개인정보처리방침
시행일: 2026년 7월 20일 · 최종 수정: 2026년 7월 20일
1. 이 방침이 다루는 것
howtodraw.cloud(이하 "서비스")는 브라우저에서 클라우드 아키텍처 다이어그램을 그리는 무료
웹 편집기이며, 개인이 취미로 운영하는 커뮤니티 서비스입니다. 판매하는 상품이 없고, 광고를
싣지 않으며, 개인정보를 판매하지 않습니다.
이 방침은 howtodraw.cloud에서 제공되는 서비스에 적용됩니다. 이 서비스의
소스 코드는 MIT 라이선스로 공개되어 있으며, 직접 내려받아 실행하는 경우에는 서버가 없으므로
이 방침의 서버 관련 항목이 적용되지 않습니다.
2. 로그인하지 않고 사용할 때
편집기는 로그인 없이 완전하게 동작합니다. 이 경우 개인정보는 서버로 전송되지
않습니다.
-
작성 중인 다이어그램과 편집기 설정(기본 스타일, 즐겨찾는 아이콘, 단축키, 언어 등)은
브라우저의 로컬 저장소에만 저장됩니다.
-
링크로 공유하기(
#d= 형식)는 다이어그램을 압축해 URL 조각(fragment)에
담습니다. URL 조각은 브라우저가 서버로 보내지 않는 부분이므로, 이 방식으로 공유한
다이어그램은 서비스가 보관하지 않습니다.
-
광고, 행동 분석 도구, 트래킹 스크립트, 트래킹 쿠키를 사용하지 않습니다.
3. Google 계정으로 로그인할 때 수집하는 정보
로그인은 Google OAuth 2.0과 AWS Cognito를 통해 처리됩니다. 서비스는 Google에
openid, email, profile 범위(scope)만 요청하며,
Google로부터 다음 정보를 전달받아 저장합니다.
- 이메일 주소 및 이메일 인증 여부
- 프로필 사진 URL (계정 버튼에 표시하는 용도)
- 계정을 식별하기 위한 고유 식별자(Cognito가 발급하는
sub)
서비스는 Google 비밀번호를 받지 않으며, Gmail·Drive·연락처·캘린더 등
다른 Google 데이터에 대한 권한을 요청하지 않습니다.
4. 서비스를 이용하는 동안 저장되는 정보
-
다이어그램 — 제목, 다이어그램 내용(JSON), 미리보기 이미지, 공개 범위,
생성·수정 일시, 그리고 갤러리 목록을 위한 요약 정보(사용된 클라우드 제공사, 서비스 종류,
객체 개수).
-
동기화된 편집기 설정 — 기본 스타일, 즐겨찾는 아이콘, 사용자 지정 카테고리,
단축키, 언어, 제공사 표시 설정.
-
표시 이름 — 다이어그램을 공개할 때 작성자로 표시할 이름을 직접 지정한 경우.
-
신고 기록 — 공개된 다이어그램을 신고한 경우, 중복 신고를 막기 위해 신고자의
계정 식별자가 해당 다이어그램에 기록됩니다.
-
운영 로그 — 서버(AWS Lambda, CloudFront)가 남기는 접속 기록으로 요청 시각,
IP 주소, 사용자 에이전트, 요청 경로 등이 포함됩니다. 장애 대응과 남용 방지 목적으로만
사용합니다.
5. 이용 목적
수집한 정보는 서비스를 제공하기 위해서만 사용합니다. 즉, 이용자를 인증하고,
저장한 다이어그램을 다시 열어주고, 기기 간 설정을 동기화하고, 이용자가 직접 공개하기로 한
다이어그램을 갤러리에 보여주고, 장애와 남용에 대응하는 데 사용합니다. 마케팅, 프로파일링,
광고 타겟팅에는 사용하지 않습니다.
6. 보관 장소와 처리 위탁
데이터는 미국 버지니아 북부 리전(AWS us-east-1)에 저장됩니다. 한국에서
이용하는 경우 개인정보가 국외로 이전되어 처리된다는 점에 동의하는 것이 됩니다.
