Skip to main content

This Privacy Policy details how draw.io Diagram Editor for SharePoint (hereafter called "the app") collects, uses and shares information gathered from the User ("you"), as well as explaining how data is processed and stored. The app is created by draw.io Ltd ("we/us/draw.io").

The app adds a web part to SharePoint pages. The web part loads the draw.io editor from app.diagrams.net, or from a self-hosted draw.io server if the page author has configured one, and lets you display, create and edit draw.io diagram files stored in your organisation's SharePoint document libraries. Usage of the online app.diagrams.net application is covered by the draw.io privacy policy; this policy is specific to the operation of the app.

If you have any questions regarding this privacy policy, please email [email protected].

Permissions

The app requests the delegated Files.ReadWrite.All permission for Microsoft Graph, which your SharePoint administrator approves in the SharePoint admin center. The web part uses this permission, on behalf of the signed-in user, only to check that a picked file contains a draw.io diagram and to create new diagram files in the folder you choose.

The draw.io editor loaded in the web part separately asks you to sign in with your Microsoft 365 account, so that it can open and save diagram files with your own permissions. No further permissions are requested.

Please refer to the privacy policy of Microsoft for more details:

Microsoft's privacy statement

Information stored in SharePoint

The web part stores a reference to the selected diagram file - its name, its URL and its identifiers in Microsoft Graph - in the properties of the page it is placed on. This information stays in your organisation's SharePoint tenant. The diagram content stays in the diagram file in your document library, where SharePoint versioning, permissions, sharing and retention apply to it as to any other document.

Personal information

No personally identifiable information (PII) is transmitted to or stored on draw.io servers by the app. Serving the editor from app.diagrams.net requires your IP address and limited information about your device, which are stored in server logs for error diagnosis and cyclically overwritten, as described in the draw.io privacy policy. The app does not use cookies, analytics or tracking.

Diagram data and authentication

Authentication to Microsoft 365 is performed directly with Microsoft, and your browser holds the authentication token. The token is not stored on draw.io servers, so we cannot act on your behalf without your knowledge.

draw.io does not have an additional authentication mechanism; there is no authentication exchange (Single Sign On).

Once a diagram is loaded for editing, it is loaded directly from Microsoft servers to your browser. It does not transmit via draw.io servers. The same principle applies when saving.

We do not store your diagram data at any time, nor do we see your data during save/load operations.

Data security

Diagram data is transmitted to draw.io servers only if you request a PDF of your diagram. The PDF generation servers are configured to industry standard security level and have ongoing security testing as part of a bug bounty program.

Data transmitted from the client browser to the PDF generation servers is encrypted with TLS 1.2+ and encrypted at all points in transit between your browser and the endpoint server.

No data is ever retained on draw.io servers; it is deleted immediately after export processing is complete. Organisations that run their own draw.io server and configure it as the web part's Base URL keep all traffic within their own infrastructure.