Skip to content

Trust & security

Your work stays yours

Draw is built local-first, so privacy isn't a setting — it's the default.

Local-first by design

Your drawings live on your device, saved in your browser. Nothing is sent to a server unless you explicitly export or share.

No account, no tracking

The editor needs no sign-up and ships no analytics or telemetry. There is no hidden data collection.

Encrypted in transit

The app and any online feature you use, like share links, are served strictly over HTTPS.

Open and auditable

A small, transparent surface area you can reason about — and verify for yourself.

How your data is handled

Where your work is stored

Drawings are saved locally in your browser (IndexedDB) and, when you choose, to a file on your disk. They are never uploaded automatically.

Share links carry their own data

A view-only share link encodes the drawing into the link itself — no server stores or sees your scene to generate it.

Embedded content is sandboxed

When you embed a web page or video, it runs in an isolated sandboxed frame with no access to the app or your data.

Links are sanitized

Hyperlinks you add or import are validated, and unsafe schemes (such as javascript: and data:) are blocked before they can ever open.

No third-party calls

Fonts and assets are self-hosted, so loading the app makes no requests to third-party CDNs or font services — nothing to leak your activity.

Strict content policy

A Content-Security-Policy constrains what the app is allowed to load and execute, reducing the blast radius of any injected content.

Cloud features & what changes

Cloud sync and accounts are not part of the app today. When they launch they will be an opt-in, paid layer — the free editor stays local-first and account-free. We'll publish the sub-processors and data practices for those services here before they go live.

Found a vulnerability?

We appreciate responsible disclosure. Email security@draw.app or use our contact page, and we'll respond promptly.

Placeholder — Replace security@draw.app with your real disclosure address, and list your sub-processors once cloud features ship.