LEGAL

Privacy Policy

Last updated: July 26, 2026

This page is provided as a good-faith, plain-language description of what ERD Factory actually does with your data, based on how the product is built today. It is not legal advice, and it hasn't been reviewed by a lawyer. Have counsel review it before relying on it for compliance purposes.

This policy explains what personal data ERD Factory ("we", "us") collects when you use the app at erdfactory.com, why we collect it, who we share it with, and the rights you have over it. It applies alongside our Cookie Policy, which covers what we specifically store on your device.

Who we are

ERD Factory is operated by [legal entity name and registered address to be added here]. For any privacy question or request, contact us at [email protected] (placeholder — point this at a monitored inbox before publishing).

What we collect, and why

Account data

Email address, display name (if provided by Google/GitHub sign-in), the authentication provider you used, and your account creation date, via Firebase Authentication. Why: to create and secure your account and let you sign back in. Legal basis: performance of the contract you enter into by signing up.

Your schema content

The DDL/SQL you paste or generate, parsed schema structure, table notes, project and collection names, and version history, stored in Firestore and linked to your account. Why: that's the core service — saving and versioning your schemas. Legal basis: performance of contract.

Billing data

Your subscription tier and Stripe customer/subscription IDs. Card and payment details are entered directly into Stripe's hosted checkout and never reach our servers. Why: to run the Free/Pro subscription you chose. Legal basis: performance of contract, and legal obligations around financial record-keeping.

AI feature usage

When you use AI Analysis, Apply Fixes, AI Designer, or Change Request generation, the relevant schema content and your request are sent to Google's Gemini API to generate a response. We also record a monthly token-usage counter tied to your account. Why: to provide those optional AI features and enforce the Free/Pro usage caps described on our Pricing page. Legal basis: performance of contract (you triggered the request); legitimate interest in enforcing plan limits fairly.

Support & feedback

If you submit a bug/feature/general report via the in-app feedback form, we store the message plus lightweight context (editor mode, project id, browser user agent) tied to your account, and may email a notification to our own support address. Why: so we can read, triage, and follow up on it. Legal basis: legitimate interest in supporting our users.

Transactional email

Password-reset and account-related emails are sent via Resend to the email address on your account. Why: account security and service communication. Legal basis: performance of contract.

Analytics (optional, consent-based)

If you accept analytics cookies in the banner, we use Google Analytics (via Firebase) to see which pages are visited and how the product is used — pseudonymous identifiers, approximate location derived from IP, browser/device type, and pages viewed. Why: to understand product usage and improve it. Legal basis: your consent, which you can withdraw at any time — see our Cookie Policy.

Who we share it with

We don't sell personal data. We share it only with the service providers ("sub-processors") that help us run ERD Factory, each only for the purpose described above:

  • Google (Firebase / Google Cloud Platform) — authentication, database (Firestore), hosting, and analytics.
  • Google (Gemini API) — processes schema content and prompts only when you actively use an AI feature.
  • Stripe, Inc. — payment processing and billing; Stripe acts as an independent controller for the payment details you give it directly.
  • Resend — delivery of transactional emails.

These providers operate infrastructure outside the EEA (primarily the US). Where that's the case, we rely on the safeguards each provider offers for international transfers (such as Standard Contractual Clauses) — see their own privacy documentation for specifics.

How long we keep it

  • Account and schema data: for as long as your account exists.
  • Billing records: retained by Stripe per standard financial record-keeping requirements, independent of whether you keep using ERD Factory.
  • Feedback submissions: retained indefinitely today — we don't yet have an automated deletion flow for these, so if you want one removed, contact us directly.
  • Analytics data: subject to Google Analytics' standard retention settings. Rejecting or withdrawing consent stops new collection going forward; it doesn't retroactively delete data already collected while consent was given.

We don't yet have a self-service "delete my account" button — if you want your account and associated data deleted, email us and we'll do it manually.

Your rights

If the GDPR applies to you, you have the right to access, correct, export, or request erasure of your personal data, to object to or restrict certain processing, and to withdraw consent (for analytics) at any time without affecting the lawfulness of processing before the withdrawal. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise any of these, contact [email protected].

Changes to this policy

If we materially change what we collect or why, we'll update this page and the "Last updated" date above.

ERD Factory

Schema visualization & analysis for people who ship databases.

© 2026 ERD Factory