Privacy Policy

Last updated 2 September 2026

What Viaduct collects, why, and what you can ask us to do about it. The short version: your model is yours, we recognise you by the identifier your sign-in provider gives us rather than by your email address, and nothing leaves your browser at all if you work without an account.

1. Who is responsible

Quiet Grid Labs co. ("Quiet Grid Labs"), Žemaitės gatvė 5c, Vilnius, Lithuania, is the controller of the personal data described here. Write to support@quietgridlabs.com about anything on this page.

We are established in Lithuania, so this policy is written to the GDPR. We are not required to appoint a data protection officer and have not appointed one — write to the address above and it reaches the person responsible.

2. What we collect

Account data, from whichever provider you sign in with:

  • the provider’s own account identifier, which is the only thing we use to recognise you — never your email address;
  • your username or handle, display name, email address and avatar URL, as that provider reports them;
  • for GitLab sign-in, an access token, so the application can read the groups that decide what you may open. That GitLab is our own instance at git.quietgridlabs.com, not a third party’s.

Content you create: models, elements, connections, documentation, sequence diagrams, contracts, comments, project and version names, and the files you attach.

Technical data: a session cookie, the time of your last sign-in, and ordinary server logs — IP address, user agent, request path and time — kept for security and debugging.

Messages you send: what you write in the support and access-request forms, and the address we reply to.

Nothing is collected from the local editor. If you use Viaduct without an account, the model lives in your browser’s storage and never reaches us.

3. Why we use it, and on what basis

  • To run the service and keep your work where you left it — performance of our contract with you.
  • To keep accounts secure, prevent abuse and diagnose faults — our legitimate interest in a service that works.
  • To answer support and access requests — performance of a contract, or legitimate interest.
  • To understand which features are used, in aggregate — legitimate interest, through the privacy-preserving analytics described below.
  • To send service messages about outages, security or material changes — legitimate interest. Marketing email, if we ever send any, will be on consent you can withdraw.

We do not sell personal data, and we do not profile anyone for advertising.

4. AI tools and the MCP server

The MCP server exists so that an AI development tool you have connected — Cursor, Claude Code, or another client — can read and write your model. That happens only when you issue a personal access token and configure the client with it, and only for the projects that token can reach.

What the client then does with the data is governed by that tool’s own terms, not ours. Revoking the token in your account settings ends the access immediately.

We do not use your models to train machine learning models.

5. Cookies and analytics

One essential cookie holds your signed-in session. Without it you cannot stay signed in, so it is set when you sign in and cleared when you sign out.

Your browser also keeps preferences locally — colour theme, the provider you signed in with last, and the local model if you work without an account. These never leave your device, and they are not cookies.

Usage is measured with Umami Cloud, a cookieless analytics service that records page views and feature events without cross-site identifiers or fingerprinting, and with our own product metrics at metrics.quietgridlabs.com, which record which action happened and for which account — never the contents of your model.

6. Who else sees it

People you share with: anyone you invite to a project, and anyone holding a share link you have created, sees the content of that project.

Share links: a link you create gives whoever holds it access to that project until you revoke it. Revoking is immediate and is done from the project’s share panel.

Service providers who process data on our instructions:

  • Timeweb (Netherlands, EU) — the servers this application runs on, its database and its backups;
  • Timeweb (Netherlands, EU) — outgoing mail, meaning support replies and access-request notifications;
  • Umami Software, Inc. (United States) — the Umami Cloud analytics described above.

There is no CDN or proxy in front of the application, and the product metrics run on our own servers.

Two things you initiate leave for someone else, and neither is us passing your data on. Signing in sends you to Google, GitHub or our GitLab and brings back the account details named above; Google and GitHub decide for themselves what they do with that visit, under their own policies. Donating sends you to Stripe or CloudTips, who take the payment on their own account — we never receive your card details, only the fact that a donation arrived.

One of those is contacted by your browser directly rather than through us, and so sees the IP address any request carries: the Umami script. Everything else — the typefaces, the images, every other script — is served from this origin, so nothing further about your visit reaches anyone.

Our hosting and mail sit in the Netherlands, inside the EU, so your account and your model never leave the EEA. The analytics is the exception: Umami Cloud is operated from the United States, so the page views and events it receives are processed outside the EEA under that provider’s data processing terms. It is the only part of this that crosses the border, and it carries no account of yours and nothing from your model.

We disclose data to authorities only where the law requires it, and will tell you unless we are forbidden from doing so.

7. How long we keep it

  • Account and content: for as long as your account exists, and removed from the live database within 30 days of your asking us to delete it.
  • Backups: taken daily and kept for six months, so a deleted account survives in backups for up to six months before the last copy rolls off. Backups are only ever used to restore the service after a failure.
  • Server logs: one month.
  • Support correspondence: kept indefinitely, so that a conversation years apart still has its history. Ask us and we will delete your side of it.

Deleting an account is done by writing to us rather than by a button in the application — there is no self-service delete yet. We do it by hand, and confirm when it is done.

8. Security

Traffic runs over TLS. Session cookies are signed, HTTP-only and same-site. Personal access tokens are stored as hashes, so a copy of the database does not yield a working token. Access to production is limited to the people who need it.

No service is immune. If a breach affects your data we will notify you and the relevant authority within the time the law allows.

9. Your rights

Depending on where you live, you may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to send it to another provider. You may also complain to your local data protection authority.

Write to support@quietgridlabs.com and we will answer within one month. Your model can be exported as JSON from the editor at any time without asking us.

10. Children

Viaduct is a tool for software teams and is not directed at children. We do not knowingly collect data from anyone under 16; write to us if you believe we have, and we will delete it.

11. Changes to this policy

We update this page when what we do changes, and the date at the top says when. Material changes are announced in the application before they take effect.