Privacy Policy
Effective: September 17, 2026 · Operator: K4Works
1. Operator and scope
K4Works operates Schema Studio at schema-studio.net. This policy covers personal data handled by our website, sign-in, workspaces and cloud documents. Contact us about privacy or the service at [email protected].
2. Information and purposes
When you sign in with Google or GitHub, we process your provider account identifier, email address, and the name and profile image supplied by the provider through Supabase Auth. We use this information to identify your account, maintain your session and manage workspace access. Google access is limited to basic profile and email; we do not access Gmail, Drive or contacts. We use the email and information you send in a support request to resolve it.
3. Schema documents and browser storage
We do not request source database passwords or actual records. Imported schemas, descriptions, layouts and edits are stored in browser IndexedDB. Choosing cloud save stores the document and its workspace and author information on our servers, accessible to workspace members according to their permissions. Table names and descriptions may contain confidential information; review them before saving. Browser storage also maintains login sessions and language preferences.
4. Service providers and international processing
Supabase provides authentication and database services; Cloudflare provides website hosting, delivery and security. Our current Supabase project database is in Tokyo, Japan. Google and GitHub process information under their own policies as your chosen sign-in provider. Cloudflare’s distributed network and provider operations or support may process information outside your country. Operational logs, such as IP addresses, request times and browser information, may be processed to deliver and secure the service. Except where disclosure is legally required, we share information with providers only as needed to operate the service.
5. Limited use of Google user data
We use information received from Google only for the user-facing features described above, not for advertising targeting, sale of data or training general-purpose AI models. Our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. Retention and deletion
We retain account information and cloud documents while maintaining your account and providing the service. Request account or document deletion at [email protected]. After verifying your identity and the permissions and retention scope of shared documents, we delete active data no longer needed; information legally required to be retained is kept until that obligation ends. Provider backups and security logs expire according to provider retention cycles and may not disappear at the same time as active data. There is currently no in-app account deletion screen. Local copies remain after sign-out; clear this site’s browser data to remove them. Local checkpoints are limited to 30 per document and 30 days.
7. Your choices and safeguards
Contact [email protected] to request access, correction or deletion, or ask about data processing. You can revoke access in Google account connections or GitHub’s Authorized OAuth Apps settings. Revocation alone does not delete your existing account, cloud documents or local copies. We protect information with HTTPS, authentication and workspace access controls. The current app does not use advertising trackers or third-party marketing analytics SDKs.
8. Policy changes
We publish policy changes and their effective date on this page. We communicate material changes to data processing through an appropriate method, such as a service notice.
Google API Services User Data Policy · Google connections · GitHub OAuth Apps