| Product / Service | Login Required | Email Collected | Diagram / Data Storage Location | Analytics Collected |
|---|---|---|---|---|
| Confluence App | Via Confluence | No | Atlassian Confluence is the system of record; a verbatim copy of each saved diagram is also mirrored to our backend (Cloudflare). | Pseudonymous usage metadata via Mixpanel (no diagram content). Optional opt-in AI features and Live Agent Link. Session replay for a percentage of sessions. |
| IntelliJ IDEA & VS Code Plugins | No | No | Local only | None |
| Web App (https://app.zenuml.com) | Yes | Yes | Stored on ZenUML servers | Usage data (e.g., location, browser, pages visited) |
The sections below describe additional, feature-specific data flows in the Confluence app. Several of them (AI features, Live Agent Link) are optional and off by default.
For a small number of enterprise customers who have arranged for enhanced page capture, the Confluence app captures the full body of a Confluence page when that page is updated and stores it in our backend object storage (Cloudflare R2). This behaviour is limited to an explicit allowlist of customer sites.
For all other customers, no page body is captured or stored โ page-update events are received but discarded without being retained. Where enhanced page capture is active, we retain captured page content for no longer than 90 days on a rolling basis (in current operation, captured snapshots are automatically deleted after 7 days).
ZenUML offers optional AI features โ AI diagram generation, AI repair, and AI update. These are off by default and controlled by feature flags; they run only when you actively use them.
Because AI features send diagram content to the providers named above, do not use them for content you are not permitted to share with those providers.
Live Agent Link is an optional feature that is off by default. When you explicitly start a session, your diagram source is streamed in real time over an encrypted secure WebSocket connection (wss://*.zenuml.com) through a relay running on our Cloudflare infrastructure, and is made available to an external AI agent or MCP client that you have authorized on your own device.
The relay holds session state only transiently, for the duration of the session. Because you are connecting your diagram to a third-party AI agent of your own choosing, that agent's own privacy terms govern what it does with the content it receives.
If you render a PlantUML diagram, the PlantUML source is URL-encoded and sent over HTTPS to the public PlantUML rendering service at plantuml.com. This occurs during editing (syntax validation), on each render, and on PNG export.
According to PlantUML's own FAQ, it does not store diagrams on its servers โ rendering is stateless and the diagram is encoded in the request URL โ though it may keep transient HTTP traces for performance and then remove them. The public PlantUML service is a community service with no data processing agreement and no SOC 2 certification; PlantUML recommends self-hosting for sensitive diagrams. This applies only to PlantUML diagrams; other diagram types are not sent to plantuml.com.
We use Mixpanel to understand how the Confluence app is used. The events we send contain metadata only โ for example an opaque Atlassian account identifier, your Confluence site domain, space key, macro identifiers, opaque page/content identifiers, product type, timings, and counts. We do not send diagram source content to Mixpanel; where the size of your input matters we send only length values (such as prompt length or the size of a text change).
These identifiers are pseudonymous, not anonymous: an opaque account identifier combined with a site domain can relate to an individual or an organization. We therefore describe this data as pseudonymous rather than claiming it contains no personal data.
Two features send limited free text:
Session replay: For a configurable percentage of sessions, Mixpanel records a replay of the session (a reconstruction of on-screen interactions). This is controlled by a server-side setting and uses Mixpanel's default masking behaviour. Session replay is separate from the event analytics described above.
We use collected data to:
We share data with the sub-processors listed in Section 10 to operate the service. Beyond that, we may disclose information only if required to:
We use the following sub-processors to deliver the service. Some (OpenAI, Anthropic, plantuml.com) receive data only when you use the specific feature noted.
| Sub-processor | Purpose | In transit | At rest | Notes / compliance |
|---|---|---|---|---|
| Cloudflare | App backend & storage (D1 / R2 / KV / Workers) | TLS | AES-256 (GCM), automatic | SOC 2 / ISO |
| Atlassian | Confluence โ system of record | TLS 1.2+ (perfect forward secrecy) | AES-256 | SOC 2 / ISO |
| Diagramly.ai (our product; Neon / Vercel infrastructure) | AI generation / repair / update | TLS 1.2 / 1.3 | AES-256 | SOC 2, ISO 27001 / 27701; retains AI-repair job inputs |
| OpenAI | AI model provider (opt-in features only) | TLS | AES-256 | SOC 2 Type 2; no training by default; inputs/outputs deleted within ~30 days |
| Anthropic | AI model provider (opt-in features only) | TLS 1.2+ | AES-256 | SOC 2 Type II, ISO 27001 / 42001; no training (commercial terms ยงB); 30-day deletion of API inputs/outputs |
| Cloudflare Workers AI (Meta Llama) | AI title suggestion | TLS | n/a (ephemeral inference) | Runs on Cloudflare infrastructure; not stored |
| Mixpanel | Product analytics (metadata only) | TLS 1.2 | AES-256 | SOC 2 Type II, ISO 27001 / 27701; session replay for a percentage of sessions |
| plantuml.com | PlantUML rendering only | HTTPS | Not stored (stateless; per PlantUML FAQ) | Community service; no DPA / SOC 2; transient performance logs possible |
We may also use Google Analytics for anonymous web-traffic analysis on our marketing website only (not inside the Confluence app). You can opt out of Google Analytics tracking by installing the Google Analytics opt-out browser add-on.
In transit: All data sent to our services is encrypted with TLS/HTTPS, including secure WebSockets (wss) for Live Agent Link. Requests to our backend are authenticated using Atlassian Forge signed invocation tokens (RS256).
At rest: Content stored in our primary backend (Cloudflare D1, R2, and KV) is encrypted using AES-256 in GCM (Galois/Counter Mode), applied automatically, with keys managed by Cloudflare. Atlassian Confluence โ the system of record for your diagrams โ encrypts data in transit (TLS 1.2+ with perfect forward secrecy) and at rest (AES-256). Our AI sister product's database (Neon) encrypts data at rest with AES-256 and in transit with TLS 1.2/1.3.
Our services are not directed to children under 13. We do not knowingly collect personal data from children. If you believe we have done so, please contact us and we will delete it.
We may update this Privacy Policy from time to time. Updates will be posted on this page, and we will notify users of material changes.
If you have any questions about this Privacy Policy, or wish to make a data access or deletion request, please contact us: Email: [email protected], or use our support portal at https://zenuml.atlassian.net/servicedesk/customer/portals.