so it can be echoed back in a header. |
The playground also stores a draft diagram in your browser's local storage. That never leaves your device and is not sent to us.
5. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account, storing and displaying your content, and providing the features you use. | Performance of our contract with you |
| Keeping the service secure: rate limiting, account lockout, detecting and investigating abuse, and keeping server logs. | Our legitimate interest in protecting the service and its users |
| Fixing faults, diagnosing errors, and improving reliability and features. | Our legitimate interest in running and improving the service |
| Sending service messages about your account, security or significant changes. | Performance of our contract, or our legitimate interest |
| Meeting legal obligations and dealing with legal claims. | Compliance with a legal obligation, or our legitimate interest |
We do not use your content to train machine learning models, and we do not carry out automated decision-making that produces legal effects for you.
6. The AI assistant
The AI assistant is optional and only runs when you send it a message. When you do, your current schema and the messages in that conversation are transmitted to our AI provider, Anthropic, PBC, which processes them on our behalf to generate a reply. Conversations are not stored with your diagram; closing the editor discards them.
7. Who else processes your data
We do not sell your personal data and we do not share it for anyone else's marketing. We share it only with:
- Our hosting and infrastructure provider (Gravelines (GRA) - France), which stores and serves the service on our behalf.
- Anthropic, PBC , only if you use the AI assistant, and only the data described in section 6.
- Our email delivery provider (Zoho Europe), which sends service messages on our behalf — account confirmation, password resets and workspace invitations. It receives your email address and the contents of those messages. We do not send marketing email.
- Endpoints you nominate , when you configure a webhook — we send event data to the address you choose.
- Anyone you share with , when you create a share link, add a workspace member, or embed a diagram.
- Professional advisers, authorities or an acquirer , where we are legally required to disclose, need to establish or defend legal claims, or in connection with a sale or reorganisation of our business.
8. International transfers
Your data may be processed in countries other than your own, including outside the UK and European Economic Area. Where that happens we rely on an appropriate safeguard, such as an adequacy decision or standard contractual clauses with the recipient. Contact us if you would like details of the safeguard used.
9. How long we keep it
- Account data: for as long as your account is open, and for a short period afterwards so it can be restored if closure was a mistake.
- Content, including version history: until you delete it or close your account. Deleted content may persist in routine backups for a limited period before being overwritten.
- Server and security logs: a limited retention period, normally measured in weeks to months, unless needed for an ongoing investigation.
- Records we must keep for legal or accounting reasons: for the period the law requires.
10. How we protect it
We take security seriously and design for it. Measures include:
- session tokens held in cookies that scripts on the page cannot read, so a scripting flaw cannot lift your session;
- cross-site request forgery protection on every request that changes data;
- passwords stored only as salted hashes, with account lockout after repeated failed sign-ins;
- rate limiting on sign-in and on costly operations;
- access checks on every request, so people outside a workspace cannot tell whether a diagram exists;
- restrictions preventing the database-connection and webhook features from reaching internal or private network addresses; and
- encryption in transit.
11. Your rights
Where the law gives you these rights — for example under the UK GDPR or EU GDPR — you may ask us to:
- give you a copy of the personal data we hold about you;
- correct data that is inaccurate or incomplete;
- delete your data, where there is no overriding reason for us to keep it;
- restrict or object to how we use it, including where we rely on legitimate interests;
- provide your data in a portable format — you can also export your schemas yourself at any time; and
- withdraw consent, where we relied on it.
To exercise any of these, email hello@schemacanvas.com. We will respond within the period the law allows, normally one month. You also have the right to complain to your data protection authority; in the UK that is the Information Commissioner's Office.
12. Children
The service is not intended for children. You must be at least 16, or the minimum age of digital consent where you live if that is higher. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. The effective date at the top of the page shows when it last changed, and we will take reasonable steps to tell you about significant changes.
14. Contact
Privacy questions and requests: hello@schemacanvas.com, or write to Red Castle Technology Ltd., 51 Bracken Road, Sandyford, Dublin D18 CV48, Ireland.