legal

Privacy Policy

last updated · August 24, 2026

1. Who We Are

Gramit is a diagramming tool that lets you create, edit, and share hierarchical diagrams. For the purposes of this policy, Gramit acts as the data controller for personal data collected through the service.

For any privacy-related inquiries, contact us at privacy@gramit.io.

2. Data We Collect

We collect only what is necessary to provide the service:

  • Account data — email address and display name, provided during registration or via a social login provider (Google or Microsoft).
  • Profile photo — an avatar image you optionally upload.
  • Diagram content — the diagrams you create and save while using Gramit.
  • Technical data — anonymized error reports used solely to diagnose and fix software bugs. No personal identifiers are included.
  • Usage statistics — aggregate, cookieless measurements of how our public pages are used: the page visited, the site that referred you, and general browser, device and country information. This data is never linked to your account or to your diagrams, and your IP address is used only to derive an approximate country and is not stored.

We set no cookies for tracking or analytics, and we store nothing on your device for those purposes. Our usage statistics are aggregate and cannot identify you or follow you across other websites. We do not run advertising networks or sell data to third parties.

3. Why We Process Your Data

We process your personal data under the following legal bases (LGPD Art. 7):

  • Contract performance (Art. 7, II) — account data and diagram content are required to provide the service you signed up for.
  • Legitimate interest (Art. 7, IX) — anonymized error data helps us keep the service stable and secure, and aggregate usage statistics tell us which pages are worth keeping. Neither identifies you, so neither impacts your privacy.
  • Consent (Art. 7, I) — profile photos are processed only when you choose to upload one.

4. Third-Party Service Providers

We use trusted third-party services to operate Gramit. Each provider processes only the data necessary for their function and is bound by data processing agreements:

  • Authentication service — handles secure login, including social login via Google and Microsoft. Receives your email, hashed credentials, and name.
  • Cloud database provider — stores your diagrams, preferences, and account data.
  • File storage provider — stores profile avatar images.
  • Error monitoring service — receives anonymized crash reports with no personal identifiers.
  • Analytics service — receives aggregate page view statistics. It sets no cookies, stores no IP addresses and holds no personal identifiers.

No data is transferred to providers outside the contexts described above.

5. Your Rights

Under the LGPD (Art. 18) and applicable US privacy laws (CCPA/CPRA), you have the following rights:

  • Access — request a copy of all personal data we hold about you.
  • Portability — export your data in machine-readable JSON format directly from your account settings.
  • Correction — update your name or profile photo at any time in account settings.
  • Erasure — permanently delete your account and all associated data from your account settings. Deletion is irreversible.
  • Revocation of consent — remove your profile photo at any time; this revokes consent for processing that specific data.

To exercise any right or submit a complaint, use the tools in your account settings or contact privacy@gramit.io. We respond within 15 business days.

6. Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal data — including diagrams, preferences, and profile information — is permanently erased from our systems within 30 days. Anonymized, non-identifiable error logs may be retained for up to 90 days for operational purposes.

7. Data Security

We apply industry-standard security measures including encryption in transit (TLS), encryption at rest, and access controls that follow the principle of least privilege. No method of transmission or storage is 100% secure; we encourage you to use a strong, unique password and to enable multi-factor authentication on your account.

8. Children

Gramit is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes, we will notify you via email or a prominent notice within the app before the change takes effect.

gramit

diagrams, all the way down

docsprivacytermsopen the whiteboard ↗© 2026