Privacy Policy
Version 1.1 · Effective 2 October 2026
This Privacy Policy explains how McQuillen Interactive Pty. Ltd. (ABN 49 600 623 069) handles personal information when people visit our website, create an account for or use SimpleDiagrams Cloud, use SimpleDiagrams Desktop for macOS, use the free SimpleDiagrams V4 application for Windows, make a purchase, or contact us. We are based in Victoria, Australia.
This policy covers the website, SimpleDiagrams Cloud (the Cloud Service), the separately distributed macOS application (the Desktop App), and the free legacy SimpleDiagrams V4 application for Windows (the Windows V4 App). Unless a paragraph expressly mentions the Desktop App or Windows V4 App, references to accounts, organisations, Customer Content, subscriptions, cloud hosting, or public diagram sharing describe the Cloud Service only. Website cookies, analytics and advertising measurement describe browser visits to our website, including visits to download or buy the Desktop App; they do not run inside the Desktop App.
SimpleDiagrams Desktop and SimpleDiagrams Cloud are separate products. The Desktop App is sold two ways: on the Mac App Store, where Apple is the merchant and Apple's terms also apply, and as a direct download from this website, where Stripe processes the payment and we issue a licence key. Either way the purchase is governed by the SimpleDiagrams Desktop Licence Agreement and does not provide Cloud access; a Cloud subscription is governed by the SimpleDiagrams Cloud Terms and does not provide Desktop access. The products do not currently interoperate, and diagrams cannot be imported, transferred, or synced between them.
For Cloud Service account administration, billing, security, product operations, and support, we generally act as the organisation responsible for deciding why and how information is processed (often called a controller or APP entity). When a Customer places personal data inside its diagrams, shape configuration, or live-state values and asks us to process it, Customer generally acts as controller and we act as processor under the Data Processing Addendum.
1. Information we collect
SimpleDiagrams for macOS
The Desktop App does not require a SimpleDiagrams Cloud account and does not include advertising, analytics, tracking, an automatic crash-report uploader, or a McQuillen Interactive backend. It does not automatically send your diagrams, imported artwork, exports, filenames, file paths, or diagnostics to us.
Diagram documents, imported artwork, and exports remain in locations you select on your Mac. Custom libraries are kept in the app's local Application Support folder, and interface and workspace preferences are kept in macOS User Defaults. A copy downloaded from our website stores a last-observed timestamp in the device-local Keychain for trial integrity, and once bought it also stores its licence key there, which contains the email address the licence was issued to, its expiry date, and what it unlocks. These Keychain items are not configured to synchronise between devices and may remain after the Desktop App is uninstalled. Nothing in them is sent to us: the licence key is checked on your own Mac.
A copy from the Mac App Store is paid for when you download it from Apple. It has no trial, in-app purchase, or licence key, and it makes no purchase, restoration, or entitlement requests of its own. Apple independently processes Apple Account, payment, and transaction information under the Apple Privacy Policy. McQuillen Interactive does not receive full payment-card details, and diagram content is never sent to Apple as part of a purchase.
If you buy the Desktop App directly from this website, the purchase happens in your web browser and not inside the application. Stripe processes the payment as merchant of record under the Stripe Privacy Policy, and we receive the email address you bought with, the name you gave Stripe if any, and the payment and refund status of the order. We do not receive your full payment-card details. We create a SimpleDiagrams account for that email address so you can retrieve your licence key later, and we keep a licence record containing the email address, the product, the dates the key was issued and expires, and whether the licence has been refunded or revoked. The application itself sends us nothing: it never contacts us to check a licence.
The Desktop App keeps a bounded list of diagnostic event codes from the current launch and writes those allowlisted codes to Apple's local unified logging system. These records do not include diagram content, filenames, file paths, credentials, raw error messages, transaction payloads, product identifiers, prices, or payment details. Nothing is uploaded automatically. If you choose Export Diagnostics, the app first lets you preview and save a local report containing the app and operating-system versions and those event codes. We receive it only if you then choose to send it to us, in which case it is handled as support correspondence.
