Privacy
Your work starts local
Subpath is designed so you can edit SVGs without creating an account. Local documents and desktop files remain on your device unless you choose a connected feature. This policy explains what leaves your device when you do, and who processes it. Subpath is operated by Griffen Fargo.
Local editing
Browser documents are stored in your browser. Desktop documents and recovery data are stored on your computer. Opening, editing, and exporting local SVG files does not upload their contents to the cloud.
Sharing works one of two ways depending on the link you create. A compressed share link encodes the whole document into the URL itself, so the artwork travels inside the link you send and never reaches our servers. A short share link instead uploads a snapshot of that document so the short URL can resolve to it later — choosing a short link is a deliberate upload of that document's contents.
What we collect
- Account details. If you sign in, we store your email address and an account identifier. Authentication runs on Supabase.
- Cloud documents. If you enable cloud sync, the documents you sync — their contents, titles, and version history — are stored so they can be returned to you on other devices.
- Shared snapshots. If you create a short share link, the document snapshot behind it is stored so the link resolves. This works without an account, and your IP address is used briefly to rate-limit link creation.
- Billing records. Plan tier, subscription status, and the customer identifiers needed to reconcile your subscription. Stripe processes payments and card details directly; we never receive your full card number.
- AI requests. The prompt and generation settings you submit, plus the credits the request consumed.
- Product analytics. Usage events describing which features you use, described in its own section below.
Features that use hosted services
- Signing in and cloud document sync use Supabase.
- AI generation sends the prompt and generation settings you submit to the hosted app and, through the Vercel AI Gateway, to the model provider configured for that request — currently models hosted by OpenAI and Anthropic. Your prompt is sent to fulfil your request; we do not use your prompts or artwork to train models.
- Paid-plan checkout and account billing are handled by Stripe when enabled.
- The app is hosted on Vercel, which processes request logs on our behalf.
- Release notes, documentation, and issue reporting may open GitHub.
These features are optional. The editor continues to support local work without them, although network-backed actions are unavailable while offline.
Analytics
We use Vercel Analytics to understand which features get used. To distinguish repeat visits from new ones, the app stores a randomly generated visitor identifier in your browser's local storage and a session identifier in session storage. These are random values, not derived from anything about you, and they are not linked to your account.
Analytics events record actions such as opening a dialog, running an export, or completing an AI generation. Two of these carry text you wrote: the prompt you submit for an AI generation is included in truncated form (first 500 characters), as are error messages when a generation fails. Nothing else you type and no document contents are sent to analytics.
You can prevent analytics entirely by blocking the script in your browser or using the desktop app offline. Clearing site data removes the stored identifiers.
Cookies and browser storage
We do not use advertising or cross-site tracking cookies. The app sets a subpath-welcome-seen cookie so the welcome dialog stops reappearing, and Supabase sets session cookies once you sign in. Everything else — your documents, editor preferences, autosave state, and the analytics identifiers above — lives in your browser's local storage rather than in cookies.
How long we keep things
- Deleted cloud documents remain recoverable from trash for 30 days, then are removed automatically.
- Version history is retained for 30 days on Cloud and 90 days on Premium.
- Account and cloud document data is kept while your account is open, and removed when you delete it.
- Billing records are retained as long as tax and accounting obligations require, even after an account closes.
Your choices and rights
You can export any document to a local file at any time, and you can delete your account and its cloud data yourself from account settings. Deleting a cloud account does not touch documents stored locally on your devices.
Depending on where you live, you may have rights to access, correct, export, or erase the personal data we hold, and to object to certain processing. Contact us and we will action the request; we will not charge you for it or treat you differently for asking.
Children
Subpath is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.
Diagnostics and feedback
The desktop app only copies diagnostics when you choose that command. Review the copied text before including it in a support request. Feedback you submit may include the text and contact details you choose to provide.
Changes to this policy
This page describes current beta behavior and will be updated as connected services change. The revision date below always reflects the current version.
Questions or deletion requests
For privacy questions or requests concerning cloud account data, reach us through our support channel. Do not include private document contents or credentials in a public report.
support@subpath.devLast updated August 18, 2026. See also our Terms of Service.
Back to editor