Skip to content
Unograph
Back to website Open app

Legal

Privacy Policy

This Policy explains what personal data Unograph handles, why we use it, who receives it, and the choices available to you.

Effective July 30, 2026 Controller location: Georgia (country) Privacy contact: [email protected]

Terms Privacy Cookies Acceptable Use DPA

On this page

  1. Scope and roles
  2. Data we handle
  3. Public links
  4. Analytics and replay
  5. Purposes and legal bases
  6. Recipients
  7. International transfers
  8. Retention
  9. Security
  10. Your rights
  11. Account deletion
  12. Children
  13. Changes
  14. Contact

1. Scope and our data-protection roles

This Privacy Policy applies when you visit unograph.com, use the Unograph web application, create an account, collaborate or share content, or contact us.

The data controller for website, account, service-usage, support, and business-administration data is Grigorii Feoktistov, an individual entrepreneur registered in Georgia with identification number 306408795, who operates Unograph (“Unograph,” “we,” “us,” or “our”).

If an organisation uses Unograph to process personal data inside its diagrams, models, documentation, or other workspace content, that organisation generally decides why and how the data is used and acts as controller. Unograph processes that data on its behalf as processor. Our Data Processing Agreement governs that processing.

If your account is managed by an organisation, its administrator may control your workspace access and content. Direct questions about an organisation’s processing to that organisation first.

2. Personal data we handle

Information you provide

  • Account and profile data: email address, display name, optional avatar, account preferences, and verification status.
  • Authentication and security data: password in transit for authentication, a one-way password hash rather than the readable password, session records, email-verification and password-reset records, and optional two-factor authentication records.
  • Workspace and collaboration data: workspace membership, invitations, roles, presence, sharing permissions, and the contact details of people you invite.
  • Customer Content: diagrams, architecture models, elements, relationships, flows, descriptions, documentation, comments, version history, and other information you choose to create or upload.
  • Communications: messages, attachments, and related contact information when you request support or contact us.
  • Billing data, if paid services are introduced: billing contact, country, tax details, plan, payment status, transaction identifiers, and limited card metadata supplied by the payment provider. We do not receive the full card number or card security code.

Information generated through the Service

  • version timestamps and authorship, workspace activity, sharing status, collaboration state, and feature interactions;
  • browser and device type, operating system, language, request time, approximate network information, referring domain, and diagnostic data;
  • IP address and security logs where needed for delivery, abuse prevention, rate limiting, fraud detection, incident response, and reliability; and
  • cookie and browser-storage data described in our Cookie Policy.

Information from other services

If you choose Google sign-in, Google provides the verified email address, display name, profile image, and identifiers necessary to authenticate your account. We do not receive your Google password.

Information kept only in your browser

An anonymous draft may be stored locally until you choose cloud functionality. Theme and tutorial preferences may also remain in browser storage. Clearing browser data may remove this information, and we cannot recover a browser-only draft.

3. Public links and collaboration

When you enable an “anyone with the link” read-only view, the selected content and any personal data it contains become available to anyone who receives the URL, potentially without an account. Recipients may forward the URL or make copies outside Unograph. Do not enable public sharing for secrets, credentials, confidential information, or personal data unless you are authorised to do so.

Disabling a public link prevents future access through Unograph but does not remove copies already made by recipients or third parties. Workspace members may also see profile, presence, authorship, and activity data needed for collaboration.

4. Product analytics and Session Replay

We use PostHog’s EU service to understand which parts of Unograph are useful, diagnose usability issues, and improve the product. Analytics and Session Replay are separate, optional categories. PostHog is not initialised on this website unless you enable at least one of them.

Analytics may include pseudonymous identifiers and allowlisted events such as a page opening, navigation, a button click, a product-view change, or a workflow step. Session Replay may reproduce interactions such as clicks, scrolling, and navigation so we can investigate user-experience problems.

Sensitive authentication data is excluded. Our website analytics configuration masks input fields, disables console-log capture, removes request and response bodies and headers, sanitises routes, and is designed not to collect passwords, access tokens, secret keys, or private authentication credentials.

We disable IP-based geolocation in our PostHog configuration and do not enable advertising trackers. Analytics data is pseudonymous, not necessarily anonymous. You can accept, refuse, or later change each optional category:

5. Why we use data and our legal bases

Purpose Typical data Legal basis
Provide accounts, cloud storage, collaboration, sharing, and versions Account, workspace, Customer Content, and activity data Performance of our contract and steps you request before entering it
Authenticate users and protect the Service Credentials, sessions, IP address, device, and security logs Contract; legitimate interests in security and abuse prevention; legal obligations
Operate, troubleshoot, and support Unograph Diagnostics, service activity, and communications Contract and legitimate interests in reliable support and operations
Optional analytics and Session Replay Pseudonymous events, device data, and interaction recordings Your consent, which you can withdraw at any time
Administer paid plans if introduced Billing contact, plan, tax, and transaction metadata Contract and tax, accounting, and fraud-prevention obligations
Comply with law and protect rights Relevant account, content, transaction, or log data Legal obligations and legitimate interests in establishing or defending legal claims

Where we rely on legitimate interests, we consider the impact on your rights and do not use that basis where your interests or fundamental rights override ours. We do not sell personal data or use it for cross-context behavioural advertising.

6. Who receives data

We disclose personal data only as needed to provide and secure the Service, follow your instructions, complete a transaction, comply with law, or protect rights and safety.

Recipient Purpose Relevant location or role
Cloudflare DNS, content delivery, network performance, and security Global edge network; processor/service provider for relevant functions
Vultr Application, PostgreSQL database, storage, and backup infrastructure Configured data-centre region; support and subprocessors may operate elsewhere
PostHog Consent-based product analytics and Session Replay EU Cloud for collection and storage; provider operations and subprocessors as disclosed by PostHog
Google Optional Google OAuth authentication Google also processes your direct interaction under its own privacy terms
Stripe or the payment provider shown at checkout Payment, fraud prevention, and billing if paid features are introduced Processor and/or independent controller depending on the activity; not used for current free early access

We may also disclose relevant data to professional advisers bound by confidentiality; to a buyer or successor during a genuine financing, merger, reorganisation, or sale subject to appropriate safeguards; or to courts, regulators, and public authorities when we reasonably believe disclosure is legally required.

Other workspace members, link recipients, and the public receive data when you invite, collaborate, or enable public sharing. The current subprocessor details for Customer Content are also described in the DPA.

7. International data transfers

We operate from Georgia (country) and use providers that may process data in the European Economic Area, the United States, and other countries. Those countries may have data-protection laws different from the laws where you live.

Where a transfer safeguard is required, the mechanism for a particular transfer may include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, contractual protections with service providers, access controls, encryption in transit, and transfer-risk review. Georgian law may separately require authorisation from the State Audit Office of Georgia for certain transfers based on contractual safeguards; Standard Contractual Clauses do not replace that requirement. Our DPA describes the transfer terms for business Customer Content. Contact us for information about the mechanism applicable to a particular transfer.

8. How long we keep data

We keep personal data only for the period needed for the purposes described above, then delete or de-identify it unless a longer period is required for law, security, fraud prevention, dispute resolution, or enforcement.

Data Standard retention
Account, profile, workspace, and cloud Customer Content While the account or workspace is active; deletion from active systems normally within 30 days after a valid deletion request or closure
Protected backup copies Up to 90 days after deletion from active systems, unless recovery, security, or law requires longer isolation
Authentication and security logs Normally up to 12 months; longer only for an active incident, abuse investigation, or legal claim
Support communications Up to 3 years after the request is closed, unless a shorter period is sufficient or a dispute requires longer
PostHog analytics and Session Replay Up to 12 months, subject to shorter project settings; consent preference for 180 days
Billing and transaction records, if applicable For the period required by tax, accounting, anti-fraud, and other applicable law
Anonymous drafts and local preferences In your browser until you clear them or the browser removes them

We may retain data that has been irreversibly aggregated or de-identified because it no longer identifies an individual. Disabling a public link does not erase copies made outside our systems.

9. Security

We use technical and organisational measures designed to protect personal data, including role-based access, least-privilege controls, password hashing, secure session cookies, transport encryption, rate limiting, restricted production access, backups, logging, and incident-response procedures appropriate to the Service’s risk.

No service can guarantee absolute security. Protect your credentials, use available account-security features, limit workspace access, review public links, and contact [email protected] if you believe your account or data has been compromised.

10. Your choices and privacy rights

Depending on the law that applies, you may have the right to:

  • know whether and how we process your personal data;
  • access and receive a copy of it;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests;
  • receive portable data where the law provides that right;
  • withdraw consent at any time without affecting earlier lawful processing; and
  • complain to a competent supervisory authority.

Send a request to [email protected]. We may need to verify your identity and authority. We normally respond within the period required by applicable law. If another organisation controls the relevant Customer Content, we may refer your request to that organisation and assist it as required.

You may change optional analytics and replay consent at any time:

In Georgia, you may submit a data-protection complaint to the State Audit Office of Georgia. EEA, UK, and other residents may also complain to the authority where they live or work.

11. How to delete an account

Use any account-deletion control available in the application or email [email protected] from the address associated with your account. Tell us if you want to delete only an account, a workspace, or specific cloud content. We may ask for verification and may need workspace-owner approval for shared organisational content.

A valid deletion request removes or de-identifies applicable data from active systems within the periods above. Limited data may remain in protected backups until they expire and in restricted records where necessary for security, legal compliance, billing, or disputes.

12. Children

Unograph is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.

13. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will publish the current version here and update the effective date. If a change materially affects your rights or how we use personal data, we will provide additional notice where reasonably possible or legally required.

14. Contact

Controller: Grigorii Feoktistov, an individual entrepreneur registered in Georgia with identification number 306408795, operating Unograph.

Registered address: Georgia, Tbilisi, Krtsanisi District, Ponichala 3 Settlement, Building 5, Entrance 2, Floor 4, auxiliary storage.

Privacy and support: [email protected]

Website: https://unograph.com

Unograph

Collaborative software architecture modeling.

© Unograph

Terms Privacy Cookies Acceptable Use DPA