Privacy Policy
Last updated: 19 July 2026. This policy explains what BPMN Studio collects, why, who else sees it, and what you can do about it. If anything here is unclear, email the address below and ask.
Who is responsible
BPMN Studio (bpmnstudio.com) is an independent project built and operated by Emilis Mikalajūnas, who is the data controller for the purposes of the EU General Data Protection Regulation (GDPR).
Contact: mikalajunas.emilis@gmail.com
There is no appointed Data Protection Officer — the project is below the threshold that requires one.
What we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address and authentication credentials | To create and secure your account | Contract (Art. 6(1)(b)) |
| Process descriptions and conversation messages you type | To generate your diagram | Contract |
| Generated BPMN diagrams and their XML | To save your work and show it in your library | Contract |
| Plan, usage counters, generation counts | To enforce plan limits and bill correctly | Contract |
| Billing details (card data handled by Stripe, never by us) | To take payment | Contract, legal obligation (tax records) |
| Analytics events — pages viewed, referrer, approximate region, device type | To understand which parts of the site are useful | Consent only (Art. 6(1)(a)) |
| Server logs, rate-limit counters, error traces | To keep the service available and resist abuse | Legitimate interest (Art. 6(1)(f)) |
We do not buy data about you, we do not sell or rent your data, and we do not run advertising profiling.
Your prompts and the AI model
This is the disclosure that matters most for a tool like this, so it gets its own section.
The process descriptions you type are sent to OpenAI. BPMN Studio has no model of its own. When you talk to the wizard or press Generate, your conversation is transmitted to OpenAI's API, which returns the wizard's reply or the BPMN XML.
What this means in practice:
- Do not paste confidential or personal data into a process description. Describe roles ("claims handler"), not named individuals; describe steps, not customer records. Anything you type leaves our servers.
- Under OpenAI's API data usage policy, data submitted through the API is not used to train OpenAI's models, and is retained by OpenAI for a limited abuse-monitoring window before deletion.
- OpenAI processes this data in the United States. See International transfers below.
- No other AI provider receives your prompts. OpenAI is the only model provider in the stack.
Who else processes your data
These are our sub-processors. Each has access only to what its function requires.
| Sub-processor | Purpose | Data it sees | Location |
|---|---|---|---|
| Supabase | Database, authentication | Account email, diagrams, process descriptions at rest | EU / US |
| OpenAI | Wizard conversation and diagram generation | Process descriptions and conversation content | US |
| Stripe | Payments and subscription management | Name, email, card data (collected directly by Stripe) | US / EU |
| Vercel | Hosting, serverless functions, cookieless page analytics | Request metadata, IP address in transit | Global edge |
| Google (Analytics 4) | Site analytics — only if you consent | Pseudonymous usage events | US / EU |
Card numbers never reach our servers: checkout happens on Stripe's own hosted page.
International transfers
Some of the processors above are in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. You can request a copy of the relevant transfer safeguards at the contact address above.
Cookies and analytics
Google Analytics runs in Consent Mode v2 (advanced). Before you make a choice, no analytics cookies are set — the tag sends only cookieless pings containing a timestamp, user agent, referrer and your consent state. Analytics cookies (_ga) are set only after you accept the Analytics category. Rejecting costs you nothing and no feature is withheld.
GA4 anonymises IP addresses by default and does not log IP addresses from cookieless pings. We do not enable Google signals or cross-device advertising personalisation.
The full cookie inventory, and the control to change your mind at any time, is on the Cookie Policy page.
How long we keep things
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Diagrams and conversations | Until you delete them, or until account deletion |
| Google Analytics event data | 14 months |
Consent record (bs_consent) |
12 months, then you are asked again |
| Stripe payment and invoice records | As required by tax law (typically 7–10 years) |
| Server and error logs | Short-lived, retained by Vercel per its platform defaults |
Deleting your account removes your diagrams and conversation history from the database. Backup copies age out on the storage provider's own cycle.
Security
Diagrams and conversations are stored in PostgreSQL with Row-Level Security enabled: policies are enforced in the database itself, so one account's queries cannot return another account's rows even if application code is wrong. Traffic is served over HTTPS. API endpoints are rate-limited. Payment card data never touches our infrastructure.
No system is perfectly secure, and we make no absolute guarantee. If a breach affects your rights, we will notify the relevant supervisory authority within 72 hours and inform you where the law requires it.
Your rights
Under the GDPR you can:
- Access — request a copy of the data we hold about you
- Rectify — have inaccurate data corrected
- Erase — have your account and data deleted
- Port — receive your data in a machine-readable format (your diagrams also export directly from the app)
- Restrict or object — to processing based on legitimate interest
- Withdraw consent — for analytics, at any time, via Cookie settings, with no effect on processing already carried out
- Complain — to your national supervisory authority. In Lithuania this is the State Data Protection Inspectorate (VDAI)
Email the contact address to exercise any of these. We aim to respond within 30 days.
Children
BPMN Studio is a business tool and is not directed at children under 16. We do not knowingly collect data from them. If you believe a child has created an account, tell us and we will delete it.
Changes
Material changes to this policy will move the Last updated date above, and — where the change affects how we use your data — you will be asked for consent again before it takes effect.