We use Google Analytics to see which parts of Umlout get used. It sets cookies in your browser. Nothing about Umlout stops working if you decline.

Umlout
TemplatesFeaturesPlaygroundPricingSign inGet started
Home›Privacy Policy

Privacy Policy

Last updated 11 August 2026

Umlout is a collaborative diagramming tool. This page describes what we collect when you use it, why we hold it, who else it reaches, and how to get it back or removed.

Who we are

Umlout is operated by Individual Entrepreneur Dmitrii Korzh (identification number 345663604). We decide what personal data the service collects and why, which under UK and EU data protection law makes us the data controller for it. Reach us at legal@aeario.com.

What we collect

Account details

When you register with an email address we store that address, the username you choose, and a one-way bcrypt hash of your password — never the password itself. If you sign in with Google instead, we store your Google account identifier and the email address Google confirms for it, and no password exists for that account at all. You can add a first name, last name and profile picture; the picture is stored with your account and served to collaborators who share a diagram with you.

What you create

Diagrams, models, elements, relations and comments you make, together with who owns them and who they are shared with. This is content you control: it is stored so the service can show it back to you and to the people you share it with.

Technical records

Our servers write an access log for each request — a timestamp, the route, the response status, a request identifier, and the network address the request came from. We keep a single "last seen" timestamp per account so we can count how many people use the service. While you have a diagram open we hold a short-lived presence record, so collaborators can see each other's cursors. We also count requests per address to stop abuse of the sign-in and signup endpoints.

Things you send us

If you use the feedback form we store your message and, when you attach one, the screenshot. If you ask to be notified about a paid plan, we store the email address you give for that.

API keys

Keys you generate for the MCP server are stored only as a keyed hash plus the first few characters, which is why we can show you which key is which but can never show you a key again after it is created.

Why we hold it

Account details and content are held to provide the service you asked for — without them there is no account and nothing to show you. Technical records are held for a narrower reason: keeping the service available, diagnosing faults, and preventing abuse. We do not sell personal data, and we do not use your diagrams to train machine-learning models.

If you are in the UK or the EEA: the first is processing necessary to perform our contract with you, the second is our legitimate interest in running a secure service, and the analytics described below rely on your consent.

Who else sees it

We use a small number of outside services, and each one sees only what it needs:

  • Google — if you choose to sign in with Google, Google tells us your account identifier, email address and name. Google's own privacy policy governs what Google does with that sign-in. We load our fonts from Google's font service, so Google receives your network address on every page load. Google Tag Manager, which we use for analytics, is different: it loads only if you accept it, and it is the one thing on this page you can switch off.
  • Mailgun — sends verification emails. It receives your email address and the message.
  • Grafana Cloud — stores our application logs and metrics. Those logs include the technical records described above, which means request identifiers, network addresses and, for signed-in requests, your account identifier.

Our own database runs on servers we operate. We disclose data to anyone else only where the law requires it.

Cookies and local storage

Signing in does not set a cookie. Your session token is kept in your browser's local storage, and clearing site data or signing out removes it. The same goes for your answer to the cookie banner — it is a single value in local storage, not a cookie.

Analytics is the only thing here that sets cookies. We use Google Tag Manager to see which parts of Umlout get used, and it does not load at all unless you accept it. Decline and no analytics script is ever fetched; nothing about Umlout stops working either way.

You can change your mind at any time, right here:

You have not been asked yet, so analytics is off.

Turning analytics off stops the script from loading again, but it cannot delete cookies Google has already set — no site can remove another one's cookies. Clear those through your browser's site-data settings.

How long we keep it

Account details and content are kept until the account is deleted. Everything else expires on its own:

  • The "last seen" timestamp is discarded after 24 hours.
  • Presence records disappear within a minute of a diagram being closed.
  • Abuse counters expire with their time window, at most an hour.
  • Sign-in handshake records expire within ten minutes, and are deleted the moment they are used.
  • Logs held in Grafana Cloud follow that service's retention for our plan.

Your choices

You can see and change your name, email address and picture on your profile page, and revoke API keys there at any time.

For a copy of your data, or to have your account and its content deleted, write to legal@aeario.com. Deletion is not yet a button you can press yourself, so we handle these by hand — we will confirm when it is done. If you are in the UK or the EEA you also have the right to object to processing, to restrict it, and to complain to your data protection authority.

How we protect it

Traffic to Umlout is encrypted in transit. Passwords are stored as bcrypt hashes and API keys as keyed hashes, so neither can be read back out of our database. Sign-in handshakes are single-use and time-limited, and the token that ends a social sign-in is never placed anywhere a server or proxy would log it.

No service can promise perfect security, and we do not. If you find a weakness, we would rather hear about it than not — write to support@aeario.com.

Children

Umlout is not directed at children and is not intended for anyone under 16. If you believe a child has given us personal data, tell us and we will remove it.

Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will tell account holders by email rather than relying on you to notice.

Contact

Write to legal@aeario.com for anything about this policy or the data we hold about you. We answer from the same address, so replies stay on the same thread.

Umlout
© 2026 Umlout.
All rights reserved.
TEMPLATES
  • UML
  • Workflows
  • UI/UX
  • Agile
  • Basics
PRODUCT
  • Playground
  • Features
  • MCP server
  • Pricing
ACCOUNT
  • Sign in
  • Create account
LEGAL
  • Privacy Policy
  • Terms of Service