ERD Editor Privacy Terms Support

Privacy Policy

Effective date: September 26, 2026

erd-editor.io is a free, open-source editor for Entity-Relationship Diagrams, run by dineug. This policy explains what the site does with your information, and in particular with the data it receives from Google when you edit files in Google Drive.

The local editor

The editor at erd-editor.io keeps your schemas in your browser's own storage (IndexedDB). Their content leaves your device only when you export them or start a live collaboration session. Their names can also reach the analytics and error reports described below. A session connects browsers directly and uses public relays only to introduce them; what passes through a relay is encrypted with a key that stays in the invite link after the #, a part of the address browsers never send to a server.

Google Drive

What ERD Editor can access

When you sign in with Google at erd-editor.io/gdrive, ERD Editor asks Google for:

The files you create or import at erd-editor.io/gdrive go in a folder named ERD Editor, which ERD Editor creates in your My Drive the first time it needs one. ERD Editor never picks an ERD Editor folder someone else shares with you. It keeps using its own folder after you rename it or move it elsewhere in your My Drive, and makes a new one if the folder is deleted, in the trash, moved to a shared drive, owned by someone else, or no longer lets you add files to it. It also makes a new one after you sign out of ERD Editor or remove its access from your Google Account, since that ends its access to the files it created or opened, the folder included: the earlier folder and the files in it stay in your Google Drive, but ERD Editor can no longer list them. A file you start from Google Drive's New menu goes in the folder you started it from, or in the ERD Editor folder when Google Drive names none. When it names one, you can choose the ERD Editor folder instead, which ERD Editor also suggests if it cannot create files in yours.

Your files never pass through our server

The content, names and list of your files travel directly between your browser and Google Drive. They never pass through an ERD Editor server, and ERD Editor keeps no copy of them, not even in your browser's storage: reopening a file reads it from Google Drive again.

The server keeps encrypted cookies in your browser and no database

ERD Editor has one small server part, a sign-in relay at erd-editor.io/api/auth, running on Cloudflare Pages Functions. It exchanges the code Google gives at sign-in for tokens and renews the short-lived access token your tabs use. It has no database and keeps no record of you or your files.

The refresh token that keeps you signed in is stored only in your browser, in a cookie that is encrypted with a key only the relay holds, that scripts on the page cannot read, and that your browser sends to erd-editor.io alone. The cookie lasts 180 days from the last time ERD Editor used it, and never more than a year from the time you last signed in, after which you sign in again. While you sign in, a second cookie, protected the same way, holds that sign-in's state, including the Google account ID to sign in with when ERD Editor or Google Drive already knows it; it lasts at most 10 minutes and is deleted when the sign-in completes. The access token lives only in the memory of your open ERD Editor tabs. The relay's logs record what happened, such as a sign-in, and never a token, code, cookie or anything about your files. Cloudflare, which hosts the site, processes each request's IP address and headers as any web host does.

Signing out revokes access

Signing out of ERD Editor revokes ERD Editor's access at Google and deletes the cookie that holds the refresh token. Google revokes an app's access for your whole account, so every other device where you use ERD Editor with the same Google account has to sign in again. You can also remove ERD Editor's access at any time from your Google Account's third-party connections.

Analytics, error reports and fonts

erd-editor.io uses Google Analytics to count visits to the local editor, and Sentry to report errors. On the local editor, Google Analytics records the page's title, which names the schema you have open, and an error report can carry the labels of the controls you clicked, the name of a schema among them. Google Analytics is not loaded on the Google Drive pages (erd-editor.io/gdrive) or during sign-in, so it receives nothing from them. There, Sentry keeps no record of what you click or type, and none of the requests to Google. Before a report leaves your browser, the addresses of Google Drive's requests and of the Drive pages lose their file IDs, which become a placeholder, and their query strings. Error reports never carry your Drive files' content or names, your tokens, or your Google account ID or email address.

The editor's pages, the Google Drive pages included, load their font from Google Fonts, which receives your IP address and your browser's details with each request, as any site a page loads a file from does. This policy and the terms load nothing from another site.

Limited Use

ERD Editor's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. ERD Editor uses Google user data only to provide the Google Drive editing you see in the app. It does not sell that data, use it for advertising, let people read it, or use it to train artificial intelligence or machine learning models.

Your choices

Changes to this policy

A change to this policy is published on this page with a new effective date.

Contact

For a question or a request about this policy, email support@erd-editor.io. You can also open an issue at github.com/dineug/erd-editor/issues; issues are public, so leave personal details out of them.