Legal
Privacy Policy
Last updated · September 21, 2026
What Tierslate holds about you, why, who else sees it, how long it lasts, and what you can make us do about it. 8 numbered sections, written to be read rather than survived.
Scope of this policy
Tierslate is an architecture-diagram editor and walkthrough player at tierslate.com. It is a professional tool, not intended for anyone under 16 or under whatever age your country sets for consent to online services, and we do not knowingly collect data from children. Anything we learn a child has given us is removed. This policy does not cover other people’s sites that we link to.
We have not appointed a data protection officer. For a company of this size that is permitted rather than an omission.
What we collect
Everything we hold about you, by category. Nothing here is collected for a reason that is not in this list.
- Your Google account
- Signing in with Google is the only way to get an account, so we never see a password. Google tells us your name, email address, profile picture, whether it considers the address verified, and a stable identifier it calls the
sub, which is what your boards are attached to. Google’s own tokens stay on our server and never reach your browser. - The boards you make
- Nodes, edges, text, notes, walkthrough steps and the names you give them, so we can give them back to you and to the people you share them with. If you create or join a team, we store the team, who is in it, and the invitations sent.
- Images you upload
- The bytes, and the SHA-256 hash of those bytes, which is the name we file them under. We compute that hash ourselves rather than trusting what your browser sends.
- Collaboration edit history
- When several people edit one board at once, each change is logged so the edits can be merged and replayed in order. The log records what changed and who changed it.
- Sign-in sessions
- Your account id, when the session started, was last used and expires, plus the user-agent string and the IP address it was created from. The last two are there so you can look at your own sessions and end one you do not recognise.
- Support messages
- What you wrote: the subject, the message, the name and email address you gave, the page you were on and, if you were signed in, your account id. This is the one thing here with no deletion date, and the retention card below says so.
- Newsletter
- Only if you type your address into the subscribe form and click the confirmation link. We keep the address, that you confirmed, when, and the IP addresses you subscribed and confirmed from, because consent evidence that cannot say when and from where is not much evidence. Signing in is not consent to marketing mail; the two lists are separate.
- The early-access waitlist
- Accounts are not open yet, so the sign-in buttons take an address instead. If you leave one, we keep the address, the day you asked and the IP address the request came from, and nothing else - no name, no account, and nothing about what you drew. It sits on the same list as the newsletter and is not the same thing as being subscribed to it: you are marked as waiting, not as a subscriber, and only clicking the link in the one message we send would change that. That message has not been sent, which is also why there is no unsubscribe link for it yet - the basis card above says what to do instead.
- Payments
- Our own log of plan changes and payment events on your account. Card numbers are typed on Stripe’s page and never reach this service.
- How you use the app, if you agree to it
- What you do, never what you make. Named actions - a board opened, a node added, an export taken, a limit reached - with counts and labels from a fixed list, the plan you are on, and a random device id that is not your account and is not joined to it. Alongside them a session replay: a recording of the interface as you use it, with the board canvas cut out of it and the text you typed masked before it leaves your browser. None of this happens, and nothing is loaded or stored on your device, until you say yes. The analytics card below lists what is never measured, and that list is enforced in the code rather than promised.
- Server logs
- Ordinary web server access logs: IP addresses, paths requested, user-agent strings, so we can find faults and see abuse. This is the one thing recorded about every visitor, including one who never signs in, and it is one of the retention rows with no period.
Why we may
Under the GDPR every piece of processing needs a reason the law recognises. Ours are these, and only these. Where the reason is legitimate interests, the interest itself is named: a policy that says “legitimate interests” and stops has told you nothing.
- Your account, and the boards and images in it
- Performance of a contract You asked us for an account so you could make boards. Holding them is the service.
- Your name, email address and picture from Google
- Performance of a contract Sign-in is the only way in, and we need to know which account is yours.
- The edit history behind live collaboration
- Performance of a contract Two people editing one board at once is a feature you used; it cannot work without a record of the edits.
- Messages you send us through support
- Legitimate interests You wrote to us and we want to answer, and to recognise a second message about the same problem.
- Server access logs
- Legitimate interests Keeping the service up and working out what broke when it breaks, and noticing abuse.
- Rate-limit counters
- Legitimate interests Stopping one visitor from taking the service down for everybody else.
