Privacy Policy

Last updated: 2026-07-26

This policy covers viztext.com (the website) and the text2diagram Chrome extension (the extension). It explains what data is processed when you use Quick mode, sign in, or use Chat mode.

Information we process

  • Quick mode prompts. When you generate a diagram, your prompt, selected diagram type and language, and any context needed to complete the request are sent to our API and AI provider. Quick mode prompts and generated code are not stored in our application database. They may exist briefly in in-memory caches used to reduce latency and cost. Production application logs omit prompt and diagram content but retain operational metadata such as request time, route, prompt length, model, status, and latency.
  • Account information. Chat mode requires Google sign-in. Google may provide your name, email address, profile image, and provider account identifier. Authentication records and tokens required to maintain the connection may be stored. We do not receive or store your Google password.
  • Chat and Agent data. To maintain multi-turn context, we store your Chat messages, assistant replies, diagram type and language, structured diagram specifications, session state, and generated diagram code under your account. This content is also sent to the AI provider when needed to continue or generate the diagram.
  • Rate-limit and security data. Anonymous usage is counted using an IP-address-based daily key. Signed-in usage is counted using an account identifier. Daily counters normally expire at the next 00:00 UTC. Hosting providers may also process IP addresses, request headers, and security logs to deliver and protect the service.
  • Usage and performance analytics. We use Vercel Analytics, Vercel Speed Insights, and, when configured, Google Analytics 4. These services may process page paths, referrers, approximate country, device/browser information, IP-derived data, and performance metrics. We do not use this information to build advertising profiles.
  • Cookies and local storage. Authentication uses a secure session cookie/JWT. Analytics providers may set their own identifiers. The website also stores non-sensitive interface preferences, such as preview layout, in your browser.

How AI content is handled

Prompt and conversation content is sent to one or more configured third-party large language models solely to classify, clarify, generate, validate, or repair a diagram. The model provider may change over time and processes that content under its own terms and privacy policy. Do not submit secrets, passwords, payment-card data, health records, or other information you are not authorized to share.

Chrome extension

The extension is distributed separately from the website source. A released version may let you send text you explicitly select to viztext.com as a pre-filled Quick mode prompt, as described in its current store listing and permission screen. When you invoke that action, the selected text is handled under the Quick mode rules above. If a released version places selected text in a URL, the text may also appear in browser history and hosting request records. Review the permissions shown by your browser before installation and do not use the extension on confidential text.

Third-party services

  • Large language model providers — process prompts and conversation context when needed for AI diagram generation. The provider may change as the service evolves.
  • Google — provides OAuth sign-in and, when enabled, Google Analytics 4. See Google's privacy policy.
  • Vercel and its infrastructure providers — hosting, database connectivity, runtime logs, analytics, and performance monitoring. See Vercel's privacy policy.
  • Upstash — stores short-lived rate-limit counters when the production Redis integration is enabled. See Upstash's privacy policy.

We do not sell personal data and do not share it for cross-context behavioral advertising.

Retention

  • Quick mode content is not written to the application database; short-lived caches disappear when they expire or the process ends.
  • Daily rate-limit counters normally expire at the next 00:00 UTC.
  • Account and Chat records are retained while needed to provide the account and conversation service, unless you request deletion. Agent-loop sessions are marked expired and become inaccessible after 30 days of inactivity. Expired database records are not currently deleted automatically; they remain until a manual/system cleanup or a verified deletion request. Backups may take longer to be removed.
  • Hosting, security, and analytics records follow the retention settings and policies of the applicable provider.

Your choices and rights

You may ask to access, correct, export, or delete account and Chat data, or object to particular processing. Email [email protected] from the address associated with your account so we can verify the request. You can also sign out at any time and use Quick mode without an account. Browser or content-blocking settings can limit analytics, though they may also affect sign-in or site functionality.

Security

We use access controls, secure transport, provider-managed credentials, and production log filtering intended to protect user data. No online service can guarantee absolute security, so please avoid submitting confidential information that is not necessary to create the diagram.

Changes

If our data practices materially change, we will update the date at the top of this page and, when appropriate, provide an additional notice.

Contact

Privacy or data requests: [email protected]. For public bug reports and feature requests, use GitHub, but do not post personal or confidential information there.

← Back to text2diagram · 中文版