Open the Designer

Privacy Policy

Last updated: 19 July 2026. This policy explains what BPMN Studio collects, why, who else sees it, and what you can do about it. If anything here is unclear, email the address below and ask.

Who is responsible

BPMN Studio (bpmnstudio.com) is an independent project built and operated by Emilis Mikalajūnas, who is the data controller for the purposes of the EU General Data Protection Regulation (GDPR).

Contact: mikalajunas.emilis@gmail.com

There is no appointed Data Protection Officer — the project is below the threshold that requires one.

What we collect

Data Why Legal basis
Email address and authentication credentials To create and secure your account Contract (Art. 6(1)(b))
Process descriptions and conversation messages you type To generate your diagram Contract
Generated BPMN diagrams and their XML To save your work and show it in your library Contract
Plan, usage counters, generation counts To enforce plan limits and bill correctly Contract
Billing details (card data handled by Stripe, never by us) To take payment Contract, legal obligation (tax records)
Analytics events — pages viewed, referrer, approximate region, device type To understand which parts of the site are useful Consent only (Art. 6(1)(a))
Server logs, rate-limit counters, error traces To keep the service available and resist abuse Legitimate interest (Art. 6(1)(f))

We do not buy data about you, we do not sell or rent your data, and we do not run advertising profiling.

Your prompts and the AI model

This is the disclosure that matters most for a tool like this, so it gets its own section.

The process descriptions you type are sent to OpenAI. BPMN Studio has no model of its own. When you talk to the wizard or press Generate, your conversation is transmitted to OpenAI's API, which returns the wizard's reply or the BPMN XML.

What this means in practice:

  • Do not paste confidential or personal data into a process description. Describe roles ("claims handler"), not named individuals; describe steps, not customer records. Anything you type leaves our servers.
  • Under OpenAI's API data usage policy, data submitted through the API is not used to train OpenAI's models, and is retained by OpenAI for a limited abuse-monitoring window before deletion.
  • OpenAI processes this data in the United States. See International transfers below.
  • No other AI provider receives your prompts. OpenAI is the only model provider in the stack.

Who else processes your data

These are our sub-processors. Each has access only to what its function requires.

Sub-processor Purpose Data it sees Location
Supabase Database, authentication Account email, diagrams, process descriptions at rest EU / US
OpenAI Wizard conversation and diagram generation Process descriptions and conversation content US
Stripe Payments and subscription management Name, email, card data (collected directly by Stripe) US / EU
Vercel Hosting, serverless functions, cookieless page analytics Request metadata, IP address in transit Global edge
Google (Analytics 4) Site analytics — only if you consent Pseudonymous usage events US / EU

Card numbers never reach our servers: checkout happens on Stripe's own hosted page.

International transfers

Some of the processors above are in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. You can request a copy of the relevant transfer safeguards at the contact address above.

Cookies and analytics

Google Analytics runs in Consent Mode v2 (advanced). Before you make a choice, no analytics cookies are set — the tag sends only cookieless pings containing a timestamp, user agent, referrer and your consent state. Analytics cookies (_ga) are set only after you accept the Analytics category. Rejecting costs you nothing and no feature is withheld.

GA4 anonymises IP addresses by default and does not log IP addresses from cookieless pings. We do not enable Google signals or cross-device advertising personalisation.

The full cookie inventory, and the control to change your mind at any time, is on the Cookie Policy page.

How long we keep things

Data Retention
Account and profile Until you delete your account
Diagrams and conversations Until you delete them, or until account deletion
Google Analytics event data 14 months
Consent record (bs_consent) 12 months, then you are asked again
Stripe payment and invoice records As required by tax law (typically 7–10 years)
Server and error logs Short-lived, retained by Vercel per its platform defaults

Deleting your account removes your diagrams and conversation history from the database. Backup copies age out on the storage provider's own cycle.

Security

Diagrams and conversations are stored in PostgreSQL with Row-Level Security enabled: policies are enforced in the database itself, so one account's queries cannot return another account's rows even if application code is wrong. Traffic is served over HTTPS. API endpoints are rate-limited. Payment card data never touches our infrastructure.

No system is perfectly secure, and we make no absolute guarantee. If a breach affects your rights, we will notify the relevant supervisory authority within 72 hours and inform you where the law requires it.

Your rights

Under the GDPR you can:

  • Access — request a copy of the data we hold about you
  • Rectify — have inaccurate data corrected
  • Erase — have your account and data deleted
  • Port — receive your data in a machine-readable format (your diagrams also export directly from the app)
  • Restrict or object — to processing based on legitimate interest
  • Withdraw consent — for analytics, at any time, via Cookie settings, with no effect on processing already carried out
  • Complain — to your national supervisory authority. In Lithuania this is the State Data Protection Inspectorate (VDAI)

Email the contact address to exercise any of these. We aim to respond within 30 days.

Children

BPMN Studio is a business tool and is not directed at children under 16. We do not knowingly collect data from them. If you believe a child has created an account, tell us and we will delete it.

Changes

Material changes to this policy will move the Last updated date above, and — where the change affects how we use your data — you will be asked for consent again before it takes effect.