-
Amazon Web Services, Inc. — 인증(Cognito), 서버(Lambda), 데이터베이스
(DynamoDB), 파일 저장(S3), 배포(CloudFront). 저장·전송 목적.
- Google LLC — 로그인 인증 목적.
이 외의 제3자에게 개인정보를 제공하거나 판매하지 않습니다. 법령에 따라 요구되는 경우에만
예외로 합니다.
7. 보관 기간
- 다이어그램과 설정은 이용자가 삭제할 때까지 보관합니다.
- 다이어그램을 삭제하면 내용, 미리보기 이미지, 메타데이터가 함께 삭제됩니다.
-
탈퇴하면 해당 계정의 모든 다이어그램, 미리보기 이미지, 동기화된 설정,
표시 이름과 로그인 계정 자체(이메일 주소 포함)가 삭제됩니다. 남는 것은
없으며, 다시 로그인하면 이전과 이어지지 않는 새 계정으로 시작합니다.
-
운영 로그는 장애 대응과 남용 방지에 필요한 기간 동안만 보관하고, 목적을 다하면 삭제합니다.
8. 공개 범위는 이용자가 정합니다
모든 다이어그램은 기본이 비공개입니다. 이용자가 직접 링크 공개
(링크를 아는 사람만) 또는 전체 공개(갤러리에 목록으로 노출)로 바꿀 수 있습니다.
전체 공개된 다이어그램에는 제목, 미리보기 이미지, 요약 정보, 그리고 이용자가 지정한 표시 이름이
함께 보이며, 이메일 주소는 어떤 경우에도 다른 이용자에게 노출되지 않습니다.
9. 이용자의 권리
-
열람·수정 — 저장한 다이어그램과 설정은 로그인 후 언제든지 앱 안에서 열람하고
수정할 수 있습니다.
-
내려받기 — 모든 다이어그램은 언제든 완전한
.json 파일로
내려받을 수 있으며, 이 파일은 서비스 없이도 열립니다. 서버에만 존재하는 형식은 없습니다.
-
삭제 · 탈퇴 — 개별 다이어그램을 삭제하거나, 계정 전체를 탈퇴할 수
있습니다. 탈퇴는 설정 → 일반 → 내 계정 → 회원 탈퇴에서 직접 하실 수
있고, 별도의 요청이나 승인이 필요하지 않습니다.
-
동의 철회 — Google 계정의 앱 권한 페이지에서 이 서비스의 접근
권한을 언제든 해제할 수 있습니다.
-
위 권리 행사나 문의는 아래 연락처로 요청하실 수 있으며, 확인 후 처리합니다.
10. 안전성 확보 조치
모든 통신은 HTTPS로 암호화됩니다. 인증 토큰은 유효 기간을 짧게 두고, 저장소의 키는 계정별로
분리되어 한 이용자의 세션에서 다른 이용자의 데이터에 접근할 수 없습니다. 파일 저장소는 외부에
직접 공개되지 않고, 서버가 발급한 유효 기간이 짧은 URL로만 접근합니다.
11. 아동의 개인정보
이 서비스는 만 14세 미만 아동을 대상으로 하지 않으며, 아동의 개인정보를 알면서 수집하지
않습니다. 아동의 정보가 수집된 것을 알게 되면 삭제합니다.
12. 방침의 변경
이 방침이 바뀌면 이 페이지에 새로운 시행일과 함께 게시합니다. 중요한 변경이 있는 경우
서비스 안에서도 안내합니다.
13. 문의처
운영자: 개인 (howtodraw.cloud)
이메일: tiaz0128.dev@gmail.com
Privacy Policy
Effective: 20 July 2026 · Last updated: 20 July 2026
This is an English translation of the Korean policy. If the two ever disagree,
the Korean text governs.
1. What this policy covers
howtodraw.cloud (the "Service") is a free, browser-based editor for cloud
architecture diagrams, run by an individual as a community project. Nothing is
sold, no advertising is served, and personal data is never sold.
