Privacy Updated 6 October 2026
What goes where.
This site sets no cookies and counts visits without identifying anyone. The app has no telemetry and no account.
This website
- archdraw.dev sets no cookies and runs no ads or third-party tracking.
- It counts visits with Vercel Web Analytics, which records, for each page view, the page, the site you came from, your country and region, and your browser, operating system and device type. It uses no cookies; a visitor is recognised only by a hash of the request, which is discarded after 24 hours. We see totals, never individuals.
- Everything on the page, fonts and the analytics script included, is served from archdraw.dev. Your browser makes no requests to anyone else.
- If you use the theme switch, your choice is kept in your browser's local storage on your device. It is never sent anywhere.
- The site is hosted on Vercel. Like any web host, Vercel keeps standard request logs (IP address, user agent) for operating the site. Tawab Safi, who makes archdraw, adds nothing beyond the visit counts above.
The archdraw app
- archdraw runs on your machine. There is no archdraw server it reports to. It has no telemetry and no account.
- Your AI key stays on your machine, encrypted with your system's keychain (the Keychain on macOS; the Secret Service, such as GNOME Keyring or KWallet, on Linux) and saved in a file only your user can read. On a Linux desktop without a keyring, the app tells you the key has only basic protection.
- Your code goes only to the AI provider you pick: OpenAI, Anthropic, Google or OpenRouter. When a project is checked, archdraw sends that provider the new commit messages, the names of the files they touch and the diagram outlines. When the architecture changed, the agent reads the code it needs to draft the update. When you ask the agent for a drawing or a question, it reads the code it needs and sends it to that provider. That provider's own terms apply.
- The agent can only read. It never reads
.envfiles, keys, credential folders, Terraform state, or anything your.gitignoreexcludes, and it cannot run commands. - A drafted update waits on an
archdraw/updatebranch in your repo until you approve or discard it. Anyone who can read the repo can see that branch. - archdraw works on your repo through your own
gitand, for GitHub projects, the GitHub CLI you signed in with. - At launch and every six hours it checks GitHub Releases for a new version, so GitHub sees your IP address and the app's version. On macOS and with the AppImage, updates download on their own.
Contact
Questions about privacy: hello@archdraw.dev.