The approved legal text is provided in English.
Privacy Policy
Effective date: 2026-10-09
This Privacy Policy explains how Jittapol Prukpatarakul (จิตรพล พฤกษ์ภัทรกุล) (“VerSketch,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use versketch.xyz and related VerSketch services (the “Service”).
1. Data Controller
The controller responsible for the processing described in this Policy is:
- Legal name: Jittapol Prukpatarakul (จิตรพล พฤกษ์ภัทรกุล)
- Registration details: Operated by an individual resident in Thailand. Not registered as a separate juristic entity (company or partnership).
- Address: 133 Moo 8, Ban Na Yao, Thung Samo Subdistrict, Khao Kho District, Phetchabun Province 67270, Thailand
- Privacy contact: privacy@versketch.xyz
- Data Protection Officer, if applicable: Not appointed. VerSketch has not appointed a Data Protection Officer; privacy requests are handled directly by the operator at privacy@versketch.xyz.
- EU representative, if applicable: Not appointed. VerSketch is operated from Thailand and has not appointed a representative in the European Union or the United Kingdom. Users there may contact privacy@versketch.xyz directly.
2. Scope
This Policy applies to the VerSketch website, editor, cloud project storage, AI-assisted conversion features, read-only sharing, billing integration, and support services.
AIVerID, Stripe, and other third-party services have their own privacy notices for processing they perform independently.
3. Personal Data We Process
3.1 AIVerID account and authentication data
VerSketch uses AIVerID OAuth for login. We do not create or store your AIVerID password.
Depending on the claims supplied by AIVerID, we may receive and process:
- a stable AIVerID account identifier;
- email address and email-verification status;
- display name, given name, and family name;
- profile image;
- account creation or registration date;
- optional AIVerID profile identifiers; and
- OAuth access and refresh tokens required to maintain your authenticated session.
Authentication claims and tokens are stored in an encrypted, HTTP-only session cookie. The current session duration is up to seven days. Temporary OAuth state and PKCE data are used to complete sign-in and normally expire within ten minutes.
3.2 Projects and drawing data
When you save a project to the VerSketch cloud, we process information such as:
- project name and thumbnail reference;
- floor-plan and drawing specifications;
- levels, geometry, rooms, classifications, furnishings, annotations, and user-entered text;
- schema version, revision number, and mutation identifiers;
- project creation and modification timestamps;
- project history, snapshots, autosaves, handoff snapshots, and export-related snapshots; and
- deletion status and project promotion or migration identifiers where applicable.
Current cloud history is generally capped to the latest 30 snapshots per project, with older history pruned as newer snapshots are created.
3.3 Data stored locally on your device
VerSketch can store projects, drafts, recovery copies, and preferences in your browser’s localStorage, sessionStorage, and IndexedDB. This may include:
- full local project specifications;
- local and cloud draft copies;
- recent recovery or quarantine copies;
- onboarding and interface preferences;
- label-size and editor settings;
- saved 3D views, camera positions, north orientation, and view names; and
- DXF underlay names, parsed geometry, transforms, and import settings.
Local data remains on the device and browser profile where it was created unless you choose a feature that uploads or synchronizes it. We cannot normally access or restore local-only data.
Clearing browser storage, using private-browsing mode, resetting the browser, or losing the device may permanently remove local-only projects.
For professional-size local work, VerSketch mirrors project state into IndexedDB and automatically makes that atomic copy primary if localStorage reaches its quota. The application may request persistent browser storage and display aggregate usage and quota information reported by the browser. These operations remain on the device.
3.4 AI-assisted conversion data
VerSketch allows users to provide text, images, project context, or edit instructions for AI-assisted conversion into drawing specifications.
Conversion inputs are processed on VerSketch servers. When the active rail uses an external AI-model provider, VerSketch sends the necessary input to the current provider, Anthropic, PBC, for processing on servers located in the United States; the official current list of AI providers is available at https://versketch.xyz/subprocessors. When the active rail uses the built-in solver, no external model provider receives the input, but the input is still processed on VerSketch servers rather than staying in the browser. The interface identifies the rail that served each successful conversion.
What the provider receives is limited to what the conversion needs: the text you write, any image you supply, the portion of the project specification being edited, and the instructions our software adds to describe the required output format. It is used only to produce your requested result and to detect misuse. Under our agreement with the provider, your input is not used to train its models. The provider may retain input and output briefly for abuse detection, after which it is deleted; it does not become part of any model.
