Privacy Policy
Effective 6 September 2026
YourERD ("the Service") takes your privacy seriously. This policy explains what information the Service collects, what it is used for, how long it is kept, and what you can do about it.
1. What we collect
a. When you create an account
The Service does not collect your email address, real name, or phone number. Creating an account stores only the following:
- Username — a string you choose. It does not have to be your real name or an email address.
- Password — never stored as written. Only a scrypt hash is kept, so the operator cannot recover your original password.
- Account creation time
b. While you use the Service
- Diagram data — stored only when you choose to save. This covers the diagram name and its contents (entities, columns, relationships, memos and so on).
- MCP personal tokens — used to connect external tools. The token itself is never stored; only its SHA-256 hash, a label, and the creation and last-used times.
- Share link records — when you issue a share link, the Service keeps the SHA-256 hash of the token, the permission level, and the creation, last-used and revocation times.
If you use the Service without signing in, your diagrams are never sent to the server.
c. Collected automatically
- Server logs — for operations and troubleshooting, request times, paths, response statuses and IP addresses may be recorded.
2. How we use it
- Identifying you and keeping you signed in
- Saving, listing and sharing your diagrams
- Authenticating external tool (MCP) connections
- Keeping the Service running and diagnosing faults
We do not use this information for any other purpose.
3. Cookies and local storage
a. Cookies set by the Service
-
Authentication cookie (
token) — required to keep you signed in. It is a JWT markedhttpOnly, so scripts cannot read it, and it expires seven days after it is issued.
b. Browser local storage
These stay in your browser and are never sent to the server:
- Your chosen interface language and theme
- The identifier of the last diagram you opened
- The state of the canvas you are working on
c. Refusing cookies
You can block cookies in your browser settings. Blocking the authentication cookie means you cannot sign in, but drawing diagrams and exporting them to files continues to work.
4. Advertising and third parties
a. Google AdSense
The Service uses Google AdSense to help cover running costs.
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to this and other sites.
- You may opt out of personalised advertising at Google Ads Settings, or opt out of third-party vendors' use of cookies at www.aboutads.info.
- See Google's privacy policy for details on how Google handles this data.
b. Google Fonts
The Service loads typefaces from Google Fonts. Your IP address may be transmitted to Google's servers as part of fetching those font files.
5. Sharing with third parties
We do not sell or hand over your personal information to third parties. We may disclose information where a law enforcement authority requires it through a lawful process, and only to the extent the law requires. Our relationship with Google for advertising and fonts is described in section 4.
6. Retention and deletion
- Account information and diagrams are kept until you delete them or close your account.
- Deleting an account also deletes that account's diagrams, MCP tokens and share link records.
- Deleting an individual diagram removes it from the database immediately.
- Server logs are retained only as long as operationally necessary and then removed.
7. Your rights
- Access and correction — saved diagrams can be opened and edited from the list once you sign in.
- Deletion — you can delete diagrams yourself from the list. For account deletion, contact us at the address below.
- Disconnecting — MCP tokens and share links can be revoked directly in the editor.
8. Security measures
- Passwords are stored only as scrypt hashes; the originals are never kept.
- MCP tokens and share link tokens are stored only as SHA-256 hashes.
- All traffic is encrypted with HTTPS.
- The authentication cookie is marked
httpOnlyto prevent script-based theft.
9. Children
The Service is not directed at children under 14 and does not knowingly collect their personal information.
10. Contact
For questions about how your data is handled, to request account deletion, or to raise a complaint, contact:
- Data protection contact: YourERD operator
- Email: toughmon777@gmail.com
The Service is operated from the Republic of Korea. Korean residents may also contact the Korea Internet & Security Agency's Privacy Infringement Report Centre (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (www.kopico.go.kr, 1833-6972).
11. Changes to this policy
If this policy changes, we will post the update on this page before it takes effect. The revised policy applies from the moment it is posted here.