ErdForgeData modeling workspace · v1.1.0

Privacy policy

Privacy Policy

ErdForge processes personal data only as needed to provide ERD authoring, team collaboration, email verification, and MCP integration. This policy explains what we collect, why we collect it, and how users can exercise their rights.

Effective date: August 18, 2026

1. Purpose of processing

  • Identify members, verify email, log in, and manage accounts.
  • Create workspaces, save ERDs, invite teams, and manage collaboration permissions.
  • Issue MCP tokens, limit workspace scope, and verify integration requests.
  • Prevent security incidents, analyze errors, operate the service reliably, and respond to support requests.

2. Personal data processed

CategoryItems
Account creation and authentication

Email, password authentication data, email verification token hashes, password reset token hashes, Google login identifier, display name, user ID, account status, and role.

Team and workspace collaboration

Team membership, invitation email, invitation status, workspace permissions, ERD table, column, relationship, note, and diagram settings data.

MCP integration

Token name, token identifier and hash, token prefix, expiration date, accessible workspace scope, and last used time.

Service operations

Session token hash, IP address, browser/device User-Agent, last access time, error records, and security response logs.

ErdForge does not store raw passwords, raw MCP tokens, or Google OAuth access tokens. We store only hashes or identifiers needed for authentication and verification.

3. Retention

We delete personal data without delay after the processing purpose is fulfilled, unless minimum records are needed for deletion evidence, recovery from mistakes, abuse prevention, dispute response, or legal retention requirements.

  • Active account data: until account withdrawal, account deletion completion, or service termination.
  • Deleted user evidence: separated and retained for 3 years with only user ID and email hash.
  • Unverified signup data: deleted after 30 days from signup request or verification email dispatch.
  • Deleted workspace backups: retained temporarily for up to 1 day, with up to 10 backup slots per user.

4. Third parties and processors

ErdForge does not sell personal data. We may use processors for email delivery, traffic routing, security, and Google account authentication where needed to provide the service.

5. User rights

Users may request access, correction, deletion, or suspension of processing. Contact us by email and we will take action after verifying the requester.

6. AI ERD processing

For approved members, ErdForge uses the OpenAI API for ERD generation, refinement, and review. We send the member's requirements and selected logical schema: either the unsaved draft or the single saved ERD explicitly selected for read-only review. We do not search other workspaces or send actual database rows.

  • Do not enter actual personal values, passwords, API keys, connection strings, trade secrets, or other confidential information.
  • Logical field names and types are allowed, but actual email addresses, phone numbers, and credentials must not be entered.
  • OpenAI states that API data is not used to train OpenAI models by default unless the customer explicitly opts in.
  • ErdForge uses store: false where available, but this is not a no-retention or Zero Data Retention guarantee. See the OpenAI API data controls and OpenAI Data Processing Addendum.
  • Cloudflare Turnstile may process limited device and network signals during signup and risk-based AI requests.

ErdForge encrypts unsaved AI drafts and keeps them for idempotent retries and refinement sessions for up to two hours. OpenAI abuse-monitoring logs may include prompts and responses and are generally retained for up to 30 days by default, subject to longer retention where legally required or reasonably necessary to prevent harm.

7. Overseas transfer for AI features

This operational notice reflects Article 28-8 of Korea's Personal Information Protection Act, the PIPC overseas-transfer guidance, and the PIPC explanation of required notice items.

Recipient and contactTransfer details
OpenAI, OpCo, LLC
[email protected]

Items: AI requirements and the unsaved or explicitly selected logical schema. Country: see the OpenAI subprocessor list and processing locations, updated July 9, 2026; ErdForge does not infer a single current country. Timing and method: encrypted HTTPS when the member requests generation, refinement, or review. Purpose: provide those AI results. Retention: ErdForge draft retention and OpenAI abuse-monitoring criteria described above. Refusal and effect: do not use or cancel before sending the AI request; regular editing remains available, but AI generation, refinement, and review will not be provided.

Cloudflare, Inc.
[email protected]

Items: IP address, TLS fingerprint, User-Agent, sitekey, and associated origin. Country: ErdForge does not state that Turnstile necessarily processes in every listed country. The official source for Cloudflare Group and subprocessor processing locations is the Cloudflare services subprocessor list, last updated October 1, 2025. Timing and method: encrypted HTTPS when signup or a risk-based AI challenge is required. Purpose: bot detection and abuse prevention. Retention: the criteria in the Cloudflare Turnstile Privacy Addendum and applicable contract. Refusal and effect: do not continue the challenged request; the affected signup or AI request cannot be completed.

This operational notice is not legal advice. The policy and overseas-transfer notice require review by a Korean privacy professional before AI is enabled in production.

8. Cookies

ErdForge uses essential cookies for login sessions, language preference, and the last selected workspace. These cookies are not used for advertising tracking and can be deleted through logout or browser settings.

9. Privacy contact

Send privacy requests, complaints, or rights-related inquiries to:

[email protected]