Drawoble · Legal
Privacy Policy
This policy describes the personal data Drawoble actually processes today, written around the real behaviour of the hosted service rather than a generic template. If the product does not do something, this document does not claim it.
Private beta notice. Drawoble is in private beta. The service, its vendors and this policy change as the product matures. Material changes are announced through the change history and its RSS feed, and, where they affect your rights, by email at least 30 days before they take effect.
1. Identity of the data controller
The hosted Drawoble service at app.drawoble.com is operated by
Berk Kurtel, an individual based in Istanbul, Republic of Türkiye,
acting as the data controller (veri sorumlusu) for the personal data described
in this policy. Drawoble is a trade name; no company is registered for it at
this stage of the product.
Written contact routes, all of which reach the operator directly:
- Privacy, data-rights and KVKK/GDPR requests: privacy@drawoble.com
- Legal notices: legal@drawoble.com
- Product support: support@drawoble.com
- Billing questions: billing@drawoble.com
2. Purposes of processing
Drawoble processes five classes of data, and nothing outside them. Each class is listed with what it contains and why it exists.
2.1 Account and sign-in
Signing in is passwordless: you enter your email address, we email you a six-digit one-time code that is valid for ten minutes, and verifying that code creates your session. We therefore process:
- your email address and account identifier;
- an optional display name, which you set yourself and which is never required — your real name is never requested;
- session records: session identifiers, creation and expiry timestamps, and the browser user-agent string, which we show back to you as a coarse device label (browser and operating-system family only) so you can review and revoke your own sessions;
- abuse-prevention records: your email address and the IP address of the sign-in attempt, kept as short-lived rate-limit and lockout keys, plus the time a one-time code was last issued to an address.
Purpose: creating and operating your account, delivering the sign-in code, keeping sessions valid and revocable, and preventing brute-force and abuse of the login endpoint.
2.2 Projects, drawings and assets
When you use the hosted service, your drawing documents are stored so they survive across devices and sessions. This covers the project title you type, the drawing document itself (geometry, layers, text annotations, sheets), any images you embed, and metadata such as file size, image dimensions and content hashes.
Drawing content is yours. We process it only to operate the service for you: storing it, syncing it, letting you export it, and — when you ask us for help with a specific problem — supporting it. Your drawing titles and annotations may contain personal data about third parties (for example a client name on a title block); when they do, you are the controller for that content and Drawoble processes it on your behalf.
2.3 Error and performance monitoring
The application reports unhandled errors to the monitoring vendor listed in the sub-processor list so crashes can be diagnosed. Reports contain the error and its stack trace, the page URL, browser and device characteristics, a release identifier, and a small trail of preceding interaction events.
Alongside errors, the application measures how smoothly the editor runs and sends aggregate performance samples to the same vendor. A sample covers one short burst of activity — a few seconds of drawing, panning or zooming — and carries three numbers (an average frame rate, a 95th-percentile frame time, and a count of slow browser tasks) plus four coarse labels: which kind of interaction it was, whether the drawing was small, typical or large, a rough device tier, and the release identifier. Samples are read in aggregate, across many sessions, to find features that have become slow. They carry no drawing content, no coordinates, no layer or project names, and no text you have written.
Reports deliberately do not carry your account identifier or email address, there is no session replay, and your screen and drawings are never recorded. The monitoring vendor nevertheless receives the IP address the report is sent from, because that is inherent to any network request. Only a sample of performance traces is collected.
2.4 Support and contact
If you write to one of the addresses in section 1, we process your email address, your message, anything you attach, and the account context needed to answer you. Purpose: answering your request and keeping a record of what was asked and what we did.
2.5 Marketing communications
Drawoble does not currently operate a marketing mailing list. The only email the service sends is transactional: your sign-in code and, where relevant, account, security or legal notices. If and when optional product-update emails begin, they will require your separate, explicit, unticked opt-in — never bundled into account creation, and withdrawable in one step. Acknowledging this policy is not consent to marketing.
3. Recipients and transfers
Drawoble does not sell personal data, does not share it with advertisers or data brokers, and does not use your drawings to train machine-learning models.
Personal data is processed by a small set of service providers acting as our processors — hosting, database and storage, email delivery, edge protection and error monitoring. The current list, with each vendor's purpose, country, public data processing agreement and transfer safeguard, is published and kept up to date at:
drawoble.com/legal/sub-processors
We publish that list separately, rather than freezing vendor names into this document, so it cannot silently drift out of date. Adding or replacing a processor is announced at least 30 days in advance through the change history.
