Draw+ for Windows — Security Overview

Last updated: August 29, 2026

This page explains how Draw+ for Windows keeps your data and account safe.

1. The short version

  • Your design files stay on your computer by default — uploading is something you choose, file by file.
  • We never see your password or your credit card details.
  • By default the assistant is a rule-based interpreter running on your PC, not a generative AI model — nothing is sent to the internet. Generative AI is cloud-only and stays off until you turn it on.
  • We only store the bare minimum needed to verify your subscription.

2. Your design files stay on your PC by default

Everything you create in Draw+ — diagrams, models, requirements, project files — is saved as files on your own Windows computer. That is the default path, and it is complete on its own: if your computer is off the internet, your files are still completely private.

If you sign in, you may additionally choose to save a project to your own account so you can open it on another PC. That is always an explicit action you take on a specific project — there is no background syncing, and nothing is uploaded automatically. Projects saved this way live only under your own account: there is no shared workspace, no sharing feature, no public link, and no other user can reach them. You can list, download and delete them at any time while signed in.

3. We don't handle your password

Sign-in is handled entirely by Google's Firebase Authentication service — a platform trusted by millions of apps worldwide. When you create an account or sign in, your password goes directly to Google. Draw+ never receives it, never stores it, and never even sees it. If Google's sign-in is good enough for Gmail, it's good enough for Draw+.

4. We don't handle your credit card

Payments are processed by Stripe — one of the most widely used payment platforms in the world. When you subscribe, you enter your card details on Stripe's own secure payment page. That information goes directly from your browser to Stripe. Draw+ never receives your card number, expiry date, or security code. We only receive a confirmation that tells us your subscription is active.

5. The assistant doesn't send your data anywhere by default

By default, the Co-Pilot commands are handled by a rule-based interpreter built into the app, running directly on your Windows PC. When you ask it to generate a diagram or explain a model, it works through fixed rules locally — like a calculator, everything happens inside your computer. It is not a generative AI model, and Draw+ labels its output as not AI-generated so you always know which engine you are reading. Nothing you type into the prompt box is sent to the internet by default.

Generative AI is provided only through the optional Cloud AI mode, which is off unless you turn it on yourself. Because a cloud model has to see the design to reason about it, turning it on means both your prompt and the model you are currently working on are sent to an external Cloud AI service. We say so plainly in a consent dialog the first time you use it, and you can switch it back off at any time from the AI menu — after which the assistant returns to the built-in rule-based interpreter, running entirely on your PC. Cloud AI is also capped at 20 requests per day per user.

6. We collect as little as possible

To run the service, we need to know two things: who you are (so you can sign in) and whether your subscription is active (so the save feature works). That's it. Here's a simple breakdown:

Type of dataDo we store it?
Your design files and diagramsNo by default — stays on your computer, unless you explicitly save a project to your own account
Your passwordNo — handled by Google
Your credit card detailsNo — handled by Stripe
Prompts you type (Cloud AI off — the default)No — handled by the offline rule-based interpreter on your PC
Your email addressYes — so you can sign in
Your subscription statusYes — so the save feature works

7. Your account is protected

We've taken steps to make sure one person can never access another person's subscription. When we check your subscription, we verify that the account belongs specifically to you — not just that an email address matches. This means even if someone knows your email address, they cannot unlock your subscription on their own account.

When you sign out, any login information stored temporarily on your device is cleared.

8. Usage data is opt-in

Draw+ does not collect usage statistics or diagnostic data by default. If you want to help us improve the app by sharing anonymous usage information, you can turn that on in Settings at any time. You can also turn it off. In fully offline or air-gapped environments, this feature can be permanently disabled.

9. Payments are handled safely

When Stripe tells us about a payment or subscription change, we verify that the notification is genuinely from Stripe before acting on it. This prevents anyone from faking a "payment received" message to unlock features they haven't paid for.

10. We keep our systems up to date

Our server software is regularly reviewed and updated to address known security issues. As of June 2026, our latest review found no outstanding vulnerabilities. We also deleted any old administrative tools that were no longer needed, to reduce the risk of them being misused.

11. Who we rely on

We use two well-known, established companies to handle the most sensitive parts of our service:

  • Google (Firebase Authentication) — manages sign-in and account security.
  • Stripe — manages payments and subscription billing.

Both companies are subject to independent security audits and comply with international data-protection standards. You can read their privacy policies on their respective websites.

12. If you find a security issue

If you believe you've found a security problem in Draw+ for Windows, please let us know privately before telling anyone else. We'll investigate promptly and work to fix it as quickly as possible.


For more details on how we handle your personal information, see our Privacy Policy.