- The newsletter, and the record that you asked for it
- Consent You opted in and confirmed it. You can withdraw from a link in every message.
Taking it back: Every message we send carries an unsubscribe link, and it works without signing in or writing to anybody.
- The early-access waitlist, and the address you left on it
- Consent Accounts are not open yet and you asked to be told when they are. We hold your address, the day you asked and the IP address the request came from, and nothing else. It is one message, about one thing, and it is finished when it is sent - it does not put you on the newsletter, and only clicking the link in it would.
Taking it back: This is the one with no button, and saying otherwise would be describing a control that does not exist. Nothing has been sent to you, so there is no message carrying an unsubscribe link and nothing for you to click: the way out is the one the form promises in the same breath as it takes the address - ask us and we delete the row. That is a real mechanism and it is a human one. When the one message does go out it carries a one-click unsubscribe like everything else we send, and from that moment this works exactly the way the newsletter above does.
- Product analytics and session replay
- Consent You were asked before anything was loaded, and off is what an unanswered question means. Saying no costs you nothing: the editor behaves identically either way, and you are not asked again.
Taking it back: There is a switch, and it is in the product rather than in your browser’s settings: Help › Privacy & analytics in the editor’s menu bar, which opens Settings → Preferences → Privacy. It is two clicks from the board and it is there whether or not you have an account. Turning it off is the withdrawal. The answer is one entry in this site’s storage in your own browser and it is checked again every single time something would be sent, so it takes effect at once rather than at the next reload. Withdrawing also takes the vendor’s own cookies and storage entries off your device and empties the database it kept recordings in, which is removed when you next leave the page - their software holds the connection open, so it cannot be deleted outright while you are still here. Clearing this site’s data removes the record itself, which puts you back to not having agreed, which is off.
- Records of payments
- Legal obligation Tax and accounting law requires a seller to keep them.
Three things rest on your consent: the newsletter, product analytics, and the early-access waitlist. All three are off until you ask for them, all three say above how to take them back, and all three are separate from each other and from having an account. Signing in is not agreement to any of them, and leaving your address for early access does not subscribe you to the newsletter - only clicking the link in the one message we send would, and until you do, nothing we send to the newsletter list goes to you. The service works the same whether you say yes or no, which is what makes saying no a real option rather than a polite one.
Who else sees it
These companies process data for us. Saying “we use Stripe” discloses nothing, so each one says what actually leaves this system and where they handle it. Nobody is on this list who receives nothing, and nobody is off it who receives anything. We do not sell your data and we do not give it to advertising networks.
Google Ireland Limited
Sign-in. The only way to get an account.
- What they receive
- Nothing is sent to Google by us. Google tells us your name, email address and profile picture when you choose to sign in.
- Where they process it
- EU, with transfers to the United States under Google’s own terms
- Their own policy
- https://policies.google.com/privacy
Twilio SendGrid
Sending email: sign-in related mail, invitations, receipts, and the newsletter if you ask for it.
- What they receive
- The recipient address and the contents of the message being sent.
- Where they process it
- United States
- Their own policy
- https://www.twilio.com/legal/privacy
Stripe Payments Europe, Ltd.
Taking payment for a paid plan. Only if you buy one.
- What they receive
- Your email address and the payment details you type on Stripe’s own page. Card numbers never reach this service.
- Where they process it
- EU, with transfers to the United States
- Their own policy
- https://stripe.com/privacy
Amplitude, Inc.
Product analytics and session replay: which features get used, where people get stuck, and where they give up. Only if you agree to it, and only from the moment you do.
- What they receive
- Nothing at all until you agree - their script is not even fetched, because fetching it would hand them your address before you had said anything. After that: a random device id that is not your account and is not joined to it, the plan you are on, named actions such as "a node was added" carrying counts and labels from a closed list, and the user-agent string your browser sends with every request anyway, which their software offers no way to leave out. Never a board name, a node title, note text, an image or its file name, a board id, a share link, an email address, the tracking parameters on the link that brought you here, or free text of any kind. Session replay also sends a recording of the interface as you use it; we configure the recorder to cut the board canvas out of it and mask the text you typed before it leaves your browser.
- Where they process it
- EU. The browser is told to send to Amplitude’s EU data region and their servers there are where it is processed. Amplitude, Inc. is a United States company, so the group that runs those servers is subject to US law even though your data sits in Europe.