Because the provider processes this data in the United States, an input you send from another country is transferred internationally. We rely on the provider's contractual data-protection commitments, including standard contractual clauses where those apply, as the safeguard for that transfer. If you do not want your input processed outside your country, do not use AI-assisted conversion.
A data-processing agreement with our AI provider (Anthropic) is in place, incorporated automatically into Anthropic's Commercial Terms of Service, which we accepted when creating our API account.
Where an image workflow requires a temporary upload, the image may be held in private Supabase storage solely to provide that workflow. Temporary upload grants normally expire within two hours, and uploaded source images are scheduled for deletion within 24 hours.
When server-side AI processing is used, VerSketch may record operational metadata such as:
- input type;
- project identifier;
- processing adapter, vendor, or model;
- retry and validation status;
- build success or failure;
- token counts; and
- estimated processing cost.
If we change or add an AI provider, we will update this Policy and our service-provider information before the change takes effect, and provide any additional notice or choice required by applicable law.
Do not upload personal data, confidential plans, biometric images, government identifiers, or sensitive information unless you have the legal right and a genuine need to do so.
3.5 Billing and subscription data
Payments are processed by Stripe. Stripe may collect payment-card and billing details under its own privacy policy.
VerSketch does not store complete card numbers or card security codes. We may receive and store:
- Stripe customer and subscription identifiers;
- subscription tier and status;
- billing-period end date;
- education eligibility or expiry information;
- checkout price identifier; and
- account identifier associated with the purchase.
We may provide Stripe with your email address and VerSketch account identifier to create and manage your customer record, checkout session, subscription, and billing portal.
3.6 Read-only sharing data
A project owner can create a read-only share link. Anyone who obtains a valid share link may access the shared project without signing in until the link expires or is revoked.
The shared response may include the project name and the drawing content required to render the shared plan, including geometry, room or space names, classifications, furnishings, annotations, and other visible plan content.
VerSketch does not intentionally expose the owner’s AIVerID identifier through the public share response.
To prevent abuse, VerSketch may temporarily process the requesting IP address and store an HMAC-derived IP hash in a short-lived rate-limit record. Current rate-limit hashes are designed to expire approximately 24 hours after the most recent request associated with the hash. We do not use these hashes for advertising or cross-site tracking.
3.7 Technical and support data
When you access the Service, Vercel and other infrastructure providers may process standard request information such as IP address, browser or device type, requested URL, timestamp, response status, and security-related logs.
If you contact support, we process the information you submit, including your contact details, project or account identifiers, diagnostic information, screenshots, and correspondence.
VerSketch does not currently use advertising trackers or sell personal data.
When privacy-first reliability telemetry is enabled, VerSketch records one operational session row for a browser tab and whether that session experienced a client crash. The row contains only a coarse route group (for example, editor or pricing), coarse device class (phone, tablet, or desktop), release identifier, timestamps, and crash category. It does not contain an AIVerID, project identifier, share token, exact URL, drawing content, error message, stack trace, raw IP address, or browser fingerprint.
The same session row may also record whether that tab reached a small, fixed set of product milestones — first wall drawn, 3D view opened, export completed, code check run, and AI panel used — each recorded at most once with its timestamp. Milestones are linked only to the session row's pseudonymous key, contain none of the excluded data listed above, and are deleted together with that session row.
The random per-tab identifier is kept in sessionStorage. Before storage in Supabase, it is transformed with a deployment-specific HMAC; the raw identifier is not stored server-side. A separately domain-separated, short-lived HMAC of the requesting IP is used only to rate-limit this public endpoint under the same retention controls as other public rate-limit buckets.
3.8 Signup attribution data
When you initiate sign-in, VerSketch may process the UTM source, medium, and campaign parameters still supplied with that sign-in request, the host name of the referring website, and the time of that request. We carry this information only in the short-lived OAuth state used to complete that sign-in; we do not create a separate persistent attribution cookie. We store only the referring host, never the full referring URL, path, query, IP address, or browser fingerprint. This information is linked to your VerSketch account only when you sign in and is used to understand aggregate signup and activation channels. It is first-party measurement only and is not used for advertising or cross-site tracking.
3.9 AI assistants you connect
You can connect an AI assistant that you use under your own account with another company, such as Claude or ChatGPT, to your VerSketch account. Connection uses AIVerID authorization: you sign in and approve the requested permissions, and you can disconnect at any time.