Your account data and drawings are stored in the European Union. Some providers are US-headquartered and may access data from outside Türkiye and the EEA for support and operational purposes. Those transfers rely on contractual safeguards — Standard Contractual Clauses under GDPR Article 46 and the corresponding uygun önlem under KVKK Article 9 — and never on a consent bundled into account creation. The transfer safeguard for each vendor is stated in the sub-processor list.
Beyond those processors, we disclose personal data only where a law, a court order or a lawful authority request obliges us to, or where it is necessary to establish, exercise or defend legal claims.
4. Collection method and legal basis
| Data | How it is collected | Legal basis |
|---|---|---|
| Email address, account, display name | Entered by you on the sign-in screen | Performance of a contract — KVKK Art. 5(2)(c), GDPR Art. 6(1)(b) |
| Session records, device label | Generated automatically when you sign in | Performance of a contract and legitimate interest in account security — KVKK Art. 5(2)(c) and 5(2)(f), GDPR Art. 6(1)(b) and 6(1)(f) |
| Sign-in IP address, lockout and rate-limit records, bot-protection signals | Collected automatically by the login endpoint and by the bot-protection widget on the sign-in screen | Legitimate interest in preventing abuse and account takeover — KVKK Art. 5(2)(f), GDPR Art. 6(1)(f) |
| Projects, drawing documents, embedded images | Created by you in the application and saved to the hosted service | Performance of a contract — KVKK Art. 5(2)(c), GDPR Art. 6(1)(b) |
| Error reports and performance samples | Sent automatically by the application when an error occurs, and as aggregate performance samples while you are using the editor | Legitimate interest in operating a reliable service — KVKK Art. 5(2)(f), GDPR Art. 6(1)(f) |
| Support messages and attachments | Sent by you, by email | Performance of a contract and legitimate interest in answering you — KVKK Art. 5(2)(c) and 5(2)(f), GDPR Art. 6(1)(b) and 6(1)(f) |
| Marketing opt-in (not currently operating) | A separate, unticked checkbox, if and when it is offered | Explicit consent — KVKK Art. 5(1) açık rıza, GDPR Art. 6(1)(a) |
| Records we must keep for legal reasons | Derived from the above | Legal obligation — KVKK Art. 5(2)(ç), GDPR Art. 6(1)(c) |
All collection happens through the application itself or by email. Drawoble does not buy personal data, does not enrich it from third-party sources, and does not track you across other websites.
5. Your rights as a data subject
Under KVKK Article 11, everyone whose personal data we process has the right to:
- learn whether their personal data is being processed;
- request information about it if it has been processed;
- learn the purpose of the processing and whether it is used accordingly;
- know the third parties, in Türkiye or abroad, to whom it has been transferred;
- request correction if it is incomplete or inaccurate;
- request its erasure or destruction under the conditions of KVKK Article 7;
- request that corrections and erasures are notified to the third parties the data was transferred to;
- object to a result reached solely through automated analysis that produces an adverse outcome for them;
- claim compensation for damage caused by unlawful processing.
Where the GDPR applies, the same requests are handled as access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21).
Drawoble does not carry out automated decision-making that produces legal effects or similarly significant effects on you.
Self-service, first
Signed in, you can already export all of your drawings, delete individual projects, and delete your entire account from the account area — no request or waiting period needed. Deleting your account is deliberately explicit and is never a side effect of anything else.
Making a request
For everything else, write to privacy@drawoble.com. We answer within 30 days, a single window that satisfies both KVKK Article 13 and GDPR Article 12(3). If a request is genuinely complex we may extend it as GDPR Article 12(3) allows, and we will tell you at the time we take the extension, not afterwards.
Before acting on a request we verify that it really comes from you, using the lightest check that works: normally a confirmation link sent to your registered email address. If that address is no longer reachable we ask for another proof tied to the account. We ask for identity documents only where there are documented signs of impersonation or fraud — never as a routine step.
If you believe we have handled your data unlawfully you may complain to the Turkish data protection authority (Kişisel Verileri Koruma Kurumu) or, in the EEA, to your local supervisory authority.
