Privacy policy for draw.io in AI assistants
This privacy policy explains how the draw.io MCP server at https://mcp.draw.io/mcp ("the service") collects, uses, shares and keeps data when you use draw.io in ChatGPT, Claude or another AI assistant. The service is created by draw.io Ltd ("we/us/draw.io"), which is the controller of the personal data described here.
The service draws diagrams for your AI assistant. When you ask for a diagram, your assistant sends the service a description of it, and the service returns the diagram, which your assistant shows in the conversation. The service can also look up shapes and icons for technical diagrams, such as cloud architecture or network diagrams.
The Open in draw.io button opens the diagram in the draw.io editor at app.diagrams.net. The editor is a separate application, and your use of it is covered by the draw.io privacy policy. Your conversation with your AI assistant is covered by the privacy policy of the company that provides the assistant, for example OpenAI for ChatGPT or Anthropic for Claude. This policy covers the service only. Where it differs from the draw.io privacy policy, this policy applies to the service.
If you have any questions about this privacy policy, please email [email protected].
In short
- The service has no accounts and no sign-in. It can't access your files, your other accounts or anything else on your device.
- The service receives only what your assistant sends it to draw a diagram or to search for shapes. It never receives your conversation.
- The service doesn't store your diagrams.
- We don't sell your data, we don't use it for advertising or profiling, and we don't use it to train AI models.
What the service receives
What your assistant sends to draw a diagram
Your assistant, not you, sends requests to the service. It decides when to use draw.io and what to send. The service never receives your conversation, your prompts, your chat history, files you uploaded to the assistant, or your account details with the company that provides the assistant.
The service offers two tools to your assistant:
| Tool | What your assistant sends | What the service returns |
|---|---|---|
create_diagram | The diagram your assistant wrote, in the draw.io XML format or as Mermaid text, and optional layout settings: whether to arrange the diagram automatically, in which direction, and whether to route connectors around shapes. | The diagram, checked and with structural problems repaired, and any errors found in it, for your assistant to show in the conversation. Assistants that can't show diagrams also receive a link that opens the diagram in the draw.io editor. |
search_shapes | Search keywords, such as aws lambda, and the number of results to return. | Matching shapes and icons from the draw.io shape libraries and the draw.io icon collection: their name, size and style. For icons, the style contains the address of the icon image. |
A diagram contains whatever your assistant puts in it, usually based on what you asked for. If you ask for a diagram that contains personal data, such as the names in an organisation chart, that personal data is in the diagram the service receives. The service doesn't need personal data to draw a diagram.
Information that comes with each request
- Connection details: The name and version of your assistant's software, the features it supports, and a random session ID that the service creates when your assistant connects. The service uses these only to answer in a form your assistant can show.
- ChatGPT hints: ChatGPT adds hints to each request: your language setting, a browser or app identifier, your approximate location (city, region, country and time zone), and anonymised IDs for your ChatGPT account, the conversation and your organisation. The service doesn't read, use or store any of these hints.
- IP address: The service receives the IP address of the computer that connects to it. In ChatGPT and in Claude on the web, that computer is a server of OpenAI or Anthropic, not your device. If you connect an app on your own computer to the service, such as an AI coding assistant, the service receives your computer's IP address.
What your device downloads to show the diagram
When your assistant shows the diagram in the conversation, as ChatGPT and Claude do, it shows it in a secure frame with the draw.io viewer. The viewer draws the diagram on your device. It doesn't send the diagram anywhere. To show the diagram, your device downloads:
- the viewer software from
viewer.diagrams.net, - shape images from
app.diagrams.net, and - icon images from
icons.diagrams.net.
As with any website, these downloads tell our servers your IP address, your browser details and which file was requested, but nothing about your diagram. The viewer contains no advertising, analytics or tracking.
When you select Open in draw.io, the diagram is passed to the editor in the part of the link after the #. Your browser doesn't send that part of a link to any server.
How we use this information
We use the information described above only to:
- draw, check and return the diagram you asked for,
- find shapes and icons that match your assistant's search,
- keep the service secure and working, for example by blocking abuse and fixing errors, and
- find out which icons people search for but don't find, so that we can add them to the icon collection. For this, we use the search keywords only, as described in Sharing with the draw.io icon service.
