← Back to UMLKit

Privacy Policy

Last updated: 28 July 2026

This policy explains what UMLKit collects, why, who processes it on our behalf, and how to get it deleted. It describes what the service actually does — not a generic template.

Who we are

UMLKit is a tool that turns a written project brief or an uploaded requirements document into UML diagrams. The service is operated from Morocco. For any privacy question or request, contact soulayman.aabaid2004@gmail.com.

What we collect

Account data. Your full name, username, and email address. Your password is never stored — only a bcrypt hash of it, which cannot be reversed.

Content you create. The project descriptions you write or the text extracted from documents you upload, the structured brief generated from it, and the resulting diagrams. This is stored so you can find your projects again.

Subscription data. Your plan status and the customer and subscription identifiers issued by our payment provider. We never receive or store your card details.

We do not use advertising cookies or third-party analytics trackers. The only cookie we set is the one that keeps you signed in.

Uploaded documents

When you upload a PDF, the text is extracted in your own browser. The PDF file itself is never uploaded to our servers. Only the extracted text is sent, so that a brief can be written from it.

Who we share it with

We use the following processors, and only for the purposes listed:

  • Vercel — hosting and serving the website.
  • Neon — the PostgreSQL database where your account and projects are stored (hosted in the United States).
  • NVIDIA — the AI models that write your brief and generate the diagrams. Your project description is sent to them for this purpose.
  • plantuml.com — renders diagram code into images. The diagram source is sent from your browser to this public rendering server. Do not put confidential information into a diagram.
  • Creem — our merchant of record. They process payments, handle tax, and are the seller shown on your statement.
  • Resend — sends account emails such as address verification and password resets.

We do not sell your personal data, and we do not share it for advertising.

How long we keep it

Your account and projects are kept until you delete them or ask us to close your account. Deleting your account removes your profile and all of your saved projects. Records we are required to keep for tax or accounting purposes are retained by our payment provider under their own policy.

Your rights

You can access and correct your name and username from your account page at any time. You can delete any project yourself. To request a copy of your data or the deletion of your account, email soulayman.aabaid2004@gmail.com and we will action it within 30 days.

Security

Passwords are hashed with bcrypt. Sessions use signed tokens sent over HTTPS in an HTTP-only cookie, and changing your password immediately signs out every other device. No system is perfectly secure, but access to your projects is scoped to your account on every request.

Children

UMLKit is not directed at children under 16 and we do not knowingly collect their data.

Changes

If this policy changes materially, the date at the top of this page will be updated. For anything unclear, email soulayman.aabaid2004@gmail.com.