Once connected, the assistant can read your VerSketch cloud projects and the information VerSketch derives from them, such as quantities and code-check results; validate and preview edits; create new projects; and submit proposed changes, all within the permissions you approved. The assistant cannot accept a proposal, save over your work, or delete a project. Every proposal waits for you to accept or reject it in VerSketch.
VerSketch receives only what the assistant sends when it calls VerSketch, such as the project it asks for, a proposed plan, and a short summary it writes for the proposal. VerSketch does not receive your conversation with the assistant. VerSketch checks each request's authorization with AIVerID and may reuse a successful check in server memory for up to 60 seconds, identified only by a one-way hash of the token. VerSketch does not store the assistant's access token.
For each proposal, VerSketch stores the project identifier, your account identifier, the base and proposed plan, the summary, its status, revision numbers, any retry identifier supplied with the request, and the related timestamps. A proposal that is neither accepted nor rejected expires after 7 days. Accepted, rejected and expired proposal records are scheduled for deletion 30 days after they were resolved or expired; an accepted change remains part of your project. VerSketch may also record usage metering for connected assistants, such as the type and size of each operation, which is kept while your account is active for quota and billing purposes. Rate-limit records are short-lived.
Project data that VerSketch returns to the assistant is then processed by the company that provides that assistant, under its own terms and privacy notice and under your account with it. That company is not a VerSketch service provider, and this Policy does not govern its processing. Connect only assistants you trust with your project information.
4. How We Use Personal Data
We use personal data to:
- authenticate users and maintain secure sessions;
- create, save, synchronize, recover, export, and share projects;
- provide AI-assisted conversion requested by the user;
- process subscriptions and provide billing management;
- prevent fraud, abuse, unauthorized access, and excessive automated requests;
- diagnose errors and protect the reliability of the Service;
- respond to support, privacy, security, and legal requests;
- comply with legal, accounting, and regulatory obligations; and
- improve the Service using operational information that is reasonably necessary for that purpose.
We do not use project content to train a general-purpose AI model unless we first provide a separate, clear notice and obtain consent where required.
5. Legal Bases
Depending on the activity and applicable law, including Thailand’s Personal Data Protection Act B.E. 2562 (“PDPA”) and the EU/UK General Data Protection Regulation (“GDPR”), we rely on:
- Performance of a contract: to provide login, project storage, sharing, conversion, exports, subscriptions, and support requested by you.
- Legitimate interests: to secure the Service, prevent fraud and abuse, maintain reliability, and understand operational failures, balanced against your rights.
- Legal obligations: to maintain required tax, accounting, payment, security, and compliance records and respond to lawful requests.
- Consent: where required for optional processing, sensitive data, non-essential storage technologies, or a future AI-provider workflow.
- Establishment, exercise, or defence of legal claims: where reasonably necessary and permitted by law.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing already lawfully completed.
6. Cookies and Browser Storage
VerSketch currently uses:
- an encrypted authentication-session cookie, normally lasting up to seven days;
- a short-lived OAuth state cookie, normally lasting up to ten minutes;
- a language-preference cookie, which may last up to one year; and
- localStorage and IndexedDB for projects, drafts, recovery data, and editor preferences; and
- sessionStorage for a random per-tab reliability-session identifier when telemetry is enabled.
Authentication and security cookies are necessary to provide the Service. Local project storage is used to provide the editing and recovery features selected by the user.
7. Service Providers and Disclosures
We may disclose limited data to:
- AIVerID, for identity and OAuth authentication;
- Vercel, for website and application hosting;
- Supabase, for the database and private object storage, currently hosted in Tokyo, Japan (
ap-northeast-1); - Stripe, for checkout, subscription, payment, and billing-portal services;
- future AI-processing providers, only after the notices described in Section 3.4 have been completed;
- professional advisers and auditors subject to confidentiality obligations; and
- courts, regulators, law-enforcement authorities, or other parties where disclosure is legally required or necessary to protect legal rights and safety.
Our current service-provider list is available at https://versketch.xyz/subprocessors.
We do not sell personal data or share it for cross-context behavioural advertising.
8. International Transfers
The Supabase project used for VerSketch is hosted in Tokyo, Japan. Vercel, AIVerID, Stripe, support providers, and future approved providers may process data in other countries.