Free SimpleDiagrams V4 for Windows
The Windows V4 App is a separate legacy application for local diagram editing. You need to sign up for a website account to access the free V4 installer. The existing V4 Mac installer on the legacy downloads page also requires a website account. Once installed, the app needs no account, purchase, licence key, activation, trial, or connection to a licensing server. It does not automatically send diagrams, imported files, preferences, usage analytics, or error reports to us. Online shape search has been removed. Checking for updates opens our official downloads page in your browser only when you choose that menu action.
You choose where to save Windows V4 diagrams and exports. The app can also keep preferences, recent file paths, favourites, copied or custom libraries, palettes, and a diagnostic log in local application storage. That log may contain error details; it is different from the macOS Desktop App's bounded diagnostic event codes. Uninstalling V4 may leave local application data and your saved files on your computer. McQuillen Interactive cannot retrieve or erase those local files for you.
If you choose to copy an error message or log and send it to support, please review it first. We receive only what you choose to send and handle it as support correspondence under this policy. If you open our website from Windows V4, the website and browser sections of this policy apply to that visit. Cloud accounts, Mac purchases, and Mac trial or licence-key processing do not apply to Windows V4 use.
SimpleDiagrams Cloud account and organisation information
We collect names or usernames, email addresses, password hashes, email-verification state, organisation names, memberships, roles, invitations, and account preferences. We do not store a readable copy of your password.
SimpleDiagrams Cloud Customer Content and live-diagram data
We store diagram names and visibility, drawing scenes, shape instances, references to supplied shape definitions and libraries, configuration, external references, connector attachments, current runtime state, state timestamps and related revision information. Customer controls what it places in these fields. The Service is intended for diagrams and current operational state, not for sensitive personal profiles, medical records, payment-card data, or secrets.
SimpleDiagrams Cloud billing information
We receive Stripe customer and subscription identifiers, plan, subscription status, billing period, cancellation state, billing contact details, tax and address details, and payment-event results. Stripe collects and stores full card and payment-method details; SimpleDiagrams does not receive or store full card numbers.
Purchases use Stripe Managed Payments, with Stripe acting as merchant of record and Link providing the customer-facing checkout, transaction communications, order management, and transaction support. McQuillen Interactive supplies SimpleDiagrams and provides product support. Stripe also processes information for its own payment, fraud-prevention, tax, and legal purposes, rather than only on our instructions. Its handling of that information is described in the Stripe Privacy Policy.
Historical desktop licence records
We retain a limited set of historical SimpleDiagrams desktop purchaser and licence records, including purchaser name and email, licence key, validation status, and registration counts. These records came from the former desktop product and are used only to honour validation for already-distributed paid desktop versions. They are not used as SaaS accounts, product analytics, or a marketing list.
SimpleDiagrams Cloud usage, technical, and security information
We collect IP address, user-agent, requested URL, time, session and CSRF identifiers, authentication and security events, error details, plan-entitlement decisions, rate and usage counters, API or agent channel, resource identifiers, idempotency keys, and operational logs. Short-lived product analytics may include stable page names and normalized, bounded SDShape Library search phrases with result counts. We record the version, hash, time, channel, and request context when a user accepts legal documents. We avoid putting access tokens, full diagram state, passwords, or payment credentials in logs.
Communications
We collect information you provide in support requests, privacy or copyright notices, survey answers, feedback, and other correspondence.
Newsletter signups (website)
If you ask to be told when SimpleDiagrams becomes available, we store the email address you give us, which page you submitted, whether you have confirmed it, and the times we sent and you confirmed that request. We also record the referring page, browser user-agent, IP address, and anti-automation score from the signup so we can investigate misuse of a public form; that context is cleared about 30 days later while your subscription itself is kept. You do not need an account, and we ask you to confirm the address before we add it to the list, so that nobody can subscribe you to it.
A newsletter address is used only to send you product announcements. It is not used to create an account, is not combined with Customer Content, is not sold or rented, and is not shared with anyone other than the email provider that delivers the message.
2. Sources
For SimpleDiagrams Cloud and the website, we collect information directly from you, from organisation administrators, from your browser or API client, from Stripe and other service providers, from historical desktop purchase and licence records, and from integrations or agents that your organisation authorises. If your employer, school, client, or another organisation provides your details, that organisation is responsible for its authority and notices to you. Desktop App information remains local unless you deliberately send it to us.
3. Why we use information
- create accounts, verify identity, and administer organisations and permissions;
- store, render, share, export, and update diagrams as Customer directs;
- process subscriptions, enforce entitlements and usage limits, and keep financial records;
- send verification, security, billing, service, and support messages;
- send product announcements to people who asked for them and confirmed their address, on the basis of that consent, until they unsubscribe;
- secure the Service, prevent abuse and fraud, investigate incidents, and debug errors;
- understand aggregate feature use and improve reliability and usability;
- with separate optional consent, measure which Google advertisements lead to direct Desktop App purchases on our website;
- respond to requests, enforce our agreements, and resolve disputes; and
- comply with tax, accounting, privacy, consumer, court, and other legal obligations.
Where GDPR or similar law requires a legal basis, we rely as appropriate on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent for an optional activity where consent is the appropriate basis. Acknowledging this Privacy Policy is evidence that it was presented; it is not blanket consent to every processing activity.
4. When information is disclosed
We disclose information only as reasonably necessary:
- to organisation members according to roles, diagram grants, and visibility settings;
- to any signed-in human user with the URL when Customer deliberately chooses All SimpleDiagrams users visibility;
- to anyone who obtains the URL when Customer deliberately chooses Anyone with the link (no account required) visibility and anonymous diagram access is enabled in Site settings;
- to providers of hosting, payment and merchant-of-record services, transactional email, and error monitoring, subject to applicable contractual and security controls;
- to PostHog for consented website analytics, and separately to Google for consented advertising measurement, as described in section 10;
- to professional advisers under confidentiality, or to authorities when required by law or reasonably necessary to protect rights, safety, and service security; and
- in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and continued protection.
We do not sell personal information. We do not share it for cross-context behavioural advertising, and we do not use Customer Content to train a general-purpose artificial intelligence model. Our current Sub-processor List identifies providers and processing locations.
5. Broadly shared diagrams
In SimpleDiagrams Cloud, an All SimpleDiagrams users diagram and its current displayed state can be accessed by any signed-in human account that has the URL. Anonymous visitors do not receive diagram content under this visibility, and these diagrams are not globally listed.
In SimpleDiagrams Cloud, an authorised author can instead choose Anyone with the link (no account required). When anonymous diagram access is enabled in Site settings, anyone who obtains the URL can view that diagram and its current displayed state without signing in, including people overseas. Treat this option as public publication, not a secret or private link. If anonymous diagram access is disabled site-wide, signed-in users with the URL can still view under this broad visibility; the diagram does not become private.
Under either broad visibility, anyone with access may copy, capture, or redistribute what they see. Do not use these options for personal, confidential, security-sensitive, or proprietary operational information unless you have authority and understand those consequences. Restricting the diagram later cannot recall copies already made by others.
6. International processing
For SimpleDiagrams Cloud, the current production configuration places the primary application, database, and Customer Content storage in Google Cloud's australia-southeast1 region in Sydney, Australia. Google may provide support and resilience from other locations under its terms. Stripe, transactional and announcement email, anti-automation screening, website analytics and advertising measurement, error monitoring, support, and their subprocessors may process information in the United States, European Union, Australia, or other locations described in their service terms and our Sub-processor List. Privacy protections can differ between countries.
Where the Australian Privacy Principles apply, we take reasonable steps consistent with APP 8 before disclosing personal information overseas. Where European or UK data transfer law applies, the DPA describes the transfer mechanisms, which may include the European Commission Standard Contractual Clauses and the UK transfer addendum.
7. Retention and deletion
We retain account information and Customer Content while the account or organisation is open. Cancelling a paid subscription or losing paid access does not by itself delete the organisation. Unless an owner asks us to close it sooner, a lapsed organisation and its Customer Content may be retained for up to 12 months so that an owner can use supported export or restore paid access. We may remove data sooner when its purpose ends, and this period is not a promise that deleted or inactive data can be recovered.
When an organisation is deliberately closed, a diagram is deliberately deleted, or we approve a verified deletion request, we target removal of in-scope Customer Content from ordinary active systems within 7 days and complete that removal within 30 days. Explicit deletion is normally destructive: our backups are for disaster recovery, not a customer archive or trash service. Routine encrypted backups normally rotate in about 7 days. An older last-known-good backup may be kept temporarily during a recovery incident, but residual backups expire within 90 days and are not returned to ordinary use without reapplying later deletion instructions.
We ordinarily keep application and error logs for up to 30 days; raw product analytics and framework administration logs for 90 days; and selected application security, access, account, and change audit records for 12 months. Google-managed platform audit records that providers require for service security may be retained for up to 400 days. We do not keep a history of every live-state update as telemetry. We ordinarily keep resolved support correspondence for 12 months and privacy-request completion evidence for 24 months. Direct identity and unnecessary request context are removed sooner where their purpose has ended. De-identified aggregate information is retained only while it serves a defined product, reliability, security, or compliance purpose and is reviewed rather than kept by default forever.
We retain narrow legal-acceptance evidence while the relevant account, organisation, or contractual relationship remains active and for up to 7 years afterwards where needed to establish or defend rights. Genuine invoices, payments, refunds, credits, tax, and accounting records may be retained for 7 years from the applicable transaction or financial reporting period. This longer period does not apply to Customer Content, analytics, routine application logs, or every usage event merely because it relates to a paid service.
These are maximum ordinary periods, not minimum storage promises. Law, fraud prevention, security incidents, disputes, a documented legal hold, or a provider's independent legal obligations may require us to retain a narrow record longer. We limit such exceptions to what is reasonably necessary and continue to protect retained data. Authentication tokens, sessions, invitations, verification records, and similar transient data expire or are removed when they are no longer needed for their stated purpose.
Historical desktop purchaser and licence records are retained only while the validation commitment for already-distributed paid desktop versions continues. We review that need at least annually and will define notice and final deletion when the validation service ends.
Desktop App documents, imported artwork, exports, custom libraries, preferences, Keychain trial timing and licence keys, and diagnostic reports remain under the local storage and deletion controls of you and macOS; McQuillen Interactive cannot remotely retrieve or delete them. Deleting the Desktop App does not necessarily delete its Application Support, preferences, Keychain item, unified logs, or files you created elsewhere. macOS controls retention of its unified logs. Reports you save remain until you delete them. If you voluntarily send a report or other support correspondence to us, the support and privacy-request retention periods described above apply.
8. Security
For SimpleDiagrams Cloud, we use safeguards appropriate to the service and risk, including transport encryption, provider-managed encryption at rest, strong password hashing, access controls, tenant isolation, scoped application permissions, secret management, signed billing webhooks, dependency review, logging, and incident response. Payment card information is handled by Stripe's hosted interfaces. No system is completely secure, so Customer should use strong unique passwords, limit memberships and credentials, avoid unnecessary personal data, and keep appropriate exports.
The Desktop App uses the macOS App Sandbox, limits file access to user-selected locations, and in a copy from our website uses the device-local Keychain for its trial timestamp and licence key. You remain responsible for securing your Mac, backups, and files and for choosing what information to place in a diagram or support message.
9. Your choices and rights
You can update basic account information in the Service and ask us to access, correct, delete, restrict, or export personal information by contacting us. We verify requests and may need to involve the Customer organisation that controls the data. We may decline or limit a request where law permits, including to protect another person, preserve contract evidence, or comply with legal obligations.
Depending on your location, you may also have rights to object, request portability, withdraw consent for future consent-based processing, or complain to a regulator. Withdrawing consent does not affect earlier lawful processing. In Australia, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au after first giving us a reasonable opportunity to respond.
The Desktop App has no McQuillen Interactive account to close. You control its local documents, libraries, preferences, and exported diagnostic reports using the app and macOS. Contact us if you have a privacy question about desktop purchase information or support correspondence that may have reached us.
Every newsletter message carries an unsubscribe link, and using it stops further announcements without affecting any account you may separately hold. You can also ask us to delete a newsletter address entirely by contacting us. Because a newsletter signup is not an account, we may only be able to act on a request made from, or verifiable against, the address itself.
10. Website and SimpleDiagrams Cloud cookies
The Desktop App does not use web cookies. The following cookie and browser-storage disclosures apply to the website and SimpleDiagrams Cloud only.
SimpleDiagrams uses essential first-party cookies. A session cookie keeps an authenticated session, and a CSRF cookie helps prevent unauthorised form submissions. These are necessary for account and security functions and are not used for advertising. Their duration depends on session and security settings; browser controls can remove them, but blocking them may prevent sign-in or authoring.
When optional marketing analytics is enabled, we ask before starting PostHog or setting its analytics cookie. Accepting allows us to count marketing-page visits and recognise the same browser across those visits. Ignoring or rejecting the banner sends no optional analytics. We do not use session replay, automatic click tracking or identified PostHog person profiles. PostHog receives no advertising click identifiers. Separate Google Ads measurement is described below. Account, diagram, and newsletter confirmation pages are excluded. Pageview events omit referring URLs and omit query strings, except for the campaign tags described below. The provider necessarily receives connection information such as the IP address when a consented request is sent.
Separately from the browser, our own servers keep a short-lived, bounded count of product actions so that we can tell whether the service is working and being found useful: a download starting, a shape-library search and how many results it returned, a checkout beginning or completing, a desktop purchase completing, and a checkout that failed or was abandoned. These are kept whether or not you accept optional analytics, because they are the ordinary operation of the service rather than advertising. Each keeps only a small, fixed set of values listed for that action, they are pruned, and where you are not signed in they record no one: there is no identifier on them, and nothing that would let one be reconstructed. None of this is sent to PostHog unless you have accepted optional analytics.
Where you have accepted, a named subset of those counts is also sent to PostHog so that we can see how far a visit progressed rather than only that something happened: a desktop or shape-library download starting, a checkout beginning or completing, a desktop purchase completing, and a checkout that failed or was abandoned. Shape-library search terms are never sent. Each is sent with the analytics identifier already held in the ph_sd_analytics cookie, and with the campaign tags utm_source, utm_medium and utm_campaign when you arrived from a link we published; we keep the first such set for your visit in the essential session cookie, and only once you have accepted. We do not send the referring URL or advertising click identifiers. For a completed desktop purchase, our payment provider confirms settlement and we record the product, amount and currency. Cloud checkout completion records signup and the selected plan; it may start a trial or precede payment settlement, so it is not a paid-purchase count. Payment card details never reach our servers or PostHog. If you reject the banner or withdraw consent, nothing further is sent and any campaign remembered for your visit is discarded. There is one exception, and it is bounded: a checkout you had already begun is reported once more when the payment provider tells us whether it completed or expired. That report was set in motion while your consent was in force, it reaches us after you have left the page, and the checkout itself expires within a day.
The essential sd_cookie_consent cookie remembers your choice for one year. After consent, our first-party ph_sd_analytics cookie holds only an anonymous analytics identifier for up to one year. PostHog's page and session details stay in memory rather than being saved in browser storage. Use Cookie settings in the marketing-page footer to withdraw consent at any time; rejection stops future collection and removes the analytics cookie and session identifiers. We honour Global Privacy Control as rejection. Removing browser cookies causes us to ask again. Withdrawal does not erase information already received; contact us to request deletion where applicable.
Optional Google Ads measurement on the website
Advertising measurement is a separate, optional choice from PostHog analytics. Neither choice requires the other, and accepting analytics does not accept advertising measurement. We do not load a Google advertising script, pixel, or SDK. With your advertising-measurement consent, our own website code reads the Google click identifier (GCLID) in an advertising link and remembers that first eligible click for up to 30 days. Ignoring or rejecting this choice does not save an advertising identifier or create a purchase report for Google. This measurement happens on the website, not inside the Desktop App.
The essential first-party sd_ads_consent cookie remembers your advertising choice for one year. Only after acceptance, the first-party sd_ad_attribution cookie holds a signed, random reference to a short-lived server record; it does not contain the GCLID itself. That cookie and the attribution expire 30 days after capture. We stop using expired attribution immediately and remove expired records and their pending purchase reports through our daily retention process. Financial purchase and licence records remain subject to the separate retention rules in section 7.
If you complete a direct Desktop App purchase while that attribution remains valid, we may send Google the click identifier, confirmation time, actual paid amount and currency, an opaque order reference to prevent duplicate counting, and your measurement consent status. This lets Google associate the purchase with an advertisement. Our conversion export does not contain your email address, name, phone number, IP address, payment-card details, licence key, or diagram content. We do not use this information to create remarketing audiences and report advertising personalisation as denied. Read how Google uses business data and the Google Privacy Policy.
Use Cookie settings in the website footer to withdraw advertising-measurement consent. Withdrawal removes this browser's attribution cookie and server attribution, deletes related pending purchase reports, and stops their inclusion in new exports. We honour Global Privacy Control as rejection. Withdrawal cannot undo information already shared with Google; its retention and handling are governed by Google's policies. Contact us about deletion requests. If you remove the browser cookie yourself, we may no longer be able to identify the associated record; it still expires within the 30-day period. Purchases made on a different browser or device may not be attributed.
The embedded Excalidraw software runs as part of our client application; we do not use the hosted excalidraw.com service to store your SimpleDiagrams scenes.
Pages showing account signup, and configured newsletter signup or Contact forms, load Google reCAPTCHA to assess whether a submission is automated. Google receives your IP address and information about how you interact with the page, and may set its own cookies. We receive a verification result; any risk score retained with a newsletter signup is cleared with the rest of its signup context. Google's use of that information is governed by its own privacy policy and terms, linked beside the form. We use reCAPTCHA to reduce automated spam and misuse of these public forms.
11. Children
SimpleDiagrams Cloud is not directed to people under 18 and they may not create Cloud Service accounts. This account restriction does not describe local use of the Desktop App. If an educational institution wants to use SimpleDiagrams Cloud with minors, it must first enter a separate written arrangement addressing authority, notices, safeguarding, and data protection. Contact us if you believe a child has provided personal information.
12. Changes and contact
We may update this policy to reflect product, provider, or legal changes. We will post the new version and give notice of a material change as required by law. Privacy questions, complaints, and rights requests may be sent to support@simplediagrams.com.
We will acknowledge a privacy complaint, investigate it fairly, and ordinarily provide a written response within 30 days. If we need more time, we will explain why and the next step. Our response will describe the outcome and available escalation options. If you are not satisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner through oaic.gov.au.
McQuillen Interactive Pty. Ltd. · ABN 49 600 623 069 · 7/3 Bolinda Street, Bentleigh, Victoria 3204, Australia.