PRIVACY POLICY
What we know, and why.
Last updated August 19, 2026 · applies to the preview release
1. The short version
We collect what the product needs to work and nothing else. No advertising, no third-party analytics, no tracking pixels, no selling data — the only cookies are the ones that keep you signed in. Your diagrams are yours and are visible only to you and the people you share them with.
2. What we collect
- Account data. Your email address and a securely hashed password, managed by our authentication provider. We never see or store your password in plain text.
- Sign in with Google. If you choose to sign in with Google, Google shares your email address, your name, your profile picture and a Google account identifier with us. We ask Google only for that basic profile and email information — never for access to Gmail, Drive, Calendar or any other Google data — and we use it solely to create and sign you into your C4Stage account. C4Stage's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell, share or transfer that information to anyone, and we do not use it for advertising.
- Content you create. Models (nodes, edges, flows, zones, tags, positions), comments, uploaded icons, canvas names, version history and save labels — including who saved what, so history and collaboration can work.
- Configuration you enter. Health probe URLs and log queries you attach to nodes. Probes run from our servers; the URLs are never exposed to other visitors' browsers.
- Operational data. Short-lived collaboration state (shared drafts, presence), and minimal server logs for keeping the service healthy and abuse-free (for example, assistant rate-limit counters keyed to your account).
- Preferences. Interface choices like theme and panel state live in your browser's local storage and are not sent to us.
3. How we use it
To provide the service: storing and rendering your canvases, syncing edits between collaborators, probing the health endpoints you configured, sending transactional email (invitations, confirmations, password resets — never marketing during the preview), answering assistant requests, and keeping the service secure. We do not use your content to train AI models, and we do not sell or rent personal data to anyone.
4. Who processes it for us
These services process data on our behalf, only as needed to run the product:
- Supabase — authentication and the database that stores accounts and content.
- Google — only if you sign in with Google: Google authenticates you and passes us the basic profile information described above.
- Resend — delivery of transactional email.
- OpenRouter — when you use the assistant, your prompt and the relevant model context are sent to an AI model through OpenRouter to generate the reply. The assistant only runs when you invoke it.
- Our hosting infrastructure — the servers the app runs on.
- Sentry — error reports when something breaks (the stack trace, the page or route, and browser details), plus our servers' own logs, request timings and CPU profiles of our code. No session recordings, no email addresses — they are removed before anything is sent.
Stripe processes payments for paid plans as the merchant of record — card details go directly to Stripe and never touch our servers, and Stripe sends the receipts and invoices. Our side keeps only your email, the plan you are on and the subscription's status.
5. What other people can see
- Canvases are private to you and the people they're shared with, under the role you gave them (viewer or editor).
- Collaborators see your email address on shared canvases — on comments, presence and history entries.
- A public share link makes that canvas readable by anyone who has the link, without an account, until you revoke it.
6. Retention & deletion
Content lives as long as the canvas does — version history is part of a canvas, and deleting a canvas deletes its history with it. Comments can be deleted by their author or the canvas owner. If you want your account and everything owned by it removed, ask (section 9) and we will delete it within 30 days, except where a residual copy sits in short-lived backups that expire on their own schedule.
7. Cookies
The only cookie we set is the one that keeps you signed in — there's no advertising, analytics or cross-site tracking cookie, and no cookie banner because there's nothing to ask permission for. Interface preferences (theme, panel layout, which tab you last had open), short-lived collaboration details like the name shown on your cursor, and draft recovery for unsaved edits live in your browser's local or session storage, not in a cookie, and are never sent to us.
8. Security
Traffic is encrypted in transit, passwords are hashed, access to stored content is gated per account and share, and internal URLs you configure (health probes, log endpoints) are only ever called server-side. No online service can promise perfect security — don't put secrets, credentials or regulated personal data into diagrams or comments. See the security page for more detail.
9. Your rights
You can access and correct your account data in the profile panel (the account chip in the canvas toolbar), export any canvas you can see (Mermaid from the Export menu, JSON over the API), and request a copy or deletion of your data. Depending on where you live you may have additional statutory rights (access, rectification, erasure, portability, objection) — we honour requests for them regardless of geography during the preview.
10. Contact
Privacy questions or requests: reach the team through your workspace administrator or the channel that came with your invitation, and we'll respond there. By post: C4Stage, 100 King Street West, Suite 5700, Toronto, ON M5X 1C7, Canada. See also the terms of service.
11. Changes
If what we collect or how we use it changes, this page changes with it and the date above moves. Material changes will be flagged in the product before they apply.