SchemaCanvasBack to home

Legal

Privacy Policy

Version 1.0 · Effective 7 August 2026

How Schema Canvas handles personal data. In short: we collect the minimum needed to run an account-based service, we set no advertising or analytics cookies, we never sell your data, and database credentials you supply are used once and never stored.

Contents

  1. 1. Who is responsible for your data
  2. 2. What we collect
  3. 3. What we deliberately do not keep
  4. 4. Cookies
  5. 5. Why we use it, and our legal basis
  6. 6. The AI assistant
  7. 7. Who else processes your data
  8. 8. International transfers
  9. 9. How long we keep it
  10. 10. How we protect it
  11. 11. Your rights
  12. 12. Children
  13. 13. Changes to this policy
  14. 14. Contact

1. Who is responsible for your data

For the hosted service, the data controller is Red Castle Technology Ltd., 51 Bracken Road, Sandyford, Dublin D18 CV48, Ireland, registered in Ireland under number 693781. Contact us about privacy at hello@schemacanvas.com.

If your organisation runs Schema Canvas on its own infrastructure, your organisation is the controller of everything in that deployment and this policy does not apply to it. Ask your administrator for their policy.

2. What we collect

CategoryWhat it includesWhere it comes from
Account data Email address, display name, and a salted hash of your password. We never store your password itself. You, at registration
Content Schemas, diagrams, layouts, version history, comments, change proposals, workspace and membership records. You, as you use the service
Sharing data Share link tokens, and the diagram each points to. You, when you create a link
Integration data API token names and hashes, webhook URLs and signing secrets. You, when you configure them
Technical data IP address, request times and paths, browser user-agent, and error diagnostics recorded in server logs. Automatically, when you use the service
Security data Failed sign-in counts and lockout state, and rate-limiting counters keyed to your account or IP address. Automatically

We do not collect special category data, and we ask you not to put it into schemas or comments. We do not knowingly collect data from children.

3. What we deliberately do not keep

  • Database connection strings. When you connect the service to a database, the connection string is used for that single request and is then discarded. It is not written to our database and is deliberately excluded from our logs.
  • Your password. Only a salted hash is stored, using a standard slow hashing algorithm.
  • Raw API tokens and webhook secrets. Only a hash is stored for tokens, which is why a token can be shown to you exactly once.
  • Advertising and analytics profiles. We run no advertising, no third-party analytics, and no cross-site tracking.

4. Cookies

We use three cookies, all strictly necessary to operate a signed-in session. We set no advertising, analytics or tracking cookies, which is why you are not asked to consent to any.

CookiePurposeNotes
sc_at Keeps you signed in between requests. HttpOnly — unreadable to scripts in the page.
sc_rt Renews your session without making you sign in again. HttpOnly, and limited to the sign-in endpoints.
sc_csrf Protects against cross-site request forgery. Readable by the app so it can be echoed back in a header.

The playground also stores a draft diagram in your browser's local storage. That never leaves your device and is not sent to us.

5. Why we use it, and our legal basis

PurposeLegal basis
Creating and running your account, storing and displaying your content, and providing the features you use. Performance of our contract with you
Keeping the service secure: rate limiting, account lockout, detecting and investigating abuse, and keeping server logs. Our legitimate interest in protecting the service and its users
Fixing faults, diagnosing errors, and improving reliability and features. Our legitimate interest in running and improving the service
Sending service messages about your account, security or significant changes. Performance of our contract, or our legitimate interest
Meeting legal obligations and dealing with legal claims. Compliance with a legal obligation, or our legitimate interest

We do not use your content to train machine learning models, and we do not carry out automated decision-making that produces legal effects for you.

6. The AI assistant

The AI assistant is optional and only runs when you send it a message. When you do, your current schema and the messages in that conversation are transmitted to our AI provider, Anthropic, PBC, which processes them on our behalf to generate a reply. Conversations are not stored with your diagram; closing the editor discards them.

Do not put personal data, credentials or anything confidential into a schema or a message you send to the assistant. If you would rather nothing was transmitted to a third party, do not use the feature — every other part of the service works without it.

7. Who else processes your data

We do not sell your personal data and we do not share it for anyone else's marketing. We share it only with:

  • Our hosting and infrastructure provider (Gravelines (GRA) - France), which stores and serves the service on our behalf.
  • Anthropic, PBC , only if you use the AI assistant, and only the data described in section 6.
  • Our email delivery provider (Zoho Europe), which sends service messages on our behalf — account confirmation, password resets and workspace invitations. It receives your email address and the contents of those messages. We do not send marketing email.
  • Endpoints you nominate , when you configure a webhook — we send event data to the address you choose.
  • Anyone you share with , when you create a share link, add a workspace member, or embed a diagram.
  • Professional advisers, authorities or an acquirer , where we are legally required to disclose, need to establish or defend legal claims, or in connection with a sale or reorganisation of our business.

8. International transfers

Your data may be processed in countries other than your own, including outside the UK and European Economic Area. Where that happens we rely on an appropriate safeguard, such as an adequacy decision or standard contractual clauses with the recipient. Contact us if you would like details of the safeguard used.

9. How long we keep it

  • Account data: for as long as your account is open, and for a short period afterwards so it can be restored if closure was a mistake.
  • Content, including version history: until you delete it or close your account. Deleted content may persist in routine backups for a limited period before being overwritten.
  • Server and security logs: a limited retention period, normally measured in weeks to months, unless needed for an ongoing investigation.
  • Records we must keep for legal or accounting reasons: for the period the law requires.

10. How we protect it

We take security seriously and design for it. Measures include:

  • session tokens held in cookies that scripts on the page cannot read, so a scripting flaw cannot lift your session;
  • cross-site request forgery protection on every request that changes data;
  • passwords stored only as salted hashes, with account lockout after repeated failed sign-ins;
  • rate limiting on sign-in and on costly operations;
  • access checks on every request, so people outside a workspace cannot tell whether a diagram exists;
  • restrictions preventing the database-connection and webhook features from reaching internal or private network addresses; and
  • encryption in transit.

No service can promise perfect security. You are responsible for choosing a strong, unique password, for keeping your API tokens secret, and for being deliberate about what you share.

11. Your rights

Where the law gives you these rights — for example under the UK GDPR or EU GDPR — you may ask us to:

  • give you a copy of the personal data we hold about you;
  • correct data that is inaccurate or incomplete;
  • delete your data, where there is no overriding reason for us to keep it;
  • restrict or object to how we use it, including where we rely on legitimate interests;
  • provide your data in a portable format — you can also export your schemas yourself at any time; and
  • withdraw consent, where we relied on it.

To exercise any of these, email hello@schemacanvas.com. We will respond within the period the law allows, normally one month. You also have the right to complain to your data protection authority; in the UK that is the Information Commissioner's Office.

12. Children

The service is not intended for children. You must be at least 16, or the minimum age of digital consent where you live if that is higher. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy. The effective date at the top of the page shows when it last changed, and we will take reasonable steps to tell you about significant changes.

14. Contact

Privacy questions and requests: hello@schemacanvas.com, or write to Red Castle Technology Ltd., 51 Bracken Road, Sandyford, Dublin D18 CV48, Ireland.

Read the Terms of Service →Back to home