Back to Squiggler

Privacy

What we store, why, and who else sees it. Short, because the honest list is short.

Using Squiggler without an account

Nothing identifies you. We keep aggregate counts — how many tracings were drawn, which rhythms are popular, how often an export happens — and none of it is tied to a person.

Your IP address is what the free daily allowance is counted against, and what stops one script spending everyone else’s. To count it we store a scrambled form of the address — a one-way hash we cannot read an address back out of — together with today’s date and a number, and nothing else. Those rows are deleted after two days. The address itself is never written down: our server logs keep only the network part of it, with the last part replaced by zeroes before the line is written.

Visits to the site are counted by Vercel Web Analytics. It records the page, the country, where you arrived from and what kind of device you are on. It sets no cookie and stores nothing on your device, and the number it derives a visitor count from is a one-way hash that is discarded and re-salted every day — so you cannot be followed from one day to the next, here or anywhere else. That is why there is no cookie banner: there is no cookie to consent to.

A tracing you share by link is encoded in the link itself. It is never stored on a server, so a link nobody has is a tracing nobody can find.

If you comment on a post

We store what you typed: the display name, if you gave one, and the comment. We do not ask for an email address and we do not set a cookie, so a comment is not linked to you, to an account, or to anything else you have done on the site. Nothing appears until we have read it.

We also store a scrambled form of your IP address — the same kind of one-way hash the daily allowance uses, which we cannot read an address back out of — and only to notice when the same connection posts many comments in an hour. It is never used to work out who wrote something.

Because a comment carries no address, we cannot find yours in order to remove it if you ask later. Tell us what you wrote and we will delete it.

If you enter a challenge

A challenge is somebody else’s competition — a blog, a course, an organisation — running on our studio. You draw a tracing, and entering it stores three things: the tracing itself, the name you typed if you typed one, and your email address.

The address is there for one reason, which is to tell you if you win. It is never shown on the gallery, and never used to write to you about anything else or given to the site running the challenge — unless you win and we ask you first, or you ticked the separate box saying that both we and the partner running the challenge may write to you now and then. That box is unticked and stays unticked if you leave it alone, and ticking it is the only way the partner ever sees your address before a win.

If you did tick it, every letter either of us sends carries a link that takes you off the list in one press, and we keep a one-way hash of your address afterwards so that nothing puts you back on it. Leaving the list does not remove your entry or your tracing; that is the paragraph above.

We also store a scrambled form of your IP address, the same one-way hash the daily allowance uses, and only to notice when one connection sends many entries in an hour.

Your tracing is stored as the settings that draw it rather than as a picture, which is why every entry on a gallery opens in the studio. If you want your entry taken down or your address removed, tell us which challenge and roughly when, and we will delete the row.

If you meet a case on someone else’s site

Our teaching cases can be placed on other sites — an organisation’s page, a course, a lecturer’s own. The case is still served by us, so your browser asks us for it directly: no cookie is set, nothing is stored on your device, and our server logs keep only the network part of your address with the rest replaced by zeroes, exactly as they do here.

The site it sits on tells us nothing about you, and we do not record which site it was. The only thing the case sends back to the page around it is its own height, so that page can make room to read it.

With an account

We store your email address, the tracings you save (as settings, never as images), the collections you make and any captions or presenter notes you write on them, what you are entitled to, a record of the credits you have spent, and today’s count against the free daily allowance.

Comments are not part of this. They carry no account link, so signing in does not attach your name to one and deleting your account does not remove one — see above.

We use it to run the product and to contact you about your account. We do not sell it, and we do not send marketing you did not ask for. There is exactly one message we send: a welcome, once, when the account is created. Everything else that reaches your inbox — receipts, renewal reminders, a failed payment — comes from Stripe.

Who processes it

Sign-in is handled by Clerk, which sets a cookie on your device as soon as the page loads — before you sign in, and even if you never do. It identifies the browser so a session can be established and kept safe, not to follow you or to advertise; it is set by us for that purpose alone, and there is nothing in it we use for anything else. Payments are handled by Stripe, which is where your card details go — they never reach us. Its checkout also collects the billing address needed to work out the tax, and a VAT number if you say you are buying for a business; both stay with Stripe and on the invoice, and we do not store either. Data is stored in Postgres hosted by Neon, the API runs on Fly.io, and the site — along with the visit counting described above — is hosted by Vercel The welcome message is delivered by Resend, which receives your email address for that one send and nothing else. Descriptions typed into the composer are sent to an AI provider's API — Anthropic or Google, depending on how the deployment is configured — to be turned into settings.

Most of these are processors acting on our instructions, bound by their own data protection terms. Stripe is the exception: for payments it acts as an independent controller of the card and transaction data it needs for its own legal obligations, under its own privacy notice.

How long we keep it

For as long as you have an account, and then no longer than we must. Records of payments are kept as long as accounting law requires, which in Sweden is seven years.

When an account is deleted we keep a one-way scrambled form of the email address, and a note of which one-time offers it had used. We cannot read an address back out of it and it is linked to nothing else. It exists so that free starter credits and single-use codes stay single-use, and we keep it for as long as we offer them.

Your rights

Download a copy of everything we hold about you from your account settings, whenever you like — no request, no waiting. The same panel deletes your account and everything in it, apart from the one scrambled record described under “How long we keep it”.

Anything else — a correction, an objection, a question about how we use it — is an email away and we will answer within a month.

If you think we have handled your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY).

Who we are

Company
Yumed AB
Registration number
559578-4876
VAT number
SE559578487601
Email
support@squiggler.io
Taggsvampsvägen 117
141 60 Huddinge
Sweden

For education only; not for clinical use.