Privacy policy
Updated 13 August 2026
- This is a translation. The service operates under Russian law and the Russian version is the one that governs. Where the two differ, the Russian text wins.
- We do not hand the contents of your boards to third parties. We hold it to store it and to show it to you and to the people you opened it to.
- We do not sell data and we show no advertising. There are no advertising or third-party tracking cookies.
- We keep data for the shortest time that works and delete it automatically.
1.About this document
This describes what data Sketchbord collects, why, how long it keeps it and who it passes it to. It supplements the terms of service, and it is at the same time the personal-data processing policy that Russian federal law 152-ФЗ requires to be published.
The personal-data operator is the developer of the service. Their name and details will be given here; until then, the operator can be reached through the contacts in the last section.
2.What we collect
When you create an account: your email address and a password. The password is stored only as an irreversible hash — we do not know it and cannot recover it. A name is optional.
When you work on a board: what you make on it — shapes, text, notes, uploaded images, the tree of levels. This is the content you came here for.
Technical records about the service: events such as "a board was created" or "a template was inserted", per-day usage counters, and a log of the actions that matter for security (sign-in, password change, board deletion).
If you ask about a paid plan: the contact you type in yourself, and your note if you write one.
If you post an idea: its text and the comments. The ideas section is public — see section 7.
3.What our data does not contain
This matters as much as the section above:
- Board contents never reach the event statistics. We record that a board was created, but not its name and not what is drawn on it.
- Full IP addresses are not kept in the security log: the address is truncated to its network — 1.2.3.0/24 for IPv4, the first three groups for IPv6. That is enough to tie break-in attempts together and not enough to follow a person.
- Passwords, tokens, keys and authorisation headers are stripped from technical logs automatically, before anything is written.
4.What we use it for
- To run the service: to store and synchronise boards, to show them to you and to the people on them, to let you in with your password, to restore access by email.
- To find and fix faults: technical logs and request traces are what show which part broke.
- To learn what gets used: events answer questions like "do people use templates" and "which limit do they stop at". They are about features, not about people.
- To protect accounts: the security log and the failed-sign-in counter are what put a ceiling on password guessing.
- To answer you: if you left a request or wrote to us.
None of it is used for advertising, profiling or sale to third parties.
5.On what legal basis
The law requires a legal basis for every kind of processing. We have two, and both are simple:
- Performing our agreement with you — everything without which the service does not work: the account, the boards, synchronisation, password recovery, protection against password guessing. That processing is needed to carry out the terms of service, and the law asks for no separate consent to it.
- Your consent — everything else: a paid-plan request, posting an idea, writing to us. You give that consent by the act itself, by sending the form, and you choose what goes in it. Consent can be withdrawn by writing to us.
6.Cookies and the visit counter
We set one cookie. It holds the fact that you are signed in, is unreadable by page scripts (httpOnly), travels only over a secure connection, and exists so that you do not type your password on every page. The service cannot work without it, which is why we do not ask for separate consent to it.
There are no advertising cookies. The visit counter runs on every page, board pages included, but it receives exactly one thing — the page address. Before anything leaves, every message from the counter goes through our own filter, which:
- keeps the path only: everything after “?” and “#” is dropped — that is where one-time tokens live;
- throws away any invitation address whole: the code in such a link is a key to a board, and it leaves your browser neither as the page address nor as the referrer;
- replaces the page title with the constant “Sketchbord”: what your board is called is your business.
What is left of an owner's visit: "a board with this identifier was opened". The identifier is not itself a key — the board opens from your account only. A visit through an invitation is recorded differently: instead of the address, an irreversible fingerprint of the link, which shows that this invitation was opened but neither opens the board nor says which board it is. Board contents never reach the counter at all: it does not read the page. We serve the counter script from our own domain rather than embedding somebody else's.
7.What other people can see
An invitation link is access. Anyone who opens it sees the board within the role it grants. We do not check who followed it. That is why such a link is temporary: after a day it stops opening the board, and that is not a setting anybody can turn off. It can be revoked sooner, in the same place it was created.
Uploaded images are reachable by their direct address. The address contains a random unguessable part, but if such an address gets out, the image can be seen through it without signing in.
The ideas section is public. Your ideas, votes and comments are visible to everyone. Your name is shown beside them if you gave one — but never the email address you sign in with: those are different things and we do not mix them.
8.Who we pass data to
We do not sell data and do not pass it on for advertising. It is passed on only where the service would not work otherwise:
- Infrastructure providers — the database, the cache, the file storage for images, the servers. They hold the data on our instructions.
- An email service — it delivers password-recovery letters. It receives the recipient's address.
- Telegram — if you ask about a paid plan, the contact you gave and your note reach the developer as a Telegram message. This is the most visible case of data leaving: Telegram's servers are outside Russia, which makes it a cross-border transfer, so it is named separately. Do not put anything in that form you would not want sent through Telegram.
- Where the law requires it — on a lawful request.
9.Where data is stored
The database, uploaded images and technical logs live on servers inside Russia, as the personal-data law requires. The single exception described above is the paid-plan request, which by your own choice goes out as a Telegram message.
10.How long we keep it
The general rule: we keep data for the shortest time that works — while it is needed for the purposes in section 4 and while the law requires it to be kept. After that it is deleted automatically rather than left lying around.
- Boards and images — until you delete them. A deleted board goes with its levels and its images, and the links handed out for it stop working.
- Service events — 180 days, after which a nightly sweep deletes them. That is long enough to see how the service is developing and short enough not to turn the table into an open-ended archive of behaviour.
- The log of security-relevant actions — 365 days. That is what it takes to understand an incident discovered months later; then the same automatic sweep removes it. It never held a full address or a link to an account in the first place (see section 3).
- Account data — while the account exists.
11.How we protect it
- Passwords are stored as an irreversible hash; sign-in tokens and recovery links are hashed too, and a recovery link works once.
- The connection is secured, the sign-in cookie travels only over it and is unreadable by scripts.
- Changing the password and signing out everywhere invalidate previously issued tokens immediately.
- Passwords, tokens and authorisation headers are stripped from technical logs before they are written.
- Keys for AI agents can be revoked at any moment, and stop working the instant they are.
At the same time the service is in beta and we give no guarantee that data will survive — the second section of the agreement says so plainly. Do not keep anything important here only.
12.Your data is yours
- Any board can be deleted by you, at any time.
- The password can be changed, and sessions on every device ended, in your account settings.
- Agent keys and invitation links are revoked in the same place.
- To delete the account entirely, get a copy of your data, or ask what is held about you — write to us. There is no separate button for deleting an account yet, and we are not pretending there is.
When an account is deleted its boards and images are deleted, and service events lose their link to it — what remains is the anonymous fact that an event once happened.
Beyond that you have rights under the Russian personal-data law: to learn what data about you is processed; to require it corrected, blocked or destroyed if it is inaccurate or processed unlawfully; to withdraw consent. Writing to us is enough for any of those — we answer within the period the law sets (ten working days). If you believe we are handling your data wrongly you may complain to Roskomnadzor or go to court — but we would be grateful if you wrote to us first.
13.Changes to this policy
We may update this document — when a legal entity appears, for example, or payments. The date of the last change is at the top of the page; we will give notice of substantial changes rather than editing the text quietly.
14.Getting in touch
Questions about data — to support@dev-sketchbord.ru or on Telegram @kizilov_yura. The developer answers.