Mermaid Online

Mermaid Online

Privacy Policy

Mermaid Online is a local-first Mermaid diagram export tool. The core editor, preview, and image export workflow run in your browser. We do not upload, store, read, or share the Mermaid diagram code you enter into the editor.

Some optional features do involve our servers and trusted providers: signing in with Google to unlock Pro export styles and AI, paying through PayPal, and the AI generate, fix, and edit tools. This policy explains what each of those collects. Using the core editor and image export does not require an account.

Diagram code and exported images

Mermaid diagram rendering and PNG, SVG, JPG, WebP, and PDF export happen in your browser. Your Mermaid source code and exported diagram files are not sent to our application servers for the core export workflow.

If you use a URL fragment such as #code=..., the fragment is not sent to our servers as part of the HTTP request. We also do not intentionally send URL fragments, editor content, or exported diagrams to analytics providers.

Please do not paste secrets, API keys, passwords, production credentials, or highly confidential information into any public website, including this one.

Accounts and Google Sign-In

Signing in is optional and only needed to use Pro export styles or the AI features. We use Google Sign-In. When you sign in, we receive and store your Google account identifier, email address, and (if available) your name and profile picture, so we can recognize your account and apply your plan and credit balance.

We keep a signed session cookie in your browser so you stay logged in. We do not store your Google password, and we do not access your Google contacts, files, or other Google data.

AI features: generation, fixing, editing, and architecture maps

When you use the optional AI features — generate, fix, edit, or the architecture map generator — the prompt text (your description of a system, or the Mermaid code you submit) is sent to our AI provider, Zhipu AI (BigModel), to produce a response. If you use image-to-Mermaid, the image you upload is sent to the same provider so it can read the diagram. This only happens for AI requests you explicitly trigger — the core editor and image export never send your diagram anywhere.

For architecture maps, the generated specification is cached for up to seven days, keyed to your account, so regenerating the same map is free; the cache entry is then deleted. Nothing else about your diagrams is stored on our servers — the rendering, exploring, and exporting of architecture maps happen entirely in your browser.

Do not include secrets or confidential information in AI prompts. We do not use your AI prompts or diagram code to train our own models.

Payments and subscriptions

Payments for Pro subscriptions and one-time credit packs are processed by PayPal. We do not receive or store your full card or bank details — PayPal handles that. We do store records needed to run your account, such as your subscription status, plan, renewal date, credit balance, and a purchase reference for each transaction.

PayPal processes your payment information under its own privacy policy.

Analytics and usage data

We use privacy-focused analytics and performance measurement tools, including Plausible Analytics, Google Analytics 4, Ahrefs Web Analytics, and Cloudflare services, to understand how visitors use Mermaid Online and to improve the product.

These analytics may collect information such as:

  • pages visited, such as /mermaid-to-png;
  • browser, device type, approximate region, referrer, and campaign parameters;
  • page load performance and basic reliability signals;
  • anonymous product events, such as export format clicks or rendering error categories.

We do not use analytics to collect, read, upload, store, or share your Mermaid diagram code, editor text, URL fragment content, or exported diagram images. Product events should describe what happened, such as export_png_clickor render_failed, without including the original diagram source.

Cloudflare and hosting data

Mermaid Online is served through Cloudflare Workers, Cloudflare DNS, CDN, and related security and performance services. Cloudflare may process routine request and performance data on our behalf, such as IP address, user agent, timestamps, requested path, security events, and performance measurements.

Cloudflare Web Analytics or similar Cloudflare measurement tools may be used to measure traffic and performance. These tools are not intended to collect Mermaid diagram code, editor content, URL fragments, or exported diagrams.

Support contact data

If you email us, we may receive your email address, message content, and any information you choose to include. Please avoid sending sensitive Mermaid source code, credentials, or private infrastructure details unless you intentionally want us to review that information for support.

What we do not do

  • We do not upload or store your Mermaid diagram code for the core export workflow.
  • We do not use your Mermaid diagram code to train AI models.
  • We do not sell your Mermaid diagram code or exported diagrams.
  • We do not intentionally send editor content, URL fragments, or exported images to analytics providers.

Data retention and your choices

We keep your account and billing records for as long as your account is active and as needed to provide the service, resolve payment disputes, and meet legal or accounting obligations.

You can cancel a subscription at any time through PayPal. To access, correct, or delete your account data, email us at hello@mermaidonline.org and we will handle your request.

Changes to this policy

We may update this policy when we add or change analytics, hosting, support, or product features. The latest version will be posted on this page.

Last updated: July 28, 2026