Privacy Policy
Last updated: August 22, 2026
SVGSketch LLC (“we,” “us,” or “our”), a Massachusetts limited liability company, operates the SVGSketch application and website. This Privacy Policy explains what information we collect, how we use it, and your choices regarding your data.
1. Information We Collect
Information You Provide
You can sign in with Google, GitHub, Microsoft, or Discord. Whichever provider you choose, we receive and store:
- Name: your display name from the provider account
- Email address: used to identify your account. If you sign in with a different provider that reports the same email address, the sign-ins are linked to the same SVGSketch account.
- Profile picture: displayed in the application and to people you collaborate with. For Microsoft accounts we store a copy of the profile photo itself; for other providers we store its URL. If your provider supplies no picture, we generate a placeholder avatar by sending your display name to the ui-avatars.com service.
- Provider account ID: a unique identifier used to link your data to your account
Documents and Content
If you use cloud storage features, we store your SVG documents and project data on our servers so you can access them across sessions and devices. Images and other media embedded in cloud documents are stored separately as content-addressed files.
Payment Information
Pro subscriptions are billed through Stripe. Your card number and billing details are collected and processed by Stripe directly and never touch our servers. We store only your Stripe customer and subscription identifiers and the subscription status (for example: active, trialing, canceled).
AI Features
When you use the AI generation feature, your text prompt, and, when you transform existing artwork, the SVG markup of the shapes you selected, are sent to Anthropic to generate the result. If you configure your own OpenAI API key, those requests go to OpenAI instead, authenticated with your key. Your own API keys are stored only in your browser and are never saved on our servers. We do not use your prompts or artwork to train models.
Automatically Collected Information
We process standard request metadata, including IP addresses, browser type, and pages visited, for security monitoring, abuse prevention, rate limiting, and service reliability. We do not store IP addresses in our application database.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Store and serve your documents via cloud storage
- Manage billing and subscriptions
- Fulfill AI generation requests you make
- Send transactional email about your account (for example: welcome, billing, and account deletion notices). We do not send marketing email.
- Detect, prevent, and address abuse or security issues
We do not sell your personal information. We do not use your data for advertising or profiling.
3. Local-Only Usage
SVGSketch can be used entirely without an account. When used locally (without signing in):
- Your artwork is stored in your browser’s storage and stays on your device. It is never uploaded to our servers.
- Clearing your browser data will remove locally stored work
- Anonymous product analytics (see Section 6) still run in the editor unless you opt out. No account information exists in this mode, so analytics are tied only to a random visitor identifier.
4. Data Storage and Security
Your data is stored on Cloudflare infrastructure, including:
- Cloudflare D1: account data, documents, sharing settings, and subscription status
- Cloudflare R2: images and media embedded in cloud documents
- Cloudflare Durable Objects: the live state of documents being edited, including a stored snapshot that enables real-time collaboration. Snapshots are erased when the document or the account is deleted.
We use HTTPS for all data transmission. Session cookies are HTTP-only and cryptographically signed so they cannot be forged or tampered with. We implement reasonable administrative, technical, and physical security measures to protect your data.
5. Cookies
We use a minimal number of cookies, all set on our own domains:
- Session cookie (
svgsketch_session): a signed, HTTP-only cookie used to maintain your login session. It expires after 7 days. - Sign-in security cookie (
svgsketch_session_oauth): a short-lived cookie (10 minutes) that protects the sign-in flow against cross-site request forgery - Analytics cookie (
ph_*): a first-party cookie set by our analytics, used to recognize returning visitors across our marketing site, editor, and documentation. Not shared with advertisers.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
6. Analytics
We use PostHog for product analytics so we can understand how the editor and marketing site are used and prioritize improvements. Analytics requests are reverse-proxied through our own API domain: our proxy strips cookies from the request and forwards your IP address to PostHog so it can derive an approximate (city-level) location, after which the IP address is discarded rather than stored.