- Their own policy
- https://amplitude.com/privacy
Amazon Web Services EMEA SARL
Hosting. The servers and the database this service runs on.
- What they receive
- Everything the service stores, because it is stored on their infrastructure.
- Where they process it
- EU
- Their own policy
- https://aws.amazon.com/privacy/
The service runs in the European Union, but Google Ireland Limited and Twilio SendGrid and Stripe Payments Europe, Ltd. process data in the United States, which means it is handled outside the protection of EU law. That relies on the safeguards in our contract with them, normally the European Commission’s standard contractual clauses, together with the EU-US Data Privacy Framework where the company is certified under it. If you would rather no email about you left the EU, the only way to achieve that is not to have an account, because we cannot send you a sign-in or an invitation without it.
A share link is the other way your data reaches somebody. It carries a capability token in the part of the URL after the #, which browsers never send to a server, so the secret stays out of our logs. It also means anyone holding the link can open the board with whatever access the link grants, whether or not you meant to give it to them. Treat one like a key; rotating a board’s links revokes it.
How long we keep it
Every period below was taken from the thing in the code that actually does the deleting, not from what sounded reasonable. 6 of the 10 rows have no period at all, and they say so rather than being rounded up to a comfortable number.
Your account and the boards you make
No automatic deletion
Kept until you ask us to delete them. Your boards are yours and we do not sweep them.
- Enforced by
- no automatic deletion
Sign-in sessions
30 days
A session extends as you use it but can never live longer than thirty days from the moment it was created.
- Enforced by
- server/users.ts, a hard ceiling on renewals
The edit history behind live collaboration
90 days
- Enforced by
- server/db.ts, a TTL index on the ops log
Images you upload
90 days
Ninety days after an image was last fetched, not after it was uploaded, so an image still on a board you use is not swept.
- Enforced by
- server/images.ts, the sweeper
Records of payments and plan changes
30 days
This is our own event log. Stripe keeps its own records for as long as tax law requires them to.
- Enforced by
- server/db.ts, a TTL index on billing events
Server access logs
No automatic deletion
These record the address a request came from, what was asked for and when. We have not yet set a period for them and should. Say so if you want yours removed.
- Enforced by
- nothing - the web server keeps them until the disk is rotated
Proof that you asked for the newsletter
No automatic deletion
When you subscribe and when you confirm, we record the IP address you did it from. That record is what lets us show the consent was real. It is not particular to the subscribe form: every address in this table carries the one it was created from, including one left on the early-access waitlist, which has no confirming half to record. Unsubscribing removes you from the list; ask us and we will delete the evidence too.
- Enforced by
- kept for as long as the subscription, as evidence of consent
The address you left on the early-access waitlist
No automatic deletion
We hold your address, the day you asked and the IP address the request came from. Nothing deletes it on a schedule, and sending the one message you asked for does not remove it either. There is no unsubscribe link to use yet, because nothing has been sent to it: ask us and we delete the row.
- Enforced by
- nothing - it is a row on the subscriber list and nothing sweeps that list
Product analytics and session replay, if you agree to them
No automatic deletion
We have not decided how long these are kept, so we do not state a period we would not be keeping. Withdrawing your agreement stops anything further being sent, at once, and removes what their script left on your device. What is already on their servers is another matter: nothing we send identifies you, so we cannot pick your recordings and events out of it, and neither can anyone else looking at them - that is the point of sending no account id, and it is also its cost.
- Enforced by
- nothing here - Amplitude holds them under its own project settings, and nobody has set a period
Messages you send us through support
No automatic deletion
We should give these a retention period and have not yet. Until we do, ask us and we will delete yours.
- Enforced by
- nothing - there is no automatic deletion
The support one is the one to read twice. Nothing deletes a support message on a schedule, so a ticket outlives the account that sent it: delete your account and the messages you wrote to support are still here. We think that is wrong and have not fixed it. Until we do, ask us and we will delete yours by hand. Newsletter unsubscribe records are kept on purpose, so a later import cannot re-subscribe somebody who asked to be left alone. Otherwise, deleting your account deletes your personal data except where the law requires a record, which in practice means payment records.
Your rights
These are yours under the GDPR, and each one says how it works here today, because a right you cannot exercise is not a right. Most are handled by a person rather than by a button in the app, and pretending otherwise would waste your time looking for the button. We answer within one month.
