Privacy policy

Last updated 1 October 2026

The short version
  • Without an account, your drawings stay in your browser. We never receive them.
  • With an account, we store your email address, a scrambled (hashed) form of your password, and a copy of your pages so they can sync between your devices.
  • No adverts, no analytics, no tracking, and we never sell your data.
  • You can delete your account, and its cloud copy, at any time from the app.

Who we are

epicdraw ("we", "us") is the diagram editor at epicdraw.app. We are the data controller for the personal data described here. Contact us at support@epicdraw.app about anything in this policy.

Using epicdraw without an account

You can use every drawing feature without an account. Your pages, pictures, recovery copies and settings are saved by your own browser on your own device (in its IndexedDB and local storage), and a copy of the app is kept in your browser's offline cache. This data is not sent to us and we cannot see it, recover it or delete it for you. Clearing your browser's site data removes it, so download a backup for anything you want to keep.

Like any website, loading epicdraw means your browser connects to our hosting provider, Cloudflare. Cloudflare processes your IP address and basic request details to deliver the site and protect it from attacks. See "Hosting and logs" below.

What we collect if you create an account

DataWhyLawful basis
Email addressTo identify your account and let you sign inContract: providing the sync service you asked for
Password, stored only as a salted PBKDF2 hashTo check it is you when you sign in. We cannot read your password.Contract
Your pages (the workspace you sync), including any pictures you addedTo keep a cloud copy and sync it to your other devicesContract
Sign-in sessions (a random token, stored hashed, with created and expiry times)To keep you signed in for up to 30 daysContract
Account creation time, when you were last active, last sync time, count of recent failed sign-insTo run the service, understand how many accounts are in use, and protect accounts from password guessingLegitimate interests: running and securing the service
Pages you choose to share as a link, their settings (including a hashed link password), when they were shared and how many times they were openedTo show the page to people you send the link toContract
Changes viewers make to the interactive parts of a link set to "shared with everyone"So everyone with that link sees the same ticks, votes and card movesContract (for the link owner)
Password-reset links (stored hashed, valid for one hour)To let you choose a new password by emailContract
IP address, brieflyTo limit how often sign-in and sign-up can be triedLegitimate interests: preventing abuse

We only email you when you ask for a password reset. We don't send marketing. We do not ask for your name, and we do not look at the content of your pages except where needed to keep the service running, to deal with a problem you report, or where the law requires it.

Cookies and browser storage

We set one cookie, ed_session, and only after you sign in. It is strictly necessary to keep you signed in, is limited to our sync API, cannot be read by page scripts, and expires after 30 days or when you sign out. Because it is strictly necessary, we do not ask for consent. We use no advertising, analytics or third-party cookies.

If you open a password-protected share link and enter the right password, we set a strictly necessary cookie, ed_share_<link>, so you aren't asked again for 30 days. It only works for that link.

The app also uses your browser's storage to save your work, to remember sync progress, and to keep your own taps on share links set to "just for themselves". This stays on your device.

Who processes your data for us

We do not sell or rent personal data, and we share it with nobody else unless the law requires us to.

Hosting and logs

Cloudflare processes connection data (such as IP address, browser type and the pages requested) to serve and secure the site. We do not use this to build profiles of visitors. Our own error logs may briefly include technical details of failed requests, but never passwords or page contents.

How long we keep it

Security

All traffic uses HTTPS. Passwords are salted and hashed, session tokens are stored only in hashed form, cross-site requests to the API are blocked, and repeated failed sign-ins temporarily lock the account. No system is perfectly secure, so please use a password you don't use anywhere else.

Your rights

Under UK data protection law (the UK GDPR and the Data Protection Act 2018), you can ask us to:

Email support@epicdraw.app and we'll reply within one month. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk, but we'd appreciate the chance to sort it out first.

Children

Anyone can use epicdraw without an account. Accounts are for people aged 13 or over. If you believe a child under 13 has created an account, contact us and we will delete it.

Changes to this policy

If we change how we handle personal data, we'll update this page and the date at the top. If a change materially affects account holders, we'll tell you in the app before it takes effect.