Privacy Policy
Version 1.0 · Effective 19 August 2026
This Privacy Policy explains how McQuillen Interactive Pty. Ltd. (ABN 49 600 623 069) handles personal information when people visit our website, create an account for or use SimpleDiagrams Cloud, use SimpleDiagrams Desktop for macOS, make a purchase, or contact us. We are based in Victoria, Australia.
This policy covers both the website and SimpleDiagrams Cloud (the Cloud Service) and the separately distributed macOS application (the Desktop App). Unless a paragraph expressly mentions the Desktop App, references to accounts, organisations, Customer Content, subscriptions, cookies, website analytics, cloud hosting, or public diagram sharing describe the Cloud Service only.
SimpleDiagrams Desktop and SimpleDiagrams Cloud are separate products. A Desktop purchase is governed by the applicable App Store terms and does not provide Cloud access; a Cloud subscription is governed by the SimpleDiagrams Cloud Terms on this website and does not provide Desktop access. The products do not currently interoperate, and diagrams cannot be imported, transferred, or synced between them.
For Cloud Service account administration, billing, security, product operations, and support, we generally act as the organisation responsible for deciding why and how information is processed (often called a controller or APP entity). When a Customer places personal data inside its diagrams, shape configuration, or live-state values and asks us to process it, Customer generally acts as controller and we act as processor under the Data Processing Addendum.
1. Information we collect
SimpleDiagrams for macOS
The Desktop App does not require a SimpleDiagrams Cloud account and does not include advertising, analytics, tracking, an automatic crash-report uploader, or a McQuillen Interactive backend. It does not automatically send your diagrams, imported artwork, exports, filenames, file paths, or diagnostics to us.
Diagram documents, imported artwork, and exports remain in locations you select on your Mac. Custom libraries are kept in the app's local Application Support folder, and interface and workspace preferences are kept in macOS User Defaults. For trial integrity, the app stores a last-observed timestamp in the device-local Keychain. That Keychain item is not configured to synchronise between devices, may remain after the Desktop App is uninstalled, and does not contain a licence key or grant purchased access.
Purchases, offer-code redemption, restoration, and entitlement checks use Apple StoreKit. Apple independently processes Apple Account, payment, and transaction information under the Apple Privacy Policy. The Desktop App receives product information and verified purchase facts needed to determine access, such as the product, purchase date, and revocation status. McQuillen Interactive does not receive full payment-card details through the Desktop App, and diagram content is not included in StoreKit requests.
The Desktop App keeps a bounded list of diagnostic event codes from the current launch and writes those allowlisted codes to Apple's local unified logging system. These records do not include diagram content, filenames, file paths, credentials, raw error messages, transaction payloads, product identifiers, prices, or payment details. Nothing is uploaded automatically. If you choose Export Diagnostics, the app first lets you preview and save a local report containing the app and operating-system versions and those event codes. We receive it only if you then choose to send it to us, in which case it is handled as support correspondence.
SimpleDiagrams Cloud account and organisation information
We collect names or usernames, email addresses, password hashes, email-verification state, organisation names, memberships, roles, invitations, and account preferences. We do not store a readable copy of your password.
SimpleDiagrams Cloud Customer Content and live-diagram data
We store diagram names and visibility, drawing scenes, shape instances, references to supplied shape definitions and libraries, configuration, external references, connector attachments, current runtime state, state timestamps and related revision information. Customer controls what it places in these fields. The Service is intended for diagrams and current operational state, not for sensitive personal profiles, medical records, payment-card data, or secrets.
SimpleDiagrams Cloud billing information
We receive Stripe customer and subscription identifiers, plan, subscription status, billing period, cancellation state, billing contact details, tax and address details, and payment-event results. Stripe collects and stores full card and payment-method details; SimpleDiagrams does not receive or store full card numbers.
Purchases use Stripe Managed Payments, with Stripe acting as merchant of record and Link providing the customer-facing checkout, transaction communications, order management, and transaction support. McQuillen Interactive supplies SimpleDiagrams and provides product support. Stripe also processes information for its own payment, fraud-prevention, tax, and legal purposes, rather than only on our instructions. Its handling of that information is described in the Stripe Privacy Policy.
Historical desktop licence records
We retain a limited set of historical SimpleDiagrams desktop purchaser and licence records, including purchaser name and email, licence key, validation status, and registration counts. These records came from the former desktop product and are used only to honour validation for already-distributed paid desktop versions. They are not used as SaaS accounts, product analytics, or a marketing list.
SimpleDiagrams Cloud usage, technical, and security information
We collect IP address, user-agent, requested URL, time, session and CSRF identifiers, authentication and security events, error details, plan-entitlement decisions, rate and usage counters, API or agent channel, resource identifiers, idempotency keys, and operational logs. We record the version, hash, time, channel, and request context when a user accepts legal documents. We avoid putting access tokens, full diagram state, passwords, or payment credentials in logs.
Communications
We collect information you provide in support requests, privacy or copyright notices, survey answers, feedback, and other correspondence.
Newsletter signups (website)
If you ask to be told when SimpleDiagrams becomes available, we store the email address you give us, which page you submitted, whether you have confirmed it, and the times we sent and you confirmed that request. We also record the referring page, browser user-agent, IP address, and anti-automation score from the signup so we can investigate misuse of a public form; that context is cleared about 30 days later while your subscription itself is kept. You do not need an account, and we ask you to confirm the address before we add it to the list, so that nobody can subscribe you to it.
A newsletter address is used only to send you product announcements. It is not used to create an account, is not combined with Customer Content, is not sold or rented, and is not shared with anyone other than the email provider that delivers the message.
2. Sources
For SimpleDiagrams Cloud and the website, we collect information directly from you, from organisation administrators, from your browser or API client, from Stripe and other service providers, from historical desktop purchase and licence records, and from integrations or agents that your organisation authorises. If your employer, school, client, or another organisation provides your details, that organisation is responsible for its authority and notices to you. Desktop App information remains local unless you deliberately send it to us or Apple independently processes it through StoreKit as described above.
3. Why we use information
- create accounts, verify identity, and administer organisations and permissions;
- store, render, share, export, and update diagrams as Customer directs;
- process subscriptions, enforce entitlements and usage limits, and keep financial records;
- send verification, security, billing, service, and support messages;
- send product announcements to people who asked for them and confirmed their address, on the basis of that consent, until they unsubscribe;
- secure the Service, prevent abuse and fraud, investigate incidents, and debug errors;
- understand aggregate feature use and improve reliability and usability;
- respond to requests, enforce our agreements, and resolve disputes; and
- comply with tax, accounting, privacy, consumer, court, and other legal obligations.
Where GDPR or similar law requires a legal basis, we rely as appropriate on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent for an optional activity where consent is the appropriate basis. Acknowledging this Privacy Policy is evidence that it was presented; it is not blanket consent to every processing activity.
4. When information is disclosed
We disclose information only as reasonably necessary:
- to organisation members according to roles, diagram grants, and visibility settings;
- to any signed-in human user with the URL when Customer deliberately chooses All SimpleDiagrams users visibility;
- to anyone who obtains the URL when Customer deliberately chooses Anyone with the link (no account required) visibility and anonymous diagram access is enabled in Site settings;
- to providers of hosting, payment and merchant-of-record services, transactional email, and error monitoring, subject to applicable contractual and security controls;
- to professional advisers under confidentiality, or to authorities when required by law or reasonably necessary to protect rights, safety, and service security; and
- in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and continued protection.
We do not sell personal information. We do not share it for cross-context behavioural advertising, and we do not use Customer Content to train a general-purpose artificial intelligence model. Our current Sub-processor List identifies providers and processing locations.
5. Broadly shared diagrams
In SimpleDiagrams Cloud, an All SimpleDiagrams users diagram and its current displayed state can be accessed by any signed-in human account that has the URL. Anonymous visitors do not receive diagram content under this visibility, and these diagrams are not globally listed.
In SimpleDiagrams Cloud, an authorised author can instead choose Anyone with the link (no account required). When anonymous diagram access is enabled in Site settings, anyone who obtains the URL can view that diagram and its current displayed state without signing in, including people overseas. Treat this option as public publication, not a secret or private link. If anonymous diagram access is disabled site-wide, signed-in users with the URL can still view under this broad visibility; the diagram does not become private.
Under either broad visibility, anyone with access may copy, capture, or redistribute what they see. Do not use these options for personal, confidential, security-sensitive, or proprietary operational information unless you have authority and understand those consequences. Restricting the diagram later cannot recall copies already made by others.
6. International processing
For SimpleDiagrams Cloud, the current production configuration places the primary application, database, and Customer Content storage in Google Cloud's australia-southeast1 region in Sydney, Australia. Google may provide support and resilience from other locations under its terms. Stripe, transactional and announcement email, anti-automation screening, error monitoring, support, and their subprocessors may process information in the United States, European Union, Australia, or other locations described in their service terms and our Sub-processor List. Privacy protections can differ between countries.
Where the Australian Privacy Principles apply, we take reasonable steps consistent with APP 8 before disclosing personal information overseas. Where European or UK data transfer law applies, the DPA describes the transfer mechanisms, which may include the European Commission Standard Contractual Clauses and the UK transfer addendum.
7. Retention and deletion
We retain account information and Customer Content while the account or organisation is open. Cancelling a paid subscription or losing paid access does not by itself delete the organisation. Unless an owner asks us to close it sooner, a lapsed organisation and its Customer Content may be retained for up to 12 months so that an owner can use supported export or restore paid access. We may remove data sooner when its purpose ends, and this period is not a promise that deleted or inactive data can be recovered.
When an organisation is deliberately closed, a diagram is deliberately deleted, or we approve a verified deletion request, we target removal of in-scope Customer Content from ordinary active systems within 7 days and complete that removal within 30 days. Explicit deletion is normally destructive: our backups are for disaster recovery, not a customer archive or trash service. Routine encrypted backups normally rotate in about 7 days. An older last-known-good backup may be kept temporarily during a recovery incident, but residual backups expire within 90 days and are not returned to ordinary use without reapplying later deletion instructions.
We ordinarily keep application and error logs for up to 30 days; raw product analytics and framework administration logs for 90 days; and selected application security, access, account, and change audit records for 12 months. Google-managed platform audit records that providers require for service security may be retained for up to 400 days. We do not keep a history of every live-state update as telemetry. We ordinarily keep resolved support correspondence for 12 months and privacy-request completion evidence for 24 months. Direct identity and unnecessary request context are removed sooner where their purpose has ended. De-identified aggregate information is retained only while it serves a defined product, reliability, security, or compliance purpose and is reviewed rather than kept by default forever.
We retain narrow legal-acceptance evidence while the relevant account, organisation, or contractual relationship remains active and for up to 7 years afterwards where needed to establish or defend rights. Genuine invoices, payments, refunds, credits, tax, and accounting records may be retained for 7 years from the applicable transaction or financial reporting period. This longer period does not apply to Customer Content, analytics, routine application logs, or every usage event merely because it relates to a paid service.
These are maximum ordinary periods, not minimum storage promises. Law, fraud prevention, security incidents, disputes, a documented legal hold, or a provider's independent legal obligations may require us to retain a narrow record longer. We limit such exceptions to what is reasonably necessary and continue to protect retained data. Authentication tokens, sessions, invitations, verification records, and similar transient data expire or are removed when they are no longer needed for their stated purpose.
Historical desktop purchaser and licence records are retained only while the validation commitment for already-distributed paid desktop versions continues. We review that need at least annually and will define notice and final deletion when the validation service ends.
Desktop App documents, imported artwork, exports, custom libraries, preferences, Keychain trial timing, and diagnostic reports remain under the local storage and deletion controls of you and macOS; McQuillen Interactive cannot remotely retrieve or delete them. Deleting the Desktop App does not necessarily delete its Application Support, preferences, Keychain item, unified logs, or files you created elsewhere. macOS controls retention of its unified logs. Reports you save remain until you delete them. If you voluntarily send a report or other support correspondence to us, the support and privacy-request retention periods described above apply.
8. Security
For SimpleDiagrams Cloud, we use safeguards appropriate to the service and risk, including transport encryption, provider-managed encryption at rest, strong password hashing, access controls, tenant isolation, scoped application permissions, secret management, signed billing webhooks, dependency review, logging, and incident response. Payment card information is handled by Stripe's hosted interfaces. No system is completely secure, so Customer should use strong unique passwords, limit memberships and credentials, avoid unnecessary personal data, and keep appropriate exports.
The Desktop App uses the macOS App Sandbox, limits file access to user-selected locations, and uses the device-local Keychain for its trial timestamp. You remain responsible for securing your Mac, backups, and files and for choosing what information to place in a diagram or support message.
9. Your choices and rights
You can update basic account information in the Service and ask us to access, correct, delete, restrict, or export personal information by contacting us. We verify requests and may need to involve the Customer organisation that controls the data. We may decline or limit a request where law permits, including to protect another person, preserve contract evidence, or comply with legal obligations.
Depending on your location, you may also have rights to object, request portability, withdraw consent for future consent-based processing, or complain to a regulator. Withdrawing consent does not affect earlier lawful processing. In Australia, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au after first giving us a reasonable opportunity to respond.
The Desktop App has no McQuillen Interactive account to close. You control its local documents, libraries, preferences, and exported diagnostic reports using the app and macOS. Contact us if you have a privacy question about StoreKit purchase information or support correspondence that may have reached us.
Every newsletter message carries an unsubscribe link, and using it stops further announcements without affecting any account you may separately hold. You can also ask us to delete a newsletter address entirely by contacting us. Because a newsletter signup is not an account, we may only be able to act on a request made from, or verifiable against, the address itself.
10. Website and SimpleDiagrams Cloud cookies
The Desktop App does not use web cookies. The following cookie and browser-storage disclosures apply to the website and SimpleDiagrams Cloud only.
SimpleDiagrams uses essential first-party cookies. A session cookie keeps an authenticated session, and a CSRF cookie helps prevent unauthorised form submissions. These are necessary for account and security functions and are not used for advertising. Their duration depends on session and security settings; browser controls can remove them, but blocking them may prevent sign-in or authoring.
When optional marketing analytics is enabled, we ask before starting PostHog or setting its analytics cookie. Accepting allows us to count marketing-page visits and recognise the same browser across those visits. Ignoring or rejecting the banner sends no optional analytics. We do not use session replay, automatic click tracking, advertising trackers, or identified PostHog person profiles. Account, diagram, and newsletter confirmation pages are excluded; pageview events omit query strings and referring URLs. The provider necessarily receives connection information such as the IP address when a consented request is sent.
The essential sd_cookie_consent cookie remembers your choice for one year. PostHog uses the first-party ph_sd_analytics cookie for up to one year after consent, session storage for its browser session, and browser storage to remember its opt-out state. Use Cookie settings in the marketing-page footer to withdraw consent at any time; rejection stops future collection and removes the analytics cookie and session identifiers. We honour Global Privacy Control as rejection. Removing browser cookies causes us to ask again. Withdrawal does not erase information already received; contact us to request deletion where applicable.
The embedded Excalidraw software runs as part of our client application; we do not use the hosted excalidraw.com service to store your SimpleDiagrams scenes.
When configured, pages showing the newsletter signup or Contact form load Google reCAPTCHA to assess whether a submission is automated. Google receives your IP address and information about how you interact with the page, and may set its own cookies. We receive a verification result; any risk score retained with a newsletter signup is cleared with the rest of its signup context. Google's use of that information is governed by its own privacy policy and terms, linked beside the form. We use reCAPTCHA to reduce automated spam and misuse of these public forms.
11. Children
SimpleDiagrams Cloud is not directed to people under 18 and they may not create Cloud Service accounts. This account restriction does not describe local use of the Desktop App. If an educational institution wants to use SimpleDiagrams Cloud with minors, it must first enter a separate written arrangement addressing authority, notices, safeguarding, and data protection. Contact us if you believe a child has provided personal information.
12. Changes and contact
We may update this policy to reflect product, provider, or legal changes. We will post the new version and give notice of a material change as required by law. Privacy questions, complaints, and rights requests may be sent to support@simplediagrams.com.
We will acknowledge a privacy complaint, investigate it fairly, and ordinarily provide a written response within 30 days. If we need more time, we will explain why and the next step. Our response will describe the outcome and available escalation options. If you are not satisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner through oaic.gov.au.
McQuillen Interactive Pty. Ltd. · ABN 49 600 623 069 · 7/3 Bolinda Street, Bentleigh, Victoria 3204, Australia.