Privacy policy
How mdbin handles your data. This page describes what we store, why we store it, who else sees it, and the cookies we set. It is written to be read, not to be survived.
mdbin is operated by forjed.io. If anything here is unclear, or you want data removed, contact us — that form reaches a person.
Last updated: 19 August 2026.
The short version#
- Publishing a document does not require an account. Documents are public to anyone with the link — the address is unguessable, but it is not a password. We ask search engines not to index them, so a document should not turn up in search results, but treat anything you publish as readable by whoever gets hold of the link.
- Comments are anonymous by design. We never show who wrote one, even to other signed-in users.
- We set three cookies, all strictly necessary. There is no analytics, no advertising, and no third-party tracking, so there is no cookie banner to click through.
- If you use diAIgram, the text you type is sent to an AI provider outside our control. Read Artificial intelligence before putting anything sensitive in it.
What we collect#
If you never sign in#
- The document you publish, and its title, for as long as you asked us to keep it.
- A hashed form of your IP address, stored against documents, comments and URL imports. This is an HMAC-SHA256 of the address with a secret salt — it lets us respond to abuse reports without keeping a list of who read or wrote what. It is one-way: we never store the address itself and cannot look one up. Like any hash of a small space it is pseudonymised rather than anonymous — someone holding our secret salt could still test whether a given address matches — so we treat it as personal data.
- Comment text and the name you typed, if you leave a comment. The name is free text; you can leave it blank and appear as "Anonymous".
If you create an account#
- Your name and email address. The name is whatever you type — it does not have to be your legal name.
- A hash of your password. We never store the password itself and cannot recover it.
- Which documents you published, so you can manage and delete them.
- API keys you create, stored as hashes with a short visible prefix so you can tell them apart.
- Diagrams you save, your diAIgram credit balance, and the date you agreed to these terms. If you change your email address we hold the pending address until you confirm it.
Automatically, while you use the site#
- Session records, containing your IP address and browser user-agent string in readable form. These exist so you stay signed in and so we can end a session. They expire after two hours of inactivity.
- Per-day counts — how many documents you created, how many comments your documents received, and how many times each was viewed. These are counts only, not a log of individual visits.
- URL imports. If you generate a document from a URL, we keep the address you submitted and the fetched page content for about an hour while the import runs, then delete them.
- Diagnostic records when something fails, such as a URL import that could not be fetched.
We do not use analytics software, advertising networks, session recording, or fingerprinting.
Cookies#
Every cookie mdbin sets is strictly necessary for the site to function. None are used for analytics, advertising, profiling, or tracking you across other sites. Because there are no optional cookies, there is nothing to consent to and no cookie banner.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in and links your browser to its session on the server. Without it you would be signed out on every page. | Expires when the session does (2 hours of inactivity by default), or when you sign out |
XSRF-TOKEN |
Protects forms against cross-site request forgery — it is what stops another site submitting a form as you. | Same as the session |
remember_web_* |
Set only if you tick "remember me" when signing in, so you stay signed in after closing the browser. | Up to 400 days, or until you sign out — whichever comes first |
We also use your browser's local storage to remember whether you chose light or dark mode. That never leaves your device and is not a cookie.
Artificial intelligence#
diAIgram — the assistant on /diagram that turns a description into diagram source — is the
one feature that sends your content to a third party.
What is sent#
When you ask diAIgram to generate a diagram, we send the description you typed and, if you asked it to modify a diagram already open in the editor, that diagram's source. Your name, email address, IP address and account identifier are not sent.
Where it goes#
Your description is sent to a third-party AI provider for generation. Which provider and model handle a given request is a setting we change over time, so this page describes the category rather than naming today's supplier.
We only ever use endpoints hosted inside the European Economic Area. Your prompt is processed in the EEA and is not transferred outside it by us.
If you need to know exactly who is processing your data today — for a data protection assessment, a supplier list, or your own compliance — ask us and we will tell you.
What we cannot promise#
This is the part that matters, and we would rather state it plainly than bury it:
We cannot confirm what the AI provider does with the text you send, and we cannot guarantee it will not be used to train models — now or in future. We do not control their systems, their retention periods, or their terms, and those terms can change without our involvement. Any assurance we gave you about it would be a promise we are not in a position to keep.
Please treat anything you type into diAIgram as leaving our control permanently. Do not put confidential information, personal data about other people, credentials, or anything you would not want retained indefinitely into a diagram prompt.
If you would rather no content of yours reaches an AI provider, simply do not use diAIgram. Every other feature of mdbin — publishing, importing, commenting, diagramming by hand — works without it, and nothing you write elsewhere on the site is sent to any AI service.
What we keep#
We store your prompt and the generated diagram for 30 days so you can reopen the conversation and recover an earlier version, after which they are deleted automatically. We also keep a permanent record of how many tokens each generation used and what it cost — numbers only, with no prompt text and no diagram. Each record references the conversation it priced, so it can be tied to your account for as long as that conversation exists; once the conversation is deleted at 30 days the numbers stand alone.
Other services we share data with#
| Service | What reaches it | Why |
|---|---|---|
| AI providers (EEA endpoints) | diAIgram prompts and diagram source | Generating diagrams — see above |
| Bunny.net | Images embedded in published documents | Storing and serving images from a CDN |
| ZeptoMail (Zoho) | Your email address and the message body | Sending verification, password reset, and reply emails |
We do not sell personal data, and we do not share it for advertising.
Content you import stays yours to control. If you generate a document from a URL, we fetch that page from our own servers — the site you named does not see you.
How long we keep things#
- Documents — until they expire, if you set an expiry, or until you delete them. Deleting a document removes its comments and images too.
- diAIgram conversations — 30 days.
- Accounts — until deleted. Deleting an account leaves published documents and comments in place but detaches them from you, so they become anonymous rather than disappearing. It does delete your saved diagrams, diAIgram conversations, API keys and dashboard statistics.
- URL imports — about an hour. Records of a failed import — 30 days.
- Contact messages — kept so we have a record of what was asked and answered. Ask us if you want yours deleted.
- Aggregate counts — kept indefinitely. While you have an account they are keyed to it; deleting the account removes your dashboard counts and strips your id from view counts, leaving numbers that identify nobody.
Your rights#
If you are in the UK or the EEA, you have the right to access, correct, export, or delete your personal data, to object to or restrict our processing of it, and to complain to a supervisory authority — in the UK, the Information Commissioner's Office.
To exercise any of these, contact us. Account deletion is currently handled by a person rather than a button, so please ask and we will do it.
Our lawful bases: we store and publish the content you submit, run diAIgram when you ask it to, answer your contact messages, and hold your account details in order to perform the service you asked us for; we keep hashed IP addresses, session records and rate-limiting counters under our legitimate interest in keeping the service secure and preventing abuse; and we send service emails because they are necessary to operate your account. We do not send marketing email.
Security#
Passwords are hashed, API keys are stored only as hashes, IP addresses are stored only as salted HMACs, and the whole site is served over HTTPS. No system is perfect, and we will tell you if something happens that affects you.
Children#
mdbin is not directed at children under 13, and we do not knowingly collect their data. Creating an account requires you to confirm you are 13 or older.
If you believe a child under 13 has given us personal data, tell us and we will delete it and close any account involved.
Changes#
If we change this policy in a way that affects you, we will update the date at the top and, for anything significant, tell account holders by email. The current version always lives at this address.