This policy applies to the Service hosted at howtodraw.cloud. The
source code is published under the MIT license; if you run it yourself there is
no server, and the server-side sections here do not apply.
2. Using the Service without an account
The editor works fully without signing in. In that mode no personal data
is sent to any server.
-
Your working diagram and your editor settings (default styles, favorite icons,
keybindings, language, and so on) are kept in your browser's local storage only.
-
Share-by-link (the
#d= form) compresses the diagram into the
URL fragment, which browsers never send to a server. Diagrams
shared this way are not stored by the Service.
- No advertising, analytics, tracking scripts, or tracking cookies are used.
3. What we receive when you sign in with Google
Sign-in is handled through Google OAuth 2.0 and AWS Cognito. The Service requests
only the openid, email, and profile scopes,
and stores the following from Google:
- your email address and whether it is verified;
- your profile picture URL, used to draw the account button;
- a stable identifier for your account (the Cognito
sub).
The Service never receives your Google password and requests no
access to Gmail, Drive, Contacts, Calendar, or any other Google user data.
4. What is stored while you use the Service
-
Diagrams — title, diagram content (JSON), thumbnail, visibility,
creation and update timestamps, and a summary used for gallery listings (which
cloud providers and service types appear, and how many objects).
-
Synced editor settings — default styles, favorite icons, custom
categories, keybindings, language, provider toggles.
-
Display name — only if you choose one for diagrams you publish.
-
Reports — if you report a published diagram, your account
identifier is recorded on that diagram so one person cannot report it twice.
-
Operational logs — server and CDN access records (AWS Lambda and
CloudFront) including request time, IP address, user agent, and path. Used only to
keep the Service running and to handle abuse.
5. How it is used
Only to provide the Service: to authenticate you, to give your saved diagrams back,
to sync settings between your devices, to list diagrams you chose to publish, and to
respond to outages and abuse. Never for marketing, profiling, or ad targeting.
6. Where data is stored, and processors
Data is stored in the AWS us-east-1 region (Northern Virginia, USA).
If you use the Service from outside the United States, your data is transferred
there for processing.
-
Amazon Web Services, Inc. — authentication (Cognito), compute
(Lambda), database (DynamoDB), object storage (S3), delivery (CloudFront).
- Google LLC — sign-in.
Personal data is not otherwise shared with or sold to third parties, except where
required by law.
7. Retention
- Diagrams and settings are kept until you delete them.
- Deleting a diagram removes its content, thumbnail, and metadata.
-
Closing your account removes every diagram, thumbnail, synced setting,
your display name, and the sign-in record itself — your email address with
it. Nothing is kept back; signing in again starts a new account with
no link to the old one.
-
Operational logs are kept only as long as needed for reliability and abuse
handling, then deleted.
8. You choose what is public
Every diagram is private by default. You can change it to
unlisted (anyone with the link) or public (listed
in the gallery). A public diagram shows its title, thumbnail, summary, and the
display name you chose. Your email address is never shown to other
users.
9. Your rights
-
Access and correction — sign in and your diagrams and settings are
all viewable and editable in the app.
-
Portability — any diagram can be downloaded at any time as a
complete
.json file that opens in the editor with the service switched
off. There is no server-only format.
-
Deletion — delete individual diagrams, or close your whole
account from Settings → General → This account → Close account.
It takes effect immediately; no request or approval is involved.
-
Withdrawing consent — you can revoke this app's access at any time
from your Google account permissions page.
- To exercise any of these, or to ask a question, use the contact below.
10. Security
All traffic is served over HTTPS. Authentication tokens are short-lived, storage keys
are namespaced per account so one user's session cannot reach another's data, and the
file store is not publicly reachable — access goes through short-lived URLs issued by
the server.
11. Children
The Service is not directed to children under 14, and does not knowingly collect their
personal data. If we learn that we have, we delete it.
12. Changes
Changes are posted on this page with a new effective date. Significant changes are also
announced in the app.
13. Contact
Operator: an individual (howtodraw.cloud)
Email: tiaz0128.dev@gmail.com