Privacy policy
The short version: your org chart is encrypted on your device before it reaches us, and we cannot read it. This page explains exactly what we do hold.
Who we are
OrgChartBuilder is operated by OrgBuilder (ABN 39 905 138 200), based in Victoria, Australia. We are the organisation responsible for the data described on this page, and the contact point for any question or request about it.
What we store on our servers
- Your account: email address, a verification flag, your plan tier, and a value derived from your password that lets us check your login. We never store your password itself, and the value we do store cannot be used to decrypt your charts.
- Your charts, as ciphertext: encrypted blobs plus a version number. Chart and record identifiers are opaque random UUIDs — they carry no meaning about your organisation.
- Employee photos, as ciphertext: stored the same way as chart data and encrypted with the same per-chart key.
- Encrypted keys: your chart keys, wrapped so that only you (or a teammate you have explicitly shared with) can unwrap them.
- Share links and team invitations: the link identifier, its expiry, and who
created it. The decryption key for a share link lives only in the part of the URL after the
#, which browsers never send to a server — so we hold the link but not the means to read it. - Billing records: a Stripe customer and subscription identifier. Card details are handled entirely by Stripe and never touch our servers — we never see, store or process a card number.
What we cannot store
Names, job titles, email addresses, departments, reporting structure, photos, chart names, and anything else you type into a chart. These are encrypted before they leave your browser. This is a property of how the product is built, not a policy we could quietly change without shipping different software.
Usage measurement
We record a small number of product events so we can tell whether the software is working — things like "someone started a chart", "an export finished", "a sign-up was completed". These events are first-party: they go to our own servers, not to an advertising or analytics company, and there are no third-party trackers on this site.
Each event carries only:
- the event name (for example,
CHART_EXPORTED_PDF); - opaque identifiers — a random account ID and a random chart ID, never a name;
- a random per-tab session ID that lets us follow one visit from start to finish, and is not linked to your account;
- non-identifying context such as your plan tier, an export format, or a row count.
No chart content ever appears in these events — the server could not include it even by mistake, because it cannot read it. Raw events are aggregated into daily counts and the detailed rows are deleted shortly afterwards.
Cookies
We do not use cookies for advertising, tracking, or profiling. The application uses your browser's own storage to keep you signed in within a tab, as described below.
What your own browser stores
Some data stays on your device and never reaches us. It is worth knowing what is there, particularly on a shared or public computer.
- Your session, including your encryption key. Held in your browser's per-tab storage so a page refresh does not sign you out. It is scoped to that tab and is discarded when you close it.
- An offline copy of your charts, still encrypted, so a chart you have already opened loads instantly and works offline.
- Guest-mode charts, unencrypted. If you use OrgChartBuilder without an account, your chart is kept in your browser's per-tab storage so an accidental refresh does not destroy your work. It is never sent to us, and it is discarded when you close the tab. It is not encrypted, because without an account there is no key to encrypt it with — so treat guest mode on a shared computer accordingly. Signing up moves the chart to encrypted storage and clears the plaintext copy.
Signing out clears all of the above.
When data leaves us
- Payments — Stripe. When you subscribe, Stripe receives your email address and the billing and card details you enter on their checkout page, in order to take payment. Stripe never receives chart data. Their handling of that information is governed by Stripe's privacy policy.
- Email — Resend. Our email provider receives your address in order to deliver account email such as verification, team invitations and billing notices. They receive no chart data.
- Hosting — Vultr and Cloudflare. Our servers run on Vultr. Cloudflare proxies all traffic to them for DNS, caching and protection against abuse, which means your connection is encrypted to Cloudflare and re-encrypted on to us — so Cloudflare handles your requests in the clear at the network level, including your IP address. Neither provider can read your chart: its contents were already encrypted in your browser, with a key that never leaves it, before any request was made. This is the practical value of end-to-end encryption over transport encryption alone — it holds even against the infrastructure we ourselves depend on.
- Anyone you share with. A share link grants whoever holds the full URL the ability to read that chart. Team sharing grants named colleagues access. Both are your choices, and both can be revoked.
We do not sell your data, and we do not share it for advertising.
Your choices
- Export any chart to CSV, PDF or SVG at any time, on every plan including the free one.
- Revoke a share link or a teammate's access whenever you like.
- Unsubscribe from non-essential email from your account settings.
- Delete a chart, or ask us to delete your account. Deleting a chart removes its encrypted blobs from our servers.
Contact
Questions about this policy, or a request to access or delete your data: support@orgchartbuilder.app.
OrgBuilder
ABN 39 905 138 200
Victoria, Australia