Access
Handled by a person
Ask what we hold about you and get a copy of it.
Rectification
Handled by a person
Correct anything about you that is wrong.
Erasure
Handled by a person
Ask us to delete your account and what is in it.
Restriction
Handled by a person
Ask us to stop processing while a question is resolved.
Portability
You can do this yourself
Get your boards in a machine-readable form. You can already export a board from inside the editor.
Objection
Handled by a person
Object to processing we do on the basis of legitimate interests.
Withdrawing consent
You can do this yourself
Three things here rest on your agreement and all three can be taken back, though not by the same means - one of them has no button, and it is the waitlist. Unsubscribe from the newsletter at any time, from a link in every one we send. Withdraw the one you gave for product analytics and nothing further is sent or loaded, from that moment rather than from the next reload. For the early-access waitlist, nothing has been sent to you yet, so no unsubscribe link for it exists and the way out is to ask us - we delete the row. How, for each, in the section above. Withdrawing does not undo what was already lawfully done before you did it.
Complaining
Not through us
Complain to a data protection supervisory authority.
You can also change your name and picture in your Google account, which is where ours come from, and see and end your active sessions from inside the app.
Complaining does not go through us. You may complain to a data protection supervisory authority where you live, where you work, or where the thing you are complaining about happened, without asking us first. Your own national authority is the right place to start, and they will pass a complaint on if it belongs elsewhere.
Analytics, and what it never sees
We measure how the product is used, through Amplitude, on their EU servers. It is off until you agree to it: nothing is loaded, nothing is stored on your device and nothing is sent while you have not answered, because an unanswered question is a no. We ask once, in a card that does not block the page, and we do not ask again after you answer. Declining costs you nothing - there is no reduced version of the editor and no second prompt. One honest detail: while the question is still on screen, actions are held in the page’s memory - not stored, not sent - so that saying yes does not lose the last minute. Say no, or close the tab, and they are thrown away without ever leaving your browser.
What is measured is actions, never content. We record that somebody added an image; we never record which image, what it was called, or what board it was on. These are all of the actions, as the code lists them today:
app_opened, board_created, board_opened, board_shared, checkout_started, export_used, flow_recorded, image_added, lens_switched, limit_hit, node_added, notes_edited, plan_changed, recording_started, signed_in, support_ticket_sent, upgrade_viewed
Each one may carry counts and labels from a fixed list - which lens you switched to, which format you exported, which limit you hit - and the plan you are on. That is the only thing about you that is ever attached: no name, no email address, no user id, no account id. Amplitude gets a random device id of its own and nothing that joins it back to a row in our database, which also means we cannot ask it what any particular customer did.
Nothing on this list is ever sent, under any name:
- board names, node titles, region labels, note text, prose blocks
- email addresses, display names, team names, invite codes
- support ticket subjects or message bodies
- image bytes, image file names, image hashes
- board ids, document ids, share links, edit tokens
- free text of any kind, from any field, ever
The last line is the one that makes the rest enforceable rather than promised. A value is only allowed out if it is a number, a true/false, or a word from that property’s own fixed list; a string nobody put on a list cannot get through, so a future measurement cannot leak a board name by accident, it can only fail to send something and say so in a test. For the same reason we switched off the vendor’s automatic click tracking, which would attach the text of whatever you clicked - in this product, your own node titles - and we switched off the analytics script’s remote configuration, so what we measure cannot be changed from somebody else’s dashboard without a release, and we switched off its automatic capture category by category - including the one that reads the tracking parameters off the link that brought you here, the utm_ tags and the advertising click ids. What their script does send that we cannot switch off is the user-agent string your browser announces itself with on every request it makes, which says what browser, operating system and device type you are on. The options that would have added your language and your platform as measurements of their own are off.
Two limits on that, stated because they are true rather than because they help. The option that stops your IP address being stored as data and resolved into a city is on, but no option can stop their servers seeing the address your browser connects from - that is how a connection works, and the only real protection is the one above: nothing connects until you agree. And the session-replay part of their software fetches its own settings from them each time it starts, which we cannot switch off. Our rules about what to leave out are sent with it, but how often a session is recorded and how much of the rest of the interface is masked can be changed at their end, so what we can tell you is what we configure rather than a guarantee about their side of it.