We don't sell your data. We don't use it for advertising, marketing or profiling, and we don't use it to train AI models.
Sharing with the draw.io icon service
When the draw.io shape libraries have no good match for a search, the service also searches the draw.io icon service at icons.diagrams.net.
- The service sends the icon service the search keywords and the number of results only. It doesn't send the diagram, the connection details, the ChatGPT hints or the IP address of your assistant or your device.
- To find icons that match the meaning of the keywords, the icon service converts them to a search vector with an AI model that runs on Cloudflare Workers AI. Cloudflare doesn't use them to train AI models.
- The icon service keeps the results of each search in a cache for up to 30 days, so that the same search is faster next time.
- The icon service records each search in its usage statistics, with the number of results and the country of the server that sent it, and keeps these statistics for three months. For searches from the service, that server is a Cloudflare data centre, not your device.
- The icon service's request logs contain the search keywords and are kept for 7 days.
Who else receives this information
- Cloudflare, Inc. runs the service and the icon service, and delivers the viewer software, shape images and icon images, on our behalf as our sub-processor. Cloudflare also processes connection data, such as IP addresses, to protect its network against attacks.
- Google Cloud runs the servers behind
viewer.diagrams.netandapp.diagrams.neton our behalf as our sub-processor. Files that Cloudflare doesn't have in its cache are downloaded from there. - The company that provides your AI assistant, such as OpenAI or Anthropic, sends the requests and receives the responses. How it uses them is covered by its own privacy policy.
- Authorities, only where the law requires us to disclose information.
No one else receives this information.
Storage and retention
| Information | Where it is kept | How long |
|---|---|---|
Diagrams, and the responses of create_diagram | Not stored. The service processes them in memory while it answers the request. | Until the end of the request |
| Search keywords | Not stored by the service. When they are sent to the icon service, see Sharing with the draw.io icon service. | Until the end of the request. In the icon service: 30 days (cache), 3 months (usage statistics), 7 days (request logs). |
| ChatGPT hints and connection details | Not stored | Until the end of the request |
| Whether a connection has downloaded the viewer. The service records this only for assistants that don't declare whether they can show diagrams, and only against the random session ID. It contains no other information. | Cloudflare | 24 hours after it was last used |
| IP addresses, browser details and the requested file, for downloads of the viewer software and shape images | Google Cloud request logs | 30 days |
The service keeps no request logs. If it fails with an unexpected error, it writes the error to a live error log that isn't stored.
Cloudflare processes requests in the data centre that is closest to the computer that connects, which may be outside the United Kingdom. Cloudflare and Google Cloud process this information under data processing terms that include the standard data protection clauses approved for transfers out of the United Kingdom and the European Union.
Your choices
- Decide what goes into a diagram: Leave out personal data you don't want to share, or use placeholders instead, for example "Manager" instead of a name.
- Don't include sensitive data: Don't put payment card numbers, health information, government ID numbers, passwords, API keys or other secrets into a diagram. The service never asks for them.
- Check what your assistant sends: Many assistants show each request to draw.io in the conversation, and let you open it to see what was sent.
- Turn draw.io off: Disconnect or disable draw.io in your assistant's app or connector settings. Your assistant then stops sending requests to the service.
- Run it yourself: The service is open source. You can run your own copy, or use the draw.io MCP tool server on your own computer. Your diagrams then don't reach
mcp.draw.io. These options still download the viewer software and send shape searches to the icon service, as described above.
Your rights
Under the UK GDPR, you have the right to ask for access to, correction of and deletion of your personal data, and to object to or restrict how we process it. Because the service doesn't store diagrams and doesn't link requests to people, we usually hold no information that identifies you. To exercise your rights, email [email protected].
If you are not satisfied with how we handle your personal data, you can complain to the Information Commissioner's Office. Please contact us first, so that we can try to resolve it.
Security
All connections to the service, the icon service and the viewer downloads are encrypted with TLS. The service has no database of diagrams or other content you send.
Changes to this policy
We update this page when the way the service handles data changes. The version and date at the end of this page show when it last changed.
Contact
- Privacy questions: [email protected]
- Help with draw.io in AI assistants: github.com/jgraph/drawio-mcp/issues
draw.io Ltd, Artisans' House, 7 Queensbridge, Northampton, NN4 7BF, United Kingdom.
v1.0 2026.10.01