Where personal data is transferred outside Thailand, the EEA, the United Kingdom, or another jurisdiction that restricts international transfers, we will use an available lawful transfer mechanism and appropriate safeguards.
Current transfer mechanisms and safeguards: Vercel, Supabase, Stripe, and Anthropic each incorporate the 2021 EU Standard Contractual Clauses (and, where applicable, the UK International Data Transfer Addendum) into the standard agreements that apply to our accounts with them, without requiring separate execution. AIVerID's transfer safeguards are governed by AIVerID's own privacy policy.
9. Retention
We retain data only for as long as reasonably necessary for the purposes described in this Policy:
- Local-only projects and preferences remain until you or the browser removes them.
- Active cloud projects remain while your project or account is active.
- Project deletion is initially recorded as a soft deletion. A verified privacy request may be required to complete permanent erasure from active systems.
- Project snapshots are pruned as new history is created; current history is generally capped at 30 snapshots per project.
- Temporary AI image uploads are scheduled for deletion within 24 hours, and upload grants normally expire within two hours.
- Proposals from a connected AI assistant expire after 7 days if not accepted or rejected; accepted, rejected and expired proposal records are scheduled for deletion 30 days after they were resolved or expired.
- Usage metering for connected AI assistants is retained while the account remains active and is deleted when the account is deleted.
- Share records remain until revoked, expired, deleted with the project, or no longer required.
- Share rate-limit IP hashes are designed to expire approximately 24 hours after the most recent request associated with the hash.
- Privacy-first session/crash telemetry is retained for up to 90 days and then removed by the scheduled cleanup process.
- Authentication sessions normally expire within seven days, OAuth state within ten minutes, and language preferences within one year.
- Signup-attribution data is retained while the account remains active and is deleted when the account is deleted.
- Subscription and transaction records may be retained as required for accounting, fraud prevention, taxation, disputes, and legal compliance.
- Support correspondence and security records are retained only as long as needed to resolve the matter and meet applicable obligations.
Deletion from backups and provider systems may take additional time, during which the data will remain protected and unavailable for ordinary use.
10. Your Rights
Subject to applicable law and exceptions, you may have the right to:
- request access to your personal data;
- receive information about how it is processed;
- correct inaccurate or incomplete data;
- request deletion or anonymisation;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data in a structured, commonly used, machine-readable format;
- withdraw consent;
- object to or request review of a qualifying automated decision;
- appoint an authorised representative; and
- lodge a complaint with Thailand’s Personal Data Protection Committee, an EEA data-protection authority, or another competent regulator.
VerSketch does not currently make decisions that produce legal or similarly significant effects based solely on automated processing.
To exercise a right, contact privacy@versketch.xyz. We may need to verify your identity and authority before acting. We will respond within the period required by applicable law.
Some data may be retained where deletion would conflict with a legal obligation, the rights of another person, fraud prevention, security, or the establishment, exercise, or defence of legal claims.
11. Security
We use administrative, technical, and organisational safeguards designed to protect personal data, including encrypted authentication cookies, access controls, private storage, row-level database protections, signed upload URLs, rate limiting, and separation of public share data from account identifiers.
No online service can guarantee absolute security. You are responsible for keeping your device, AIVerID account, exported files, and share links secure.
If a personal-data breach creates a legally reportable risk, we will notify the competent authority and affected individuals as required by applicable law.
12. Children
The Service is not directed to anyone below 18, except where use is lawfully authorised by a parent, guardian, school, or other responsible organisation. We do not knowingly collect a child’s personal data without the authorisation required by applicable law.
13. Changes to This Policy
We may update this Policy when the Service, providers, or legal requirements change. We will publish the revised version with a new effective date and provide additional notice where a change materially affects your rights or introduces a materially different use of personal data.
14. Contact
For privacy questions or rights requests:
- Email: privacy@versketch.xyz
- Address: 133 Moo 8, Ban Na Yao, Thung Samo Subdistrict, Khao Kho District, Phetchabun Province 67270, Thailand
- DPO, if applicable: Not appointed. VerSketch has not appointed a Data Protection Officer; privacy requests are handled directly by the operator at privacy@versketch.xyz.
- EU representative, if applicable: Not appointed. VerSketch is operated from Thailand and has not appointed a representative in the European Union or the United Kingdom. Users there may contact privacy@versketch.xyz directly.