Privacy Policy
Last updated: August 7, 2026
Who we are
Szum is a chart design and rendering service operated by Bartosz Prusinowski, based in Zürich, Switzerland. Bartosz Prusinowski is the controller of the account and service-operation personal data described in this policy. You can reach us at contact@szum.io.
What this policy covers
This policy applies to the Szum website, web application, chart API, MCP server, interactive embeds, and Figma plugin. If you use Szum through a third-party product, such as Figma, GitHub, or an MCP client, that product also processes data under its own privacy policy.
Data we collect
We collect the data needed to provide, secure, and improve Szum:
- Account and authentication – your name, email address, profile image, email-verification status, and authentication records. Passwords are stored as hashes. If you sign in with Figma or GitHub, we receive the account details the provider makes available and store the identifiers and tokens needed to maintain that connection.
- Billing – your plan, subscription status, billing period, Stripe customer identifier, and usage needed for billing. Stripe collects and processes your payment details; Szum does not receive or store your full card number.
- Charts and editor content – chart configurations, data, titles, drafts, publication state, source, timestamps, and storage size when you save or publish a chart.
- API and MCP credentials – API-key names, creation dates, last four characters, and SHA-256 hashes. We do not store recoverable copies of API keys. If you connect an MCP client, we also process the client registration, authorization, and token records required for that connection.
- Usage and product analytics – render counters and product events such as opening the Figma plugin or creating, editing, publishing, or exporting a chart. Our product analytics do not include chart data, titles, configurations, email addresses, or Figma file details.
- Technical and security data – IP address, request time, route, browser and device details, referrer, approximate location, authentication and rate-limit events, and error or diagnostic information. Our infrastructure providers may process this data in request and security logs.
- Communications – messages you send through our feedback form or to our support and contact addresses, plus the information needed to deliver account, usage, storage, and billing emails. If you subscribe to product updates, we also store your email address, subscription source, consent version and time, and current subscription preference.
How chart data is handled
Chart data may contain personal or confidential information. Do not publish a chart containing information you do not want others to see. If you include personal data about other people, you are responsible for having a lawful basis to use it. We process that data on your instructions to provide the service.
- One-off renders – chart configurations submitted in the body of a render request are processed to produce the response and are not saved as charts. The rendered response may still be cached, and our infrastructure providers may retain normal operational logs.
- GET render URLs – when a chart configuration is placed in a URL, it can be recorded in browser history, server or proxy logs, referrer information, and caches. Do not use GET render URLs for sensitive chart data; use an authenticated POST request instead. Successful anonymous render responses may be cached for up to seven days.
- MCP previews – transient chart configurations created by the MCP render tool are stored in Redis for up to 1 hour so the preview URL can work.
- Saved charts and drafts – drafts and saved chart metadata are stored in our database. Published chart configurations are stored in private object storage until you delete them or your account.
- Published charts – image, embed, and chart-page URLs are accessible to anyone who has the opaque link. They are not intended to be secret or suitable for access-controlled data. Public responses may remain in edge caches for up to 24 hours after you unpublish or delete a chart.
Figma plugin and local storage
Chart previews and Figma assets are rendered locally in the plugin. The plugin stores your API key, recent chart state, and plugin preferences in Figma client storage on your device. It also attaches chart configuration, source data, and sharing metadata to the Figma nodes it creates, so that information becomes part of your Figma file.
The plugin contacts Szum to verify an API key and when you choose to publish, update, inspect, or remove a shared chart. Publishing sends the chart configuration to Szum and creates the public links described above. Figma controls its own client storage, files, and platform data.
How and why we use data
- Provide renders, saved charts, embeds, and account features
- Authenticate users and connected MCP clients
- Process subscriptions, measure usage, and bill overages
- Prevent abuse, enforce quotas, and protect the service
- Send service-related emails, opted-in product updates, and responses to support requests
- Understand aggregate usage and improve the product
- Comply with legal obligations and resolve disputes
Where the GDPR applies, we process data to perform our contract with you, for our legitimate interests in operating and securing Szum, to comply with legal obligations, and, where we specifically ask for it, with your consent. We do not sell personal data, use it for third-party advertising, or send marketing emails without your consent.
Services that process data for us
We use the following providers to operate Szum:
- Cloudflare – CDN, network security, IP handling, cache management, and Turnstile abuse checks
- Vercel – hosting, server execution, private object storage, queues, edge delivery, and privacy-focused web and product analytics
- Turso – database hosting
- Upstash – Redis storage for usage, rate limits, temporary charts, and operational state
- Stripe – subscriptions, payment processing, billing records, and usage-based charges
- Resend – transactional email delivery, opted-in product updates, subscription management, and forwarding messages sent to Szum addresses
- Sentry – application error monitoring using sanitized technical diagnostics and bounded operational state without request bodies, query strings, headers, cookies, content, or user profiles
- Figma and GitHub – optional sign-in providers; Figma also hosts and runs the plugin
- Google Fonts – font files and font metadata used when a selected chart theme requires them
These providers process data under their own terms and privacy policies. We may also disclose information when required by law, to protect users or the service, or as part of a business transfer. We do not otherwise share personal data with third parties for their own marketing.
International transfers
Szum is operated from Switzerland, and some providers process data in the European Economic Area, the United States, or other countries. Where required, transfers are based on an adequacy decision or appropriate contractual safeguards, such as standard contractual clauses.
Cookies and device storage
We use essential cookies to keep you signed in and complete security and authentication flows. We do not use advertising cookies. Vercel Web Analytics does not use cookies and reports anonymized, aggregate data. Cloudflare may use necessary security mechanisms when checking for automated abuse.
The web application may use browser storage for an unsaved local editor draft, preferences, and the last sign-in method. This stays in your browser until the application clears it or you clear site data. Figma plugin storage is described above.
Data retention
- Account, authentication, and subscription data is kept while your account is active. Some billing, fraud-prevention, and legal records may be retained longer where required or reasonably necessary.
- Newsletter consent and preference records are kept while needed to deliver updates or honor an opt-out. Deleting a linked account also removes its marketing contact.
- Saved charts and drafts are kept until you delete them or your account. Database access is removed when deletion is processed; cleanup of associated object storage is asynchronous. Limited copies may remain temporarily in provider backups or caches.
- We retain limited de-identified usage counters after account deletion for product analytics. They are not used to restore the account or contact you.
- Anonymous monthly usage data keyed by IP expires at the start of the next month. Short-term rate-limit and authentication-abuse records expire within seconds or minutes.
- Transient MCP chart previews expire after 1 hour. Public cache periods are described in the chart-data section above.
- Analytics, request logs, emails, and support records are retained according to operational need and the applicable provider settings.
Security
We use technical and organizational safeguards designed to protect data, including access controls, hashed passwords and API keys, encrypted network connections, private storage for saved chart configurations, and rate limiting. No internet service can guarantee absolute security. Keep API keys secret and do not use public chart links for confidential information.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data, and to withdraw consent where processing relies on it. You may also have the right to complain to a data protection authority.
You can manage your product-update preference, charts, API keys, and account from your account. Every product update also includes an unsubscribe option. For another request, email contact@szum.io. We may need to verify your identity before completing a request. These rights may be subject to exceptions under applicable law.
Szum does not make decisions based solely on automated processing that produce legal or similarly significant effects about you.
Children
Szum is not intended for children under 16. We do not knowingly collect personal data from children under 16.
Changes to this policy
We may update this policy as Szum changes. We will update the date at the top and, when appropriate, provide additional notice to registered users.
Contact
Questions or privacy requests? Email contact@szum.io.