What we collect:
- Page views and basic interaction events (e.g. which tools are used in the editor)
- A randomly generated visitor identifier (no name, email, or address from anonymous visitors)
- If you sign in: your account ID and email so we can associate prior anonymous activity with your account
- Approximate location based on IP address (city-level), as described above
- Error reports when something breaks, including the technical stack trace of the error
- Session replays of your editor sessions, used to debug usability issues. A replay is a recording of your editor screen, so it includes the artwork you are editing on the canvas. Text typed into input fields is masked before recording. Replays are used solely to diagnose usability problems and bugs.
PostHog Cloud processes this data in the United States. For visitors in the European Economic Area, this means data is transferred to the US under PostHog’s standard contractual clauses. PostHog’s privacy policy: posthog.com/privacy.
How to opt out: we honor the browser’s Do Not Track and Global Privacy Control signals automatically. You can also disable analytics (including session replay and error reports) for your browser at any time from inside the editor’s privacy settings, or by clearing the ph_* cookie.
7. Third-Party Services
We use the following third-party services:
- Google, GitHub, Microsoft, and Discord OAuth: for authentication. Each provider’s privacy policy applies to data they process during sign-in: Google, GitHub, Microsoft, Discord
- Cloudflare: for hosting, CDN, and data storage: Cloudflare Privacy Policy
- Stripe: for payment processing: Stripe Privacy Policy
- Resend: for delivering transactional email: Resend Privacy Policy
- Anthropic (and OpenAI, only if you bring your own API key): for AI generation, as described in Section 1: Anthropic, OpenAI
- Pixabay, Pexels, Unsplash, and Openverse: when you search the built-in stock image library, your search terms are forwarded to these providers. Unsplash images load directly from Unsplash’s CDN, which can see your IP address.
- ui-avatars.com: generates a placeholder avatar from your display name when your sign-in provider supplies no picture
- Google Fonts: loaded in the editor for text rendering and on our documentation site. Google may collect your IP address when fonts are loaded: Google Fonts Privacy
If an SVG you import references fonts or images hosted elsewhere on the web, the editor asks for your permission before fetching them; the host can see your IP address if you approve.
8. Collaboration and Sharing
When you use real-time collaboration or share a document:
- People you collaborate with see your name, email address, and profile picture, plus your live cursor position and current selection while you are in the same document
- Collaborators are invited by email address
- Live presence data (cursors, selections) is transient: it is broadcast to other participants in the moment and never stored
- Share links grant access to anyone who has the link and is signed in, at the permission level you choose. You can revoke a share link at any time.
9. Your Rights and Choices
You have the right to:
- Access your data: you can view and export all your documents at any time through the editor
- Delete your data: you can delete individual documents from cloud storage, or delete your entire account and all associated data from the editor’s account settings. You can also email us to request deletion.
- Correct your data: your name and picture come from your sign-in provider; correcting them there updates them here on your next sign-in. Contact us for anything else.
- Use the Service without an account: core editing features work locally without signing in
- Withdraw consent: you can revoke SVGSketch’s sign-in access at any time in your provider’s settings: Google, GitHub, Microsoft, or Discord’s Authorized Apps settings
If you are in the European Economic Area, the United Kingdom, or Switzerland, you additionally have the rights under the GDPR to access, rectify, erase, and receive a portable copy of your personal data, to restrict or object to our processing of it, and to lodge a complaint with your local supervisory authority. To exercise any of these rights, contact us at the address in Section 13.
If you are a California resident, the CCPA/CPRA gives you rights to know, correct, and delete the personal information we hold about you, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined in the CCPA, and we honor the Global Privacy Control signal as an opt-out. We will never discriminate against you for exercising your privacy rights.
10. Data Retention
We retain your account data and documents for as long as your account is active. If you delete your account, we will remove your personal data and documents within 30 days. This includes your account record, documents and their live collaboration snapshots, embedded media files, your analytics profile, and your Stripe customer record. Aggregated, anonymized data that cannot identify you may be retained for analytics purposes.
11. Children’s Privacy
SVGSketch is not directed to children under 13. We do not knowingly collect personal information from children under 13, or from children under 16 in the European Economic Area. If we become aware that we have collected data from a child below these ages, we will take steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Continued use of the Service after changes constitutes acceptance of the new policy.
13. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at support@svgsketch.com.