Privacy Policy
Last updated 2 September 2026
What Viaduct collects, why, and what you can ask us to do about it. The short version: your model is yours, we recognise you by the identifier your sign-in provider gives us rather than by your email address, and nothing leaves your browser at all if you work without an account.
1. Who is responsible
Quiet Grid Labs co. ("Quiet Grid Labs"), Žemaitės gatvė 5c, Vilnius, Lithuania, is the controller of the personal data described here. Write to support@quietgridlabs.com about anything on this page.
We are established in Lithuania, so this policy is written to the GDPR. We are not required to appoint a data protection officer and have not appointed one — write to the address above and it reaches the person responsible.
2. What we collect
Account data, from whichever provider you sign in with:
- the provider’s own account identifier, which is the only thing we use to recognise you — never your email address;
- your username or handle, display name, email address and avatar URL, as that provider reports them;
- for GitLab sign-in, an access token, so the application can read the groups that decide what you may open. That GitLab is our own instance at git.quietgridlabs.com, not a third party’s.
Content you create: models, elements, connections, documentation, sequence diagrams, contracts, comments, project and version names, and the files you attach.
Technical data: a session cookie, the time of your last sign-in, and ordinary server logs — IP address, user agent, request path and time — kept for security and debugging.
Messages you send: what you write in the support and access-request forms, and the address we reply to.
Nothing is collected from the local editor. If you use Viaduct without an account, the model lives in your browser’s storage and never reaches us.
3. Why we use it, and on what basis
- To run the service and keep your work where you left it — performance of our contract with you.
- To keep accounts secure, prevent abuse and diagnose faults — our legitimate interest in a service that works.
- To answer support and access requests — performance of a contract, or legitimate interest.
- To understand which features are used, in aggregate — legitimate interest, through the privacy-preserving analytics described below.
- To send service messages about outages, security or material changes — legitimate interest. Marketing email, if we ever send any, will be on consent you can withdraw.
We do not sell personal data, and we do not profile anyone for advertising.
4. AI tools and the MCP server
The MCP server exists so that an AI development tool you have connected — Cursor, Claude Code, or another client — can read and write your model. That happens only when you issue a personal access token and configure the client with it, and only for the projects that token can reach.
What the client then does with the data is governed by that tool’s own terms, not ours. Revoking the token in your account settings ends the access immediately.
We do not use your models to train machine learning models.
5. Cookies and analytics
One essential cookie holds your signed-in session. Without it you cannot stay signed in, so it is set when you sign in and cleared when you sign out.
Your browser also keeps preferences locally — colour theme, the provider you signed in with last, and the local model if you work without an account. These never leave your device, and they are not cookies.
Usage is measured with Umami Cloud, a cookieless analytics service that records page views and feature events without cross-site identifiers or fingerprinting, and with our own product metrics at metrics.quietgridlabs.com, which record which action happened and for which account — never the contents of your model.
7. How long we keep it
- Account and content: for as long as your account exists, and removed from the live database within 30 days of your asking us to delete it.
- Backups: taken daily and kept for six months, so a deleted account survives in backups for up to six months before the last copy rolls off. Backups are only ever used to restore the service after a failure.
- Server logs: one month.
- Support correspondence: kept indefinitely, so that a conversation years apart still has its history. Ask us and we will delete your side of it.
Deleting an account is done by writing to us rather than by a button in the application — there is no self-service delete yet. We do it by hand, and confirm when it is done.
8. Security
Traffic runs over TLS. Session cookies are signed, HTTP-only and same-site. Personal access tokens are stored as hashes, so a copy of the database does not yield a working token. Access to production is limited to the people who need it.
No service is immune. If a breach affects your data we will notify you and the relevant authority within the time the law allows.
9. Your rights
Depending on where you live, you may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to send it to another provider. You may also complain to your local data protection authority.
Write to support@quietgridlabs.com and we will answer within one month. Your model can be exported as JSON from the editor at any time without asking us.
10. Children
Viaduct is a tool for software teams and is not directed at children. We do not knowingly collect data from anyone under 16; write to us if you believe we have, and we will delete it.
11. Changes to this policy
We update this page when what we do changes, and the date at the top says when. Material changes are announced in the application before they take effect.