6. Retention and deletion
| What | How long |
|---|---|
| Account, projects and drawings | For as long as your account exists |
| Deleted project (in trash) | Recoverable for 30 days, then permanently purged |
| Deleted account | Access ends immediately; drawings, assets, exports and account rows are permanently purged by an automated nightly job |
| Generated export archives | Removed automatically 24 hours after they are created |
| Sign-in lockout and rate-limit records | Cleared once the address has been idle for about a day |
| Sessions | Expire at the latest 30 days after sign-in; individual access tokens last at most one hour and are refreshed |
| Error reports | The monitoring vendor's standard retention window |
| Support correspondence | Kept while the matter is open, plus the period we may need it as a record |
| Database backups | Scheduled backup copies age out on their own cycle; deleted data can persist in them until that cycle lapses |
When you delete your account we sign you out everywhere and refuse new sign-ins immediately. An access token already issued to your browser can remain technically valid for up to one hour, which is why we say access ends shortly rather than instantly. The automated purge then removes stored drawings, assets, generated exports and the account records themselves.
After the purge, the same email address can register again as a completely new, empty account.
7. What we store in your browser
Drawoble sets no cookies. The application never writes a cookie, and there is no advertising, analytics or cross-site tracking storage of any kind.
What the application does keep on your own device:
- Your session, held in the browser's session storage — which is cleared when you close the tab — unless you tick “remember this browser”, in which case it is held in local storage and still expires after 30 days.
- Preferences: theme, units, snapping, panel layout, shortcut overrides, recently opened files and similar editor settings.
- Crash-recovery drafts of documents you are working on, kept in the browser's local database so an unexpected reload does not lose your work.
Preferences and crash-recovery drafts stay on your device; they are not uploaded. Clearing your browser data removes all of it. Because none of this storage is used for advertising or measurement, there is currently no cookie banner to accept or reject. If Drawoble ever introduces non-essential storage, we will ask for your consent first, with rejection made as easy as acceptance, and this policy will be updated before it happens.
8. Support and break-glass access
Nobody at Drawoble browses your drawings. There is no routine-path access to customer content, and support does not start by opening your files.
Exceptional access exists — a solo-operated service cannot honestly claim otherwise — and it is governed by rules rather than by habit: it happens only when a specific support request or a live incident requires it, it is limited to what that request needs, it is time-bounded, and the reason is recorded. As the private beta hardens, these records move into an append-only audit trail; today they are kept as operator logs.
Infrastructure providers hold the technical ability to access stored data as part of operating their platforms; that access is governed by their own agreements, listed in the sub-processor list.
9. How we protect your data
- All traffic is encrypted in transit, and stored drawings and assets live in private buckets that are never publicly listable or readable.
- Database access is constrained by row-level security so an account can only reach its own rows, and upload permissions are cryptographically scoped to your own storage path.
- Sign-in has no password to steal: codes are single-use, short-lived, rate-limited and lockout-protected, and are additionally protected by a bot-detection challenge.
- Privileged server operations run through a small set of audited server-side functions rather than from the browser.
- The published Security Policy gives security researchers a clear reporting channel and safe-harbour terms.
No service can promise perfect security. If a personal-data breach occurs, we will notify the competent authority and affected users as KVKK and the GDPR require.
10. What we deliberately do not promise
- Instant erasure from backups. Active systems are purged on the schedule above; cold backup copies age out on their own cycle.
- End-to-end or zero-knowledge encryption. Drawoble does not claim it; claiming it would be false while the service stores, syncs and exports your documents.
- Portability of every log line. You can export your drawings and request your account data; we do not promise a machine-readable copy of every internal diagnostic trace.
- Uninterrupted availability. That is a service question, addressed in the Terms of Service, not a privacy promise.
11. Eligibility and children
Drawoble is a professional drafting tool intended for adults. It is not directed at children, and we do not knowingly create accounts for them. You must be old enough under the law of your country of residence to enter into the Terms of Service. If you believe a child has created an account, write to privacy@drawoble.com and we will remove it.
12. Changes to this policy
Each published version of this policy lives at a permanent address of the form
/legal/privacy/v1, /legal/privacy/v2, and so on. Published
versions are never deleted or rewritten in place, so the text you were shown remains
verifiable later. /legal/privacy always resolves to the current version.
- Corrections — typos, broken links, formatting — are fixed in place without a new version.
- Clarifications that do not change how we process data or what rights you have produce a new version and a change-history entry.
- Material changes — a new data class, a new processor, a new transfer, or any change to your rights — produce a new version, a change-history entry, and an email notice at least 30 days before the new version takes effect.
The full history is at /legal/privacy/changelog, with an RSS feed you can subscribe to.
13. Contact and governing text
Questions about this policy, and all data-rights requests, go to privacy@drawoble.com. Formal legal notices go to legal@drawoble.com.
This policy is governed by the laws of the Republic of Türkiye. It is published in Türkçe and English; where the two versions conflict, the Türkçe text prevails. Where this policy and the Terms of Service disagree on a privacy question, this policy controls.