Privacy Policy
Effective September 8, 2026
Canvas is an experimental design tool operated by Ferum Labs ("we", "us"). This policy explains how we handle personal information when you use hellocanvas.ai and the Canvas services we operate. This policy applies only to Canvas.
1. Information we handle
- Account information. When you sign in with Google or an email verification code, Clerk processes authentication for us. We receive your account identifier, verified email address, and, when available, your name and profile picture. We also maintain a Canvas account identifier and account status.
- Design content. Depending on the features you use, Canvas handles design files, images, layouts, comments, prompts, generated output, and project previews. Some editor changes stay in your browser rather than being saved to a shared server.
- Optional voice and AI input. If you use an enabled voice or coding-agent feature, the audio, prompt, and relevant project context are processed to carry out your request. These features are not enabled in every deployment.
- Technical information. Our hosting, authentication, and security providers process information such as IP addresses, browser information, request times, session activity, and errors to deliver and protect the service.
- Support communications. We receive the information you send when contacting us or reporting a problem.
2. Google sign-in
Canvas requests only basic identity permissions: OpenID, email address, and profile information. We use this information to authenticate you, create or update your Canvas account, and display your profile. Google sign-in does not give Canvas access to your Gmail messages, Google Drive files, calendar, or Google password.
We do not use Google account information for advertising or send it to the coding agent as project context. Canvas's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
3. Why we use information
We use information to provide authentication and design features, fulfill your requests, operate hosting and storage, respond to support inquiries, diagnose failures, prevent abuse, and meet applicable legal obligations. Where applicable, we rely on providing the service you request, our legitimate interests in operating a secure service, legal obligations, or your consent for optional processing.
4. Service providers and sharing
- Clerk provides account authentication, Google sign-in, email verification, and session security.
- Vercel hosts the web application and, where configured, isolated project preview environments.
- Amazon Web Services provides backend infrastructure and storage, including image assets and account storage where enabled.
- OpenAI processes prompts, relevant code or design context, and audio when an enabled AI or transcription feature is used. Review the content you submit; do not include secrets or information you are not authorized to share.
Providers receive information needed for their role and process it under the applicable service arrangements. We may also disclose information at your direction, when legally required, to protect rights and safety, or as part of a business transfer subject to applicable privacy obligations. We do not sell personal information.
5. Project previews and local drafts
Signing in to Canvas does not automatically make a separately hosted project preview or asset URL private. Anyone with access to an unprotected preview may be able to view its contents or source. Only share material suitable for that preview's access controls. Connected projects may be operated by someone other than Ferum Labs and have their own privacy practices.
Canvas uses browser storage for preferences, editor drafts, and certain comments. Browser-only changes may disappear when a tab closes or storage is cleared; they are not a guaranteed backup. Removing a Canvas account does not automatically remove files from an independently managed project, repository, or preview.
6. Cookies and browser storage
Canvas and its authentication provider use cookies and similar storage for sign-in, security, preferences, and editor state. Blocking required cookies can prevent sign-in. You can clear browser storage using your browser settings, but this may sign you out or delete local drafts. These public legal pages do not install advertising or analytics scripts.
7. Retention and security
We retain information as needed to provide the service, maintain security, resolve issues, and satisfy legal obligations. Retention depends on the kind of information and where it is stored. After account deletion, limited records may remain to prevent an old synchronization event from recreating the account; backup and security records may remain until their retention periods end.
We use technical and organizational safeguards, but no service can guarantee absolute security or uninterrupted availability. Keep independent copies of important work and do not upload passwords, private keys, or highly sensitive personal information.
8. Your choices and requests
You can choose email sign-in instead of Google, decline microphone permission, and avoid optional AI features. You can manage Google's connection to Canvas in your Google Account settings. Disconnecting Google does not by itself delete your Canvas account or existing project content.
To request access, correction, export, or deletion of personal information, contact zo@ferumlabs.com. Depending on your location, you may also have rights to object to or restrict processing, withdraw consent, appeal a decision, or complain to a data-protection authority. We may need to verify your identity before acting. We will handle requests as required by applicable law.
9. International processing and children
Our providers may process information in the United States and other countries. Where required, applicable transfer safeguards govern these transfers. Canvas is intended for adults, not children under 18. If you believe a child has provided personal information, contact us.
10. Changes and contact
We will update this page when our practices change and provide additional notice when required. Questions about this policy or Canvas privacy can be sent to Ferum Labs at zo@ferumlabs.com.