Privacy Policy — Arrows & Boxes
Version 1.0 — effective 2026-07-17
This policy explains how Rulecore AB handles personal data in connection with the Arrows & Boxes website and application at arrowsboxes.com ("the Software").
The short version: your diagrams never reach us. Arrows & Boxes runs entirely in your browser, there is no account and no cloud, and we do not use cookies, analytics, advertising, or tracking of any kind. The only personal data we are involved with is the connection data your browser unavoidably sends in order to load the page, and anything you choose to put in an e-mail to us.
1. Data controller
| Legal name | Rulecore AB |
| Registration number | 556895-5669 |
| Postal address | Bergåsvägen 1, 433 51 Öjersjö, Sweden |
| VAT number | SE556895566901 |
| info@rulecore.com |
We have not appointed a data protection officer; we are not required to. Privacy questions go to info@rulecore.com.
2. Your diagrams are not personal data we process
Everything you create in Arrows & Boxes — diagrams, text, notes, scripts — is stored on your device, in your browser's storage, and in files you save yourself. It is never transmitted to us, and we have no ability to access, read, or recover it.
This means we are not the controller for the content of your diagrams, even if you put personal data in them. That data stays under your control. If you use Arrows & Boxes to process other people's personal data in a professional capacity, you are the controller for it, and this policy does not cover that processing.
It also means we cannot help you recover lost work. Browser storage can be erased by clearing site data, by private/incognito modes, or by browser and device faults. Use Save/Export to keep your own copies.
3. What we process, why, and on what basis
3.1 Delivering and protecting the website
When your browser loads arrowsboxes.com, it necessarily sends your IP address, and typically your user agent (browser and operating system), the address you requested, and the time of the request. Our hosting provider processes this at the network edge in order to route the response to you and to protect the site against attack and abuse.
- Purpose: delivering the Software to you; security, integrity, and abuse prevention.
- Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in making the Software available and keeping it secure. We consider this proportionate: the data is the minimum a web request requires, we do not use it to identify or profile you, and we have switched off the request logging our hosting platform would otherwise have enabled by default.
- Retention: we do not operate any server, database, or application log of our own, and we keep no copy of this data. Our hosting provider processes it transiently for delivery and retains limited security and aggregate traffic data under its own retention schedule (see clause 5).
3.2 If you contact us
If you e-mail us, we process your e-mail address, your name if you give it, and whatever you choose to write.
- Purpose: reading and answering your message.
- Legal basis: our legitimate interests (Article 6(1)(f) GDPR) in responding to enquiries; or, where your message concerns this Agreement, performance of a contract (Article 6(1)(b) GDPR); or compliance with a legal obligation (Article 6(1)(c) GDPR) where, for example, you exercise a data-subject right.
- Retention: for as long as needed to deal with your message and to keep a record of it, normally no more than 24 months, and longer only where a legal obligation or a legal claim requires it.
4. Storage on your device — and why there is no cookie banner
Arrows & Boxes stores data in your browser (IndexedDB and local storage):
- your documents and their panel layout — so your work is still there when you come back;
- a record that you accepted the licence terms — so we do not ask you again;
- a few local preferences, such as whether you have dismissed the first-run hint.
All of this is strictly necessary to provide the service you have explicitly requested, so under Chapter 9, Section 28 of the Swedish Electronic Communications Act (lag (2022:482) om elektronisk kommunikation) it does not require your consent — which is why you are not asked for any.
We set no cookies. We use no analytics, no advertising, no tracking pixels, no fingerprinting, and no third-party scripts of any kind. Nothing stored on your device is ever read by us or sent anywhere. You can erase all of it at any time by clearing this site's data in your browser — that will also delete your diagrams.
5. Who else is involved
| Recipient | Role | What for | Where |
|---|---|---|---|
| Cloudflare, Inc. | Processor | Hosting and delivering the static site; edge security | EU edge; US parent |
| Our e-mail provider | Processor | Receiving and storing e-mail you send us | EU |
We have a data processing agreement with each processor. We do not sell personal data, we do not share it for advertising, and we do not disclose it to anyone else except where we are legally required to, or where it is necessary to establish, exercise, or defend a legal claim.
Transfers outside the EU/EEA: our hosting provider is a US company and its group may access data from outside the EU/EEA. Such transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with supplementary technical measures. You may request a copy of the relevant safeguards at info@rulecore.com.
6. Material you fetch from third parties
Arrows & Boxes lets you write scripts that fetch data from addresses you choose. If you do, your browser contacts that third party directly — sending it your IP address and whatever your script sends.
That is a connection between you and that third party, on its terms and its privacy policy. It does not pass through us, we do not see it, and we are not the controller for it. Only fetch from sources you trust.
7. No profiling or automated decisions
We do not profile you, and we make no automated decisions producing legal or similarly significant effects concerning you (Article 22 GDPR).
8. Children
Arrows & Boxes is not directed at children, and we knowingly collect no personal data from them. Because we operate no accounts and collect no data beyond what clause 3 describes, we do not process children's data in practice.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify it if it is inaccurate or incomplete;
- erase it ("right to be forgotten");
- restrict our processing of it;
- object to processing based on our legitimate interests, on grounds relating to your particular situation — including an absolute right to object to direct marketing (we do none);
- data portability, where processing is based on consent or contract and is carried out by automated means; and
- withdraw consent at any time, where we rely on consent (we currently do not), without affecting the lawfulness of processing before withdrawal.
To exercise any of these, e-mail info@rulecore.com. We will respond within one month; we may need to verify your identity first, and we may extend the period by two months where a request is complex, telling you why.
Please note the practical limit: for the processing in clause 3.1 we hold no data that identifies you and retain no logs, so in most cases there is simply nothing for us to retrieve, correct, or erase. We will tell you if that is the case.
Right to complain: if you believe we handle your personal data unlawfully, you may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy@imy.se, https://www.imy.se — or with the supervisory authority in your EU/EEA country of residence or workplace.
10. Security
The site is served over HTTPS. It runs no server code, holds no database, and stores no user data on our
side — the most effective safeguard being that there is almost nothing to safeguard. On our hosting
platform we keep request logging, preview URLs, and the default workers.dev hostname switched off, so
the site is reachable only through arrowsboxes.com and no request data is retained there.
11. Changes to this policy
We may update this policy. The version and date at the top identify the current text. Where a change materially affects you, we will give notice in the Software before it takes effect. Previous versions are available on request at info@rulecore.com.
12. Contact
Questions, requests, or complaints about privacy:
Rulecore AB · Bergåsvägen 1, 433 51 Öjersjö, Sweden · info@rulecore.com
Arrows & Boxes is a trademark of Rulecore AB.
See also the End-User License Agreement.