Skip to main content

Privacy policy for draw.io for Google Docs, Sheets and Slides

This privacy policy explains how the draw.io add-ons for Google Docs, Google Sheets and Google Slides (together called "the add-ons") access, use, store and share Google user data. The add-ons are created by draw.io Ltd ("we/us/draw.io").

The add-ons insert draw.io diagrams that are stored in your Google Drive into the Google Docs document, Google Sheets spreadsheet or Google Slides presentation you have open, as images. When you ask them to, they update those images with the current version of each diagram.

The Edit Selected and New Diagram menu items open the draw.io editor at app.diagrams.net in a new browser tab. The editor is a separate application, and your use of it is covered by the draw.io privacy policy. This policy covers the add-ons only.

If you have any questions about this privacy policy, please email [email protected].

Google user data the add-ons access​

Google asks you to allow the following permissions before an add-on can use them. The quoted text is the description Google shows you on its consent screen.

Only the Google Drive files you select​

https://www.googleapis.com/auth/drive.file: "See, edit, create, and delete only the specific Google Drive files you use with this app"

  • The add-ons read only the diagram files that you select, or upload, in the Google file picker. They read each file's name, type, size and content, so that they can render the diagram as an image.
  • The Google file picker is part of Google. It shows you your Google Drive, and tells the add-ons only which files you selected. A file you upload in the file picker is saved to your Google Drive by Google, and then read like any other file you selected.
  • The add-ons don't list, read, modify or delete any other files in your Google Drive. They never change or delete your diagram files.
  • Access to a file you selected lasts until you revoke it, so that the add-ons can update the diagram's image later. If your file contains diagrams you haven't selected before, for example diagrams that someone else inserted, the add-on asks you to select those diagram files in the file picker before it updates them. Diagrams you skip stay as they are.

The file you have open​

  • Google Docs: https://www.googleapis.com/auth/documents.currentonly: "View and manage documents that this application has been installed in"
  • Google Sheets: https://www.googleapis.com/auth/spreadsheets.currentonly: "View and manage spreadsheets that this application has been installed in"
  • Google Slides: https://www.googleapis.com/auth/presentations.currentonly: "View and manage the Google Slides presentations that this application is installed in"

Each add-on uses this permission only on the file you have open, and only when you choose an item from its menu. It inserts the diagram images, and finds the images it inserted earlier so that it can update them. It finds these images by their link to the diagram, or in Google Sheets, by their alt text. To place and size the images, it also reads the cursor or selection, the current slide or cell, and the page size. Apart from these images and their links, it doesn't read the content of your file.

The add-on dialogs​

https://www.googleapis.com/auth/script.container.ui: "Display and run third-party web content in prompts and sidebars inside Google applications"

The add-ons use this permission to show their dialogs: the Google file picker, page selection, progress and error messages. The dialogs are served by Google Apps Script, and load only Google resources.

Connections to Google Drive and the draw.io export service​

https://www.googleapis.com/auth/script.external_request: "Connect to an external service"

The add-ons use this permission for two kinds of requests only: to the Google Drive API, to read the files you selected, and to the draw.io export service, to render those diagrams as images. The add-ons are set up so that Google Apps Script blocks requests to any other address.

How the add-ons use Google user data​

The add-ons use Google user data only to insert diagram images into your files and to update them. They run only when you choose an item from the draw.io menu, apart from adding that menu when you open a file. They don't run in the background.

  • The add-ons don't read your name, email address, contacts or any other information from your Google Account.
  • The add-ons contain no advertising, analytics or tracking.
  • We don't sell Google user data, and we don't use it for advertising.
  • We don't use Google user data to develop, improve or train generalised AI or machine-learning models.
  • No one at draw.io can read your diagrams or your files, because we don't store them.

Sharing with the draw.io export service​

To turn a diagram into an image, the add-ons send the content of the diagram file to draw.io's export service at convert.diagrams.net.

  • The request is encrypted with TLS. It is sent from Google's servers, where the add-ons run, not from your browser.
  • Apart from the diagram, the request contains only rendering options, such as the page to render and the page width of your file. It doesn't contain the name or ID of the diagram file, or any information about you.
  • The export service renders the diagram as a PNG image and returns it to the add-on. It processes the diagram in memory, and doesn't store the diagram or the image. Its logs record technical details of each request, such as its size and how long it took, but never the diagram.
  • The export service runs on Cloudflare's serverless platform. Cloudflare processes the request on our behalf, as our sub-processor.

No other party receives Google user data from the add-ons.

Storage and retention​

draw.io doesn't store Google user data. The add-ons have no database, and keep no copy of your diagrams or your files.

What the add-ons save, they save in your own file:

  • Each image you insert is saved in your document, spreadsheet or presentation.
  • With each image, the add-ons save a link to its diagram. The link contains the diagram file's Google Drive ID, the diagram page and the scale. In Google Docs and Google Slides, it is the image's link. In Google Sheets, it is the image's alt text. The add-ons use it to update the image later.

This information stays in your file, where your Google sharing settings apply to it as to the rest of the file. Anyone who can see your file can see these links, but they can only open a diagram if its file is shared with them. To remove this information, delete the image or its link.

Error reports: If an add-on stops because of an unexpected error, Google Apps Script records the error in the add-on's Google Cloud project, so that we can fix it. The record contains the error message and where the error happened in the add-on's code. Google labels it with a temporary identifier that doesn't reveal who you are. It doesn't contain your diagrams or the content of your files.

Authentication​

Google handles sign-in and permissions. There is no draw.io account, and no separate sign-in.

The OAuth access token that Google issues stays with Google. Google Apps Script uses it to call Google Drive, and the add-on dialog passes it to the Google file picker. draw.io servers never receive the token, so we can't act on your behalf.

Revoke access or uninstall​

  • Revoke access: Go to myaccount.google.com/permissions, select draw.io, and remove its access. The add-ons then can't read any of your Google Drive files, including files you selected before.
  • Uninstall: In Google Docs, Google Sheets or Google Slides, select Extensions > Add-ons > Manage add-ons, then uninstall draw.io. If your Google Workspace administrator installed the add-on for your organisation, ask them to uninstall it.

Images you inserted stay in your files as ordinary images, and your diagram files stay in your Google Drive.

Limited Use​

draw.io's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Changes to this policy​

We update this page when the way the add-ons use Google user data changes. The version and date at the end of this page show when it last changed.

Contact​

draw.io Ltd, Artisans' House, 7 Queensbridge, Northampton, NN4 7BF, United Kingdom.

v1.0 2026.09.25