What stays on your device
Unsigned drawings live only in the active editor tab unless you export them. Signed-in cloud save uses your SVG Lab account instead of browser-persistent storage. Concretely:
- Your unsigned drawings are not saved after refresh or close. Export the file or sign in for cloud save before leaving.
- Your editor preferences (such as colour swatches and magnetic snap) are kept in memory for the current tab only.
What we collect
To understand whether the editor is useful and to catch bugs, we send a small amount of anonymous usage data to a handful of privacy-respecting services. None of it includes the drawings you make.
- Cloudflare Web Analytics: cookieless page-view metrics: which page was visited, the referring URL, your country (not city or IP), browser family, and Core Web Vitals (how fast the page loaded for you). This is used to measure traffic and performance. Cloudflare's product specifically does not use cookies and does not fingerprint individual visitors. More info.
- PostHog: product analytics that capture page views, the page you came from, your country, your browser, and the time you arrived/left. SVG Lab configures PostHog with memory-only persistence, so analytics state is not kept across browser restarts by SVG Lab. PostHog session recording is disabled. If you sign in, we also record which site referred you and which page you landed on, so we can tell which channels bring people to SVG Lab. To carry that across the sign-in redirect we keep it in your browser's per-tab session storage, which your browser clears when you close the tab; it is never written to a cookie and never survives a browser restart. PostHog privacy policy.
- Sentry: receives a copy of any JavaScript error that the editor throws, plus the surrounding browser context (URL, browser version, the last few user actions in the app). This is how we find and fix bugs. Sentry privacy policy.
- Standard request data (your IP address, browser version, and the page you requested) is briefly seen by Cloudflare, our hosting provider, the same way every website on Cloudflare does. Cloudflare uses this for delivering the page and for DDoS protection.
- AI Generate: if you use the Pro-only AI Generate feature, the prompt text and/or reference image you submit is sent to a third-party AI provider to produce the generated SVG. This only happens when you click Generate; nothing is sent for the rest of the editor.
- Supabase: handles account authentication (signing in) and stores your account profile, cloud projects, and usage counters (like exports and auto-traces used this period) in its database. Supabase privacy policy.
- Paddle: our merchant of record for paid plans. If you subscribe or buy a top-up, Paddle processes your email address, payment details, billing address, and tax information under its own privacy policy; SVG Lab does not see or store your card details. Paddle privacy policy.
- In-app feedback: if you send feedback from the widget in the editor, the message is emailed to SVG Lab support along with any reply address you type. If you are signed in, we also send an acknowledgement to your account email. Feedback is not written to our database and is not sent to Sentry.
For metered Pro features (auto-trace, exports, and AI generations) we log a per-account usage event each time you use them: the timestamp, which feature was used, your IP address, and your browser's user-agent string. This is used to enforce plan quotas, prevent abuse, and, where needed, as evidence in payment disputes. These usage logs are kept for up to 24 months.
What we don't collect
- No traditional advertising cookies.
- No advertising pixels, no behavioural retargeting, no fingerprinting beyond the anonymous browser-session identifier described above.
- No cross-site tracking: the analytics above only see what happens on
svglab.app. - No copy of your drawings unless you are signed in and save a project to the cloud. Without an account, nothing you draw leaves your browser.
- No session replay or screen recording.
Opting out
If you'd rather not be counted at all, you have a few options:
- Turn on Do Not Track in your browser. Cloudflare Web Analytics honours it automatically.
- Use a privacy-focused browser extension like uBlock Origin or Privacy Badger to block the analytics endpoints. This is the most reliable option today.
SVG Lab does not yet offer an in-app switch to turn analytics off.
Accounts and cloud projects
Accounts are live. Signing in is optional: the editor is free and fully usable without one, and if you never sign in, your work stays in your browser and is not uploaded anywhere.
- If you sign in, we store your email address, your account ID, and any project you save to the cloud. A cloud project includes the drawing itself, not just its name.
- While you have a cloud project open, it is saved automatically about every five seconds so you do not lose work.
- Projects are stored in our Supabase database and scoped to your account. Other signed-in users cannot read your projects.
- Our internal admin tools show your account, plan, usage history, and a project's name, page count, and last-updated time. They do not display the contents of your drawings, except for MCP sessions recorded during early access, described below.
- Deleting a project deletes the stored copy. To delete the whole account, use Delete account under Settings on your Account page. That removes your projects, profile, and usage history permanently. If you have a paid plan, cancel it first so billing stops.
The SVG Lab MCP (connecting an AI app)
If you connect an AI app such as Claude, ChatGPT, Codex or Cursor to SVG Lab, that app sends requests to our MCP server to design in your account.
- What we receive: the requests the AI app makes (which tool it called and the details it sent, such as text, colours, sizes and image links), our replies, and the designs it creates in your projects. We do not receive your conversation with the AI app, your prompts to it, or anything else in that app, unless the AI app itself includes it in a request.
- How you connect: you sign in to SVG Lab and approve the connection. The AI app receives a token, never your password. You can disconnect an app, or revoke an MCP key, at any time from the MCP panel in the editor.
- Every request: we log the time, the tool used, whether it succeeded, how long it took, which AI app sent it and your country, to run the service, enforce limits and prevent abuse.
- Your usage history: for each request we also keep, in your account, the time, the tool, which allowance paid for it (your plan, the free trial or a top-up), whether it worked, and the name of the project it worked in, so you can see your own usage in the editor and on the MCP usage page. Only you can see it there. It holds no request details and no designs, and it is deleted automatically after 90 days.
- Session review is off: until 26 September 2026, during early access, we also reviewed MCP sessions, meaning the requests above with their details and the designs they produced, to find where the MCP fell short and improve it. That review stopped when the SVG Lab MCP became part of the Plus and Max plans on 26 September 2026, and new sessions are not recorded for it. Sessions recorded during early access are seen only by the SVG Lab team and are deleted automatically 60 days after they were recorded. We do not use this material to train AI models or share it with anyone else.
- Images you ask the MCP to place from a web link are fetched by our server and saved into your project like any other image. Photo searches go to Unsplash or Pexels, which see the search words but not who you are.
Third-party services we use
- Cloudflare hosts the site, provides DNS, the CDN, DDoS protection, and the cookieless analytics described above. Their privacy policy is at cloudflare.com/privacypolicy.
- PostHog provides the product-analytics described above. We use the EU/US Cloud service. Their privacy policy is at posthog.com/privacy.
- Sentry provides the error-monitoring described above. Their privacy policy is at sentry.io/privacy.
- A third-party AI provider processes the AI Generate requests described above.
- Supabase provides account authentication and stores account, project, and usage-counter data as described above. Their privacy policy is at supabase.com/privacy.
- Paddle is the merchant of record for paid plans and processes payment, billing, and tax data as described above. Their privacy policy is at paddle.com/legal/privacy.
Your rights
If you're signed in, your account profile, cloud projects, and billing details are stored with Supabase and Paddle as described above, and you can review most of it directly in the app: Account for your profile, My Projects for saved projects, and Billing for your subscription and usage. You can delete the account yourself with Delete account under Settings on the Account page. For anything else, such as correcting or exporting your data, email support@svglab.app. If you've never signed in, clearing your browser's site data for svglab.app removes everything SVG Lab put there locally.
Children
SVG Lab is a general-purpose creative tool with no targeted features for children, no advertising, and no data collection. It's safe for any age.
Changes to this policy
If we change what's collected, this page will be updated and the date at the top will be revised. Significant changes will also be flagged in the editor itself.
Contact
Questions? Reach the maintainer through the project's GitHub repository or the in-app feedback widget once it ships.