Canvas

Privacy

Last updated September 28, 2026

Canvas uses your information only to operate and improve the product and—if you explicitly ask us to—send product updates. We do not sell your personal information.

Using the Canvas workspace

You can sign in with an email code or Google. If you choose Google, Google shares your verified email address and basic profile information with our authentication provider, Supabase. Canvas uses persistent authentication cookies to remember your sign-in on this browser. You can sign out at any time.

When AI features are enabled and you request a response or quiz, prompts, attached images, and selected note or source context are sent to OpenAI. Canvas sends these requests with response storage disabled. Under OpenAI's default API data controls, request data may still be retained in abuse-monitoring logs for up to 30 days and is not used to train models unless the account explicitly opts in. See OpenAI's API data-controls documentation.

In the signed-in workspace, your projects, notes, messages, highlights, quiz progress, PDFs, and images are saved to your private cloud account so you can continue on another device. Uploaded PDFs are available for reading and are automatically prepared for use in project chats.

Uploading a PDF starts preparation automatically. Preparation processes the PDF in an isolated worker and sends its extracted text to OpenAI to create search embeddings. When you ask a question with project sources enabled, your question is used for lookup and relevant passages may be included in the answer request, even if you did not highlight them yourself. Embedding requests have their own API data controls; disabling response storage does not mean that every provider log has zero retention.

Previously saved PDFs are not prepared automatically, and projects you previously set to reading only keep that choice. Prepare all PDFs in project settings prepares every previously saved PDF in that project. Removing a PDF stops new processing and schedules removal of its derived data. Cleanup becomes eligible after a 24-hour grace period and runs during subsequent maintenance; in-flight work and already issued storage permissions must finish or expire safely. Data already sent to a provider cannot be recalled. Past conversation requests, answers, and their source evidence remain part of those conversations until you delete them. Temporary lookups that were never attached to a response expire separately. Removing a PDF also removes access through its source links.

Your browser also keeps cached files, drafts, and changes waiting to sync. Clearing site data can remove changes that have not yet reached the cloud. The app distinguishes saved cloud work from pending local changes. Older browser-only work is uploaded only when you explicitly import it into your signed-in account.

Joining the waitlist

If you explicitly join the Canvas waitlist, we store the email address you confirm so we can send early-access invitations and occasional product updates. You can unsubscribe from those emails at any time.

Service providers

Vercel hosts the website and provides aggregated, cookie-free web analytics. Supabase provides account authentication, workspace storage, and private file storage. Resend delivers sign-in emails, Neon stores waitlist records, and OpenAI provides enabled AI features. These providers process information to help us operate Canvas. See Vercel's analytics privacy documentation.

How long we keep it

We keep a waitlist email until the waitlist ends, you unsubscribe, or you ask us to remove it. Cloud workspace data remains associated with your account until it is deleted or you request its removal. During early access, account export and deletion requests may be handled manually. Backup copies expire separately from active data; we will explain the applicable backup retention when handling a deletion request. Browser-only copies remain until you remove them.

Your choices

To ask what information we hold, correct it, or request deletion, email hello@canvaslearn.app.