Trust center

Security & compliance

We built Modudraft with a privacy-first stance from day one. Here's exactly what we collect, where it lives, and who can see it.

What we store

Anonymous / Free users
  • Diagrams stored in localStorage only — never sent to our servers
  • No account, no server storage
  • Anonymous analytics events (page views, feature usage) — no PII, GDPR-compliant
Registered users (Pro / Team)
  • Email address (for auth + billing)
  • Diagram data (JSON) stored in encrypted database
  • OAuth tokens for social login (Google, GitHub, Microsoft) — never your password
  • No payment data stored by us — Stripe handles billing

Your data rights

Export

Download all your diagrams at any time from Account → Export data.

Delete account

Permanently delete your account and all associated data from Account → Delete account.

Access request

Email [email protected] for a full data export or GDPR subject access request.

Compliance

  • GDPR — we process minimal data, honor erasure requests, and our analytics are cookieless and GDPR-compliant.
  • CCPA — we do not sell personal data to third parties.
  • SOC 2 — not yet certified. In progress for Team plan.

Questions about security or a vulnerability to report?

[email protected]