Skip to content
PrivacyTerms of UseOpen Canvas

Your information

Privacy Policy

This policy explains what Canvas processes, why we process it, and the choices available to you across startwithcanvas.com, the Canvas app, and Canvas Clipper.

Effective August 17, 2026

1. Who operates Canvas

Canvas is operated by Bruce Stenberg, an individual doing business as Canvas, based in Philadelphia, Pennsylvania, United States (collectively, “Canvas,” “we,” “us,” or “our”). This Privacy Policy applies to startwithcanvas.com, app.startwithcanvas.com, the Canvas Clipper Google Chrome extension, and related support communications (the “Services”).

Canvas is the controller of personal information processed for its own purposes. If an organization provides your account, that organization may also control workspace information and your access to it.

2. Information we collect

Information you provide

  • Account and profile information: email address, display name, authentication records, account and workspace identifiers, role, permissions, and business-account details.
  • Workspace content: board titles, notes, shapes, comments, tasks, files, images and other media, links, capture content, revisions, sharing settings, and collaboration activity that you or your collaborators submit.
  • Communications: messages and information you send to support, sales, or privacy contacts, including feedback and troubleshooting material you choose to provide.

Information collected when you use the Services

  • Technical and usage information: IP address, approximate region derived from IP, browser and device type, operating system, page and feature interactions, timestamps, request and performance data, and diagnostic events.
  • Session replay and diagnostics: in the Canvas web app we use Datadog to understand reliability and usability. This may reproduce interactions and visible interface state. We configure sensitive fields, including password, one-time-code, token, payment, and file-input fields, to be masked or excluded, and we scrub known account and content fields from diagnostic events. Please do not place sensitive personal information in board content or fields where it is not needed.
  • Browser storage: cookies, local storage, session storage, and IndexedDB records used for sign-in, preferences, guest continuity, pending operations, media previews, and offline or resilient app behavior.

3. Canvas Clipper Chrome extension

Canvas Clipper has one purpose: it lets you deliberately preview and save content from the public page you are viewing into an authorized Canvas Capture Inbox. It does not continuously monitor your browsing.

What the extension accesses

Only after you open the extension or choose a Canvas context-menu command, Canvas Clipper may read the current tab’s page title, canonical or current URL and domain, metadata description, selected text, one visible image candidate and its alternative text, or the focused link’s URL and text. Depending on what you choose, this information may be considered website content or web-history information. The extension also uses your Canvas account and workspace identifiers and a time-limited authorization token to save the confirmed capture.

How permissions are used

  • activeTab and scripting: temporarily inspect only the tab on which you invoked Canvas Clipper and build a local preview.
  • contextMenus: provide Save page, Save selection, Save image, and Save link commands that you choose to invoke.
  • storage: hold a pending preview, connection request, and time-limited Canvas connection in Chrome session storage.
  • Canvas host access: connect only to authorized Canvas app origins to establish the connection and submit a capture you confirmed.

The extension displays a preview before saving, does not inject broad background content scripts, does not run remote code, and does not contact arbitrary websites. A pending draft is removed after a successful save or when its browser session ends. The resulting capture remains in Canvas as described under Retention below.

Chrome Web Store User Data Policy

Canvas Clipper’s use and transfer of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only to provide or improve the user-facing clipping feature, maintain security, prevent abuse, