Privacy Policy
Last updated July 30, 2026
1. Overview
This Privacy Policy describes how Graphsky handles personal information when you use graphsky.app (the "Service"). It applies to account holders and visitors alike. The data controller for the Service is Graphsky Inc., which you can reach at hello@graphsky.app.
2. Information We Collect
- Account data — when you register with email and password, your name, email address, and a salted password hash, managed by our authentication system. We never store your password in plain text.
- GitHub / Google sign-in data — if you sign in with a third-party provider, we receive your name, email address, and avatar from that provider to create and identify your account.
- Architecture and canvas data — the diagrams, nodes, edges, services, data flows, C4 hierarchies, and architecture content you create or import, used to build and render your canvases.
- Chat and query data — the questions, prompts, and messages you send to per-node AI chat advisors.
- Server logs — our hosting and backend providers record standard request logs (such as IP address, timestamp, and request path) to operate the Service and keep it secure.
- Product analytics — we use PostHog to understand which features people use. PostHog receives event names and their properties, page URLs, your signed-in user id, and your team id (grouped as a team). We do not send node or edge content, service names, or chat messages to PostHog — only counts and identifiers.
3. How We Use Information
- to provide, maintain, and improve the Service;
- to process architecture data through our AI provider in order to power the import, advisor, and query features you invoke (see Section 4);
- to process payments when you subscribe to a paid plan; and
- to communicate with you about the Service.
4. Sharing and Subprocessors
We do not sell personal data. We share data only with the service providers that help us run the Service. Providers marked planned are not active yet and receive no data until the related feature launches.
- Convex — backend, database, and authentication hosting (current).
- Cloudflare — application hosting and content delivery (current).
- GitHub — OAuth sign-in and repository import (current).
- Vercel — AI Gateway that routes AI requests to the model provider (current).
- Anthropic — AI model provider that processes your data to fulfill the import, advisor, and query requests you make (current).
- PostHog — product analytics that helps us understand which features people use (current).
- Stripe — payment processing (planned; activated when paid plans launch).
- Resend — transactional email (planned).
- Google — OAuth sign-in (planned).
5. Data Retention and Deletion
We retain your data while your account is active. If you delete your account, we delete your personal information and canvas data, except where retention is required by law. You can also request deletion by emailing hello@graphsky.app.
6. Cookies
We use essential and analytics cookies. See our Cookie Policy for details.
7. Security
We take reasonable technical and organizational measures to protect your data. See our Security overview for details.
8. Your Rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information (for example under the GDPR or CCPA). To exercise these rights, email hello@graphsky.app.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be announced with reasonable notice; the "Last updated" date above reflects the current version.
11. Contact
Privacy questions? Email hello@graphsky.app.