Back to home

Privacy Notice

Exact data practices for excalimate.com and app.excalimate.com

Last updated: 12 July 2026

Controller and scope

excalimate, the owner of theexcalimate/excalimate repository, is the controller for the processing described here. This notice covers the public landing site, the browser application, aggregate service analytics, and the optional encrypted-sharing service.

Privacy questions and rights requests can be raised throughGitHub Discussions. Discussions are public, so do not include sensitive or identifying information in the initial post.

Important distinction

Excalimate does not run consentless client-side product analytics. Cloudflare necessarily processes IP addresses and HTTP metadata to deliver and secure the service and provides aggregate edge traffic reports. Optional PostHog product analytics is separate, pseudonymous rather than legally anonymous, and starts only after consent.

Exact processing inventory

The entries below are generated from the same inventory that restricts application analytics. Adding a new PostHog event requires adding it to this public list.

Service delivery and security

Every request
Exact data
Source IP address, requested host/path, HTTP method and headers, timestamp, response status, and transfer size are processed by Cloudflare to deliver and secure the service.
Purpose
Deliver pages and app assets, prevent abuse, and maintain availability.
Legal basis
Legitimate interests in operating a secure and reliable service.
Recipient
Cloudflare, acting primarily as hosting/CDN processor.
Retention
Cloudflare service-log retention follows the contracted service settings; Excalimate does not export these logs for analytics.

Aggregate traffic statistics

Every request; no client analytics beacon
Exact data
Aggregate request counts, bandwidth, HTTP status/error counts, cache performance, and country-level traffic. Excalimate does not use IP-derived unique-visitor counts as anonymous analytics.
Purpose
Capacity planning, reliability monitoring, and service improvement.
Legal basis
Legitimate interests; retained reports no longer identify a visitor.
Recipient
Cloudflare edge/zone analytics.
Retention
Raw or exported reports: up to 30 days. Non-identifying aggregate trend reports: indefinitely.

Optional product analytics

Only after analytics consent
Exact data
Only the events and bounded properties listed in the event catalogue, plus a random in-memory session identifier, event timestamp, SDK name/version, and transient network metadata.
Purpose
Understand feature use and prioritize product improvements.
Legal basis
Consent.
Recipient
PostHog Cloud EU as processor. IP capture must be disabled in project settings.
Retention
Up to 12 months.

GitHub repository star count

When the app toolbar loads
Exact data
GitHub receives ordinary request network metadata such as IP address, User-Agent, and Origin. Excalimate requests only public repository metadata.
Purpose
Display the public repository star count.
Legal basis
Legitimate interests, subject to the documented ePrivacy assessment.
Recipient
GitHub.
Retention
Determined by GitHub for its network logs. A local one-hour cache is used only with preference-storage consent.

Public feedback portal

When a visitor opens feedback details, submits feedback, comments, or votes
Exact data
Submitted title, description, category, optional display name (or "Anonymous"), comment text, vote state, GitHub issue/comment numbers and timestamps, a random feedback-cookie UUID, and HMAC-derived author/vote tokens. Submitted text and display names are public. GitHub receives only the derived tokens, not the raw cookie UUID.
Purpose
Publish requested product feedback, attribute the chosen display name, show vote state, and prevent duplicate votes.
Legal basis
Performance of the requested feedback service and legitimate interests in operating a public product-feedback channel.
Recipient
Cloudflare Worker and GitHub as the public feedback repository host.
Retention
Public submissions, comments, and derived tokens remain until the corresponding GitHub issue or comment is deleted. The feedback identity cookie expires after one year.

Feedback abuse prevention

When the feedback API handles a request
Exact data
IP address used as a rate-limit key, request origin and headers, Turnstile response token, and a random verification idempotency UUID. The token and IP address are sent to Cloudflare Turnstile; Excalimate does not place them in an application database.
Purpose
Prevent automated abuse, forged requests, spam, and excessive submissions.
Legal basis
Legitimate interests in protecting the service and public feedback channel.
Recipient
Cloudflare Workers rate limiting and Cloudflare Turnstile.
Retention
Transient request and rate-limit processing; Cloudflare service logs follow the contracted service settings.

dotLottie runtime

When the landing home page loads its animation examples
Exact data
unpkg/Cloudflare receives ordinary resource-request metadata such as IP address, User-Agent, requested pinned asset, and Origin. Referrer transmission is disabled.
Purpose
Render the animation examples on the landing site.
Legal basis
Legitimate interests, subject to the documented ePrivacy assessment.
Recipient
unpkg, delivered through Cloudflare.
Retention
Determined by the recipient for its network logs.

Encrypted project sharing

Only when the user selects Share
Exact data
An end-to-end encrypted project blob, random share ID, content length/type, and expiry timestamp. The encryption key remains in the URL hash and is not sent to the server.
Purpose
Provide a user-requested share link.
Legal basis
Performance of the requested service.
Recipient
Cloudflare Worker and R2.
Retention
Up to 30 days.

MCP live connection

Only when the user connects
Exact data
The configured MCP endpoint receives the live-mode requests and scene updates needed for that connection.
Purpose
Provide the user-requested MCP live workflow.
Legal basis
Performance of the requested service.
Recipient
The MCP endpoint selected by the user.
Retention
Controlled by that endpoint; Excalimate does not centrally store the connection contents.

Optional PostHog event catalogue

These events are sent only after an affirmative analytics choice. The SDK allowlist discards undeclared events and properties before transmission.

EventPurposeAllowed custom properties
animation_exportedAnimation exportedUnderstand which export formats need the most support.
  • format: One of: mp4, webm, gif, svg, lottie, dotlottie.
project_sharedProject sharedMeasure use of encrypted sharing.None
project_createdProject createdUnderstand common canvas formats.
  • aspect_ratio: One of: 16:9, 4:3, 1:1, 3:2.
project_savedProject savedMeasure use of local project saving.None
project_loadedProject loadedUnderstand how projects are reopened.
  • source: One of: file, checkpoint, share_url.
excalidraw_importedExcalidraw importedMeasure import workflows.
  • source: One of: file, url.
mode_switchedEditor mode switchedUnderstand use of editing and animation modes.
  • mode: One of: edit, animate.
playback_actionPlayback actionImprove animation-preview controls.
  • action: One of: play, pause, stop.
keyframe_actionKeyframe actionImprove keyframe editing.
  • action: One of: add, move, delete, update.
track_actionTimeline track actionImprove timeline-track controls.
  • action: One of: add, remove, toggle.
sequence_actionSequence actionImprove sequence-reveal workflows.
  • action: One of: create, update, delete.
camera_actionCamera actionImprove camera framing controls.
  • action: One of: change_aspect_ratio, fit_to_scene.
  • ratio: For aspect-ratio changes only; one of: 16:9, 4:3, 1:1, 3:2.
theme_toggledTheme changedUnderstand light and dark theme use.
  • theme: One of: light, dark.
group_actionGrouping actionImprove grouping workflows without recording project contents.
  • action: One of: group, ungroup.
  • element_count_bucket: One of: 1, 2-5, 6-20, 21+.
mcp_actionMCP actionImprove optional MCP live-mode setup.
  • action: One of: connect, disconnect, set_url.
creator_workspace_changedCreator workspace changedUnderstand use of the progressive Magic, Sequence, and Studio workspaces.
  • workspace: One of: magic, sequence, studio.
  • source: One of: switcher, escalation, project-load, query.
creator_project_startedCreator project startedImprove the paths used to begin a project.
  • path: One of: draw, import-excalidraw, open-project, mcp, template.
creator_template_galleryTemplate gallery actionImprove template discovery without recording search text.
  • action: One of: open, search, category.
  • category: A fixed public template category or all.
creator_template_usedTemplate usedUnderstand which public template categories and formats are useful.
  • category: A fixed public template category.
  • aspect_ratio: One of: 16:9, 4:3, 1:1, 3:2.
creator_scene_state_capturedScene state capturedImprove Smart Transition setup for different diagram sizes.
  • element_count_bucket: One of: 0, 1-10, 11-100, 101-1000, 1001+.
creator_smart_transition_previewedSmart Transition previewedImprove local transition matching and preview guidance.
  • change_count_bucket: One of: 0, 1-10, 11-100, 101-1000, 1001+.
  • ambiguous_mapping_count_bucket: One of: 0, 1, 2-5, 6+.
  • camera_included: Whether the preview included a camera transition.
creator_smart_transition_decidedSmart Transition decisionMeasure whether local transition suggestions are useful.
  • decision: One of: accepted, rejected.
  • ambiguous_mapping_count_bucket: One of: 0, 1, 2-5, 6+.
creator_smart_transition_escalatedSmart Transition escalatedUnderstand when creators need more transition control.
  • action: One of: customized, open-studio.
creator_auto_animate_previewedAuto Animate previewedImprove deterministic local animation suggestions.
  • scope: One of: selection, diagram.
  • strategy: A fixed local Auto Animate strategy.
  • confidence_band: A bounded confidence category.
  • target_count: The number of animation targets.
creator_auto_animate_appliedAuto Animate appliedMeasure whether deterministic local animation suggestions are useful.
  • scope: One of: selection, diagram.
  • strategy: A fixed local Auto Animate strategy.
  • confidence_band: A bounded confidence category.
  • recipe_count: The number of generated animation recipes.
creator_auto_animate_rejectedAuto Animate rejectedImprove deterministic local animation suggestions.
  • scope: One of: selection, diagram.
  • strategy: A fixed local Auto Animate strategy.
  • confidence_band: A bounded confidence category.
creator_preset_appliedAnimation preset appliedUnderstand which local animation presets and controls are useful.
  • preset: One of: fade, slide, draw, pop.
  • direction: For directional presets only; one of: left, right, up, down.
  • selection_size: The number of selected targets.
  • speed_band: One of: slow, normal, fast.
creator_first_previewFirst creator previewImprove the path from editing to the first animation preview.
  • workspace: One of: magic, sequence, studio.
  • reduced_motion: Whether reduced-motion preference was active.
creator_escalatedCreator controls escalatedUnderstand when creators move to more advanced controls.
  • destination: One of: sequence, studio.
creator_sequence_openedSequence workspace openedImprove animation-order and timing workflows.
  • action_count: The number of sequence actions.
  • custom_count: The number of customized sequence actions.
creator_sequence_action_reorderedSequence action reorderedImprove accessible animation-order controls.
  • source: One of: drag, keyboard.
creator_sequence_timing_changedSequence timing changedImprove sequence timing controls.
  • scope: One of: single, bulk.
  • start_mode: One of: absolute, afterPrevious, withPrevious.
  • speed_band: One of: fast, normal, slow, custom.
creator_sequence_actions_groupedSequence actions groupedImprove simultaneous animation workflows.
  • action_count: The number of grouped sequence actions.
creator_sequence_customized_opened_in_studioCustomized sequence opened in StudioImprove handoff from Sequence to advanced timeline editing.
  • status: One of: customized, detached, unmanaged.
creator_sequence_bulk_actionSequence bulk actionImprove multi-action sequence editing.
  • action: One of: enable, disable, delete, timing.
  • action_count: The number of affected sequence actions.
landing_page_viewedLanding page viewedUnderstand which public documentation sections are useful.
  • page: A fixed public page category; never a full URL, query string, or hash.
landing_external_link_clickedLanding external link selectedUnderstand which public resources visitors choose to open.
  • destination: A fixed destination category; never link text or a full URL.

PostHog also attaches only these technical fields:distinct_id, $session_id, $window_id, $lib, $lib_version, $process_person_profile.The random identifiers exist only in memory for the current page session. PostHog also receives the event timestamp, event UUID, SDK transport request, and therefore transient network metadata. PostHog project settings must keep IP capture disabled.

Browser storage

Local project data remains on your device unless you explicitly use encrypted sharing. Optional preference keys are written only after preference-storage consent.

KeyExact contentsPurposeCategory
excalimate-analytics-consentVersioned analytics and preference choices with a decision timestamp.Remember privacy choices.Required
excalimate_feedback_idA random UUID and HMAC signature in a Secure, HttpOnly, SameSite=Lax cookie with a one-year expiry.Remember feedback authorship and vote state and prevent duplicate votes.Required only for feedback features
excalidraw-animate-autosaveThe current project and animation timeline.Recover the locally edited project.Required local app data
excalidraw-animate-recentUp to ten recent local projects.Show the user their recent projects.Required local app data
excalimate-themelight or dark.Remember the selected theme.Optional preference
excalimate-mcp-urlThe MCP endpoint entered by the user.Remember the optional live-mode endpoint.Optional preference
excalimate-gh-starsPublic GitHub star count and one-hour cache timestamp.Avoid repeated GitHub API requests.Optional preference

Rejecting or withdrawing optional choices removes PostHog persistence and optional preference keys. Required local project/autosave data can be removed by clearing this site's storage in your browser.

Data excluded from analytics

  • Names, email addresses, account identifiers, or advertising identifiers
  • Diagram/project text, shapes, files, names, or encryption keys
  • Full URLs, query strings, URL hashes, or referrers
  • Typed input, clipboard contents, screenshots, or session replay
  • Precise location, cross-site activity, or device fingerprints

Excalimate does not sell analytics data, run advertising analytics, create marketing profiles, or use analytics for cross-site tracking.

Consent and objection controls

Optional PostHog analytics and optional preference storage are off until selected. You can withdraw either choice at any time through Privacy and data in the app toolbar or Privacy choices in the landing-page footer. Withdrawal does not affect processing that occurred while consent was valid.

Service delivery, security, reliability, and aggregate Cloudflare reporting rely on legitimate interests under Article 6(1)(f) GDPR. You may object to legitimate-interest processing. Some network processing is required to provide a site you request; if an aggregate report can no longer be linked to a person, it cannot be located or deleted as an individual record.

The automatic GitHub star-count and pinned unpkg runtime requests are not categorized as analytics, but GitHub and unpkg/Cloudflare receive ordinary network metadata before an analytics choice. Excalimate relies on legitimate interests for these limited requests and assesses ePrivacy requirements separately.

Processors, recipients, and transfers

  • Cloudflare provides CDN, security, hosting, Workers, R2, Turnstile, rate limiting, and aggregate traffic analytics. Its global network may process data outside your country under its data-processing terms and transfer safeguards.
  • PostHog Cloud EU processes optional analytics as a processor. Excalimate requires an up-to-date DPA, subprocessor review, EU project region, disabled IP capture, and a 12-month retention ceiling.
  • GitHub receives the public repository metadata request and hosts public feedback submissions, comments, display names, and derived vote/authorship tokens. It may act as an independent recipient for public content and service logs.
  • unpkg/Cloudflare delivers the pinned dotLottie runtime and receives the ordinary resource-request metadata described above.

Current provider terms, subprocessors, adequacy decisions, and contractual safeguards are reviewed as part of release operations. Links:Cloudflare privacy,PostHog privacy, andGitHub privacy.

Public feedback

Feedback titles, descriptions, categories, comments, and the display name you choose are published in the Excalimate GitHub repository. Do not submit confidential, sensitive, or third-party personal data. A signed, one-year feedback identifier is used only for authorship and vote state; GitHub receives derived HMAC tokens rather than the raw identifier.

Cloudflare rate limiting and Turnstile process the request IP address and verification token to protect the portal from abuse. Excalimate does not place those security values in a separate application database.

Encrypted sharing and MCP

Sharing is user-triggered. Encryption happens in your browser; only the encrypted blob, random share ID, object metadata, and expiry are sent to Cloudflare. The decryption key is placed after # in the share URL, which browsers do not send in the HTTP request. Shared blobs expire after 30 days.

MCP live mode connects only when requested. The selected MCP endpoint receives the requests and scene updates needed for that connection. If you configure a third-party MCP endpoint, its operator controls its own processing and retention.

Your EEA and UK rights

Depending on the processing, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent at any time. You also have the right to complain to your local data-protection authority; UK users can contact theInformation Commissioner's Office.

Excalimate may need enough information to verify and fulfill a request. Do not publish sensitive verification material in a public GitHub Discussion.

Changes to this notice

Material changes to optional analytics invalidate the stored consent version and present the choices again. The updated date on this page records notice revisions.