Legal
Privacy
Eskiz is a place to make things. What you make, and what you tell us, stays yours. This page says what we collect, why, who helps us run Eskiz, and how to take it all back.
Last updated 30 September 2026
1. Who we are
Eskiz.ai (“Eskiz”, “we”) runs eskiz.ai and the Eskiz app. For the personal data described on this page, we are the controller: we decide why and how it is used.
When a company or a team uses Eskiz, the work in its workspace belongs to that organisation. For that content we act on the organisation’s behalf and follow its instructions. If your workspace is run by an organisation, its own policies may apply too.
2. What we collect
If you join the waitlist
Your email address, and when you joined. We use it for one thing: to write to you when Eskiz opens. Nothing before, and nothing else.
When you create an account
- Your email address and your name.
- How you sign in: with a password, or with Google or GitHub. Your password is checked by our identity provider and never stored by us; we never see your Google or GitHub password at all.
- Your active sessions, so you can review them and end any of them.
- If you turn on two-step verification, the factor is held by our identity provider.
Workspaces and teams
A workspace’s name, its members and their roles, and the invitations sent from it. An invited address is stored encrypted until the invitation is accepted or ends.
Your work
The projects and canvases you create: their names, their content (sketches, models, parameters, drawings) and what you export from them. While Eskiz is in early access, your canvases are stored in your browser, on your device. When you save one to a workspace — to share it with your team, for example — it is stored on our servers too, so the people you have shared it with can open it.
Billing
For paid plans: the plan, the billing contact address, invoices and payment status. Payments are processed by Stripe; we never see or store your full card number.
Records that keep Eskiz working and secure
- Security records of sign-ins and of sensitive actions, such as changing someone’s role or deleting a workspace. They protect your account and give workspace owners an audit trail.
- Error reports when something breaks. They exclude the content of your work and any password or token.
- Usage counts for metered features, such as the AI assistant, so they can be limited and billed.
A record of how people find and use Eskiz
A short history of milestones in your relationship with Eskiz: that you joined the waitlist, created an account, or created a workspace or a project. It is tied to your account, and it never contains the names or the content of your work. We use it to understand what brings people to Eskiz and what they do next, so we can decide what to build. You can object to it at any time (see Your rights).
What stays on your device
Your preferences (theme, shortcuts, how you move around a model), a local copy of your work, and signals about how you are using Eskiz — for example, that the same step was undone several times in a row — so Eskiz can offer help at the right moment. These stay in your browser. We don’t receive them unless a future setting asks you, and you say yes.
3. How we use it, and why we are allowed to
The legal bases named here are those of the EU and UK GDPR; the same purposes apply wherever you are.
| Purpose | Data | Legal basis |
|---|---|---|
| Run Eskiz for you | Account, workspaces, your work, sessions | Our contract with you |
| Keep it secure | Security records, sign-in data, automated bot protection | Legitimate interests: safe accounts and a safe service |
| Billing and tax | Billing data | Contract; legal obligation |
| Service email | Your address, for sign-in codes, security alerts, invoices and invitations | Contract |
| News about Eskiz | Your address | Consent, only if you ask for it; unsubscribe any time |
| Make Eskiz better | The milestone record, error reports | Legitimate interests; you can object |
| AI features | Your request and the context it needs | Contract, only when you use them |
4. What we don’t do
- Sell or rent personal data.
- Show ads, or use advertising or analytics trackers from other companies.
- Use your content — drawings, models, parameters, prompts — to train AI models, ours or anyone else’s.
- Look at your work, unless you ask us to (to help with a problem, for example), the law requires it, or we must investigate a serious breach of our Terms.
5. AI features
When you use an AI feature, we send your request, and the part of your work it needs, to an AI model provider to produce an answer. We only use providers whose terms don’t allow them to train on it and that keep it no longer than they need to prevent abuse. AI answers can be wrong: see the Terms.
6. Who helps us
A few companies run parts of Eskiz for us. Each works under a written agreement that limits it to the service it provides.
| Provider | What they do | What they handle |
|---|---|---|
| WorkOS | Sign-in, identity, two-step verification | Name, email, sign-in events |
| Stripe | Payments | Billing details, payment method |
| Vercel | Hosts eskiz.ai and keeps the waitlist | Waitlist addresses, website requests |
| Resend | Sends email | Your address and the message |
| Cloud hosting | Runs the Eskiz app and its databases | What section 2 says is stored on our servers |
| AI model providers | Answer AI requests, only when you use them | Your request and the context it needs |
| Error reporting | Crash and error reports | Technical details, never your work |
Before accounts open to the public, every provider on this list will be named, and the list kept current.
8. How long we keep it
- Your account: for as long as you have it.
- When you delete your account: access closes at once. After a 14-day grace period, in which you can change your mind, your profile, sessions and sign-in identity are deleted, and the milestone record is kept only in a form that names nobody.
- Records the law or security requires: invoices and payment records, for as long as tax and accounting law requires; evidence that a deletion or a sensitive change took place, kept without your name wherever possible.
- Team workspaces: work in a team’s workspace belongs to that workspace, and is deleted with it.
- The waitlist: until we have written to you when Eskiz opens, or sooner if you ask.
- On your device: until you clear it or sign out.
9. Your rights
Wherever you live, you can ask us to:
- show you the personal data we hold about you, and give you a copy;
- correct it;
- delete it;
- give it to you in a portable format;
- stop or limit a use of it, or withdraw a consent you gave.
Many of these are in the app already: edit your profile, end sessions, or delete your account from your account settings. For anything else, contact us and we will answer within one month.
In the EU, the EEA, the UK and Switzerland these rights come from data protection law, and you may also complain to your local data protection authority. If you live in California, we do not sell or share personal information, as those words are used in the CCPA.
10. Where your data is processed
The providers above may process data outside your country, including in the United States. When data leaves the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (with the UK addendum) or another lawful transfer mechanism.
11. Keeping it safe
Everything travels encrypted, and our providers encrypt it at rest. Each workspace’s data is kept apart at the database level, two-step verification is available for every account, and access is limited to the people who need it to run Eskiz. No system is perfectly secure: if a breach affects your data, we will tell you promptly, and say what we are doing about it.
12. Children
Eskiz is not for anyone under 16.
13. Changes
We will post any change here with a new date. If a change matters, we will tell you by email or in the app before it takes effect.
14. Contact
Eskiz is not open to the public yet. Before it opens, this section will give the address to write to about your data or this policy.