Session replay is a recording of the interface, and it is masked. Once you have agreed, sessions are recorded so we can watch where people get stuck. We configure the recorder to cut the board canvas out of the recording entirely and to mask the places that carry text you typed, before anything leaves your browser, so what it is set up to capture is layout, navigation and interaction: where you moved, what you clicked, where you gave up. That is not a nicety. What is on your canvas is usually not yours to give away - it is your employer’s or your client’s system architecture, their service names, their schema - and you cannot consent on their behalf.
Changing your mind takes effect immediately, not at the next reload. Your answer is kept in this site’s storage in your own browser, under tierslate.analytics.consent, and it is read again every single time something would be sent. Withdrawing does more than stop the sending: the recorder is removed, anything waiting to be sent is dropped unsent, and what their script left on your device is deleted - its cookies, its storage entries and the database it kept recordings in. It is deleted by us, key by key, because their software offers no way to ask for it. Clearing this site’s data removes the answer itself, which puts you back to not having agreed - and not having agreed means off.
Cookies and automated decisions
German law, the TTDSG, treats anything stored on or read from your device the same way whether it is a cookie or not, so local storage counts and both are listed here. It is a short list because there is very little.
tierslate_sid- The session cookie, which is what keeps you signed in. HttpOnly, so page scripts cannot read it; SameSite=Lax; Secure in production; cleared when you sign out. Strictly necessary, so it does not ask for consent.
tierslate_oauth- Set only while you are signing in and cleared the moment you land back. It ties the Google sign-in you started to the browser that finishes it, which is what stops somebody handing you a link that signs you into their account. Short-lived and strictly necessary.
tierslate/theme- Local storage. Whether you chose light or dark. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
tierslate/doc- Local storage. The autosave of the board you are editing, so a crashed tab does not cost you your work. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
tierslate/team- Local storage. Which team you were last working in. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
tierslate/seen- Local storage. That you have been here before, so the first-visit pitch is not shown twice. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
tierslate/previewWidth- Local storage. How wide you dragged the walkthrough preview dock, so it opens that width next time. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
tierslate/billing-before-checkout- Session storage, this tab only. What your plan was just before you went to Stripe, so the app can tell when the change has landed. It is dropped half an hour after it is written, and when the tab closes. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it. Closing the tab removes it too.
tierslate.returnHash- Session storage, this tab only. The part of the address after the
#- which board you were looking at - held for as long as it takes Google to send you back, so you land where you left. It is deleted the moment it is used, and it is kept out of the address we send to our own server on purpose, because for a shared board that fragment is the key to it. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it. Closing the tab removes it too. tierslate/recording-audio- Local storage. Whether you chose to include your microphone and your system audio the last time you recorded a walkthrough. The choice is stored; no audio is. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
tierslate.analytics.consent- Local storage. Your answer to the analytics question - yes or no - with the date you gave it. It is here whichever way you answered, because it is what stops you being asked again, and it is read before anything would be sent. Removing it does not turn anything on: it puts you back to not having agreed, which is off. It stays on your device, is never sent to us or to anyone else, and clearing your browser data removes it.
That is the complete list of what we put on your device, and it is checked against the code rather than written from memory. There is no advertising cookie and no cross-site tracking cookie anywhere in it.
Agreeing to analytics adds one more set, and they are not ours. Once you say yes, Amplitude’s script is loaded and it keeps its own record on your device: the random device id it uses instead of your name, whatever it has measured but not yet uploaded, and a small database holding a recording it has not uploaded yet. They are entries in this site’s storage rather than cookies, because we told their software to keep them there - left to itself it would have put the device id in a cookie. Every one of them is named with the prefix AMP_, which is how we find them again. Say no, or say nothing, and none of them is ever created, because the script is never fetched. Withdraw after having agreed and we delete them for you, one at a time, because their software offers no way to ask it to.
Nothing here decides anything about you. We make no automated decisions with a legal or similarly significant effect and we do not profile you. Nothing scores you or ranks you. The only automatic thing is the rate limit that stops one account overwhelming the service, and it applies to requests rather than to people.
Changes to this policy
We will update this page as the product changes and the date at the top changes with it. If a change matters to you, a new processor or a new purpose, we will tell you in the app or by email rather than quietly editing the page. See also our Terms and Conditions.
Back to Tierslate