← orgchart.fyi

Privacy policy

Effective [EFFECTIVE DATE]. Operated by [OPERATOR LEGAL NAME]. Contact: [CONTACT EMAIL].

orgchart.fyi lets an organization build and share its org chart. This page lists exactly what we hold, why, who else handles it, and how to get rid of it. It is written to be read.

Two kinds of data, two roles

Your account (who you are when you sign in) is ours to look after, and this policy governs it. An organization's chart — the names, titles, reporting lines and other details of the people on it — is entered by that organization, and the organization decides what goes on it and who may see it. For chart data we act on the organization's behalf (a "processor", in data-protection terms), and the organization is responsible for having the right to put its people's details on a chart. If you are on a chart and want something about you changed or removed, ask your organization's admins; you can also write to us.

What we collect

Data When Why
Account: your name, email address and, if you sign in with Google or Microsoft, the profile image URL and account identifier they provide. No password: we never have one. When you first sign in. To recognise you and show you the organizations you belong to.
A sign-in link: when you ask for one by email, a one-way hash of the link's one-time token. We store the hash, never a working link. Until you open the link or 15 minutes pass. To check the link you open is the one we sent.
Organizations and memberships: an organization's name, its colour, the email domains it lets people join from, who belongs to it and in what role (owner, admin, editor, member). When an organization is created or changed. To decide who may see and change each chart.
Invitations: the email address invited, the role offered and who invited it. When an admin invites someone; removed when accepted or declined, or after 30 days. To let that address join when it signs in.
The chart: whatever the organization enters about its people and positions — typically names, job titles, reporting lines, departments, locations, work email and phone, start dates, and any other fields the organization adds (which may include private ones such as salary or date of birth, visible only to the people the organization allows). When the organization's admins, editors or members enter it. It is the chart. It is shown to each person only as far as the organization's visibility settings allow, and that is enforced on our server.
The chart's history: every change, who made it and when. With every change. So admins can see how the chart changed, and to find mistakes.
The organization's plan: when its free trial ends, which plan it has (Starter, Professional or Enterprise), its status and paid-through date, who bought it, and the Lemon Squeezy customer and subscription ids. If we gave the plan for free, a note that it came from a free offer in place of those ids — or, where a code was used, a shortened hash of the code, never the code itself. The trial's end when the organization is created; the rest when an owner buys a plan or accepts a free grant. To know what the organization is entitled to. We never see a payment card number.
Technical: your IP address and browser identifier, in server logs and in a short-lived in-memory counter. Every request. To run the service, and to limit how often one address can ask for sign-in links or redeem a code.

We do not collect payroll, bank or government identifiers, and we do not connect to any HR or payroll system. We do not use analytics or advertising trackers.

Cookies and storage on your device

Who else handles your data

Only the services needed to run the site, each for one job:

We do not sell data, share it for advertising, or build profiles.

Exports

Admins can download the chart as a spreadsheet (CSV or Excel), a full backup (JSON), a picture (SVG or PNG) or a printout. Members and editors can too, but only if an admin turns that on for the organization. A download holds only what the person downloading it can already see on the chart. The file is made in your browser from the chart already on your screen: nothing extra is fetched and no other service is involved. Once saved, the file is outside orgchart.fyi, and keeping it safe, sharing it and deleting it are the organization's responsibility.

How long we keep it

Your choices and rights

Age

The site is a business tool and is for people 18 and over.

Changes

When this page changes, the effective date above changes with it. Material changes to how we handle account data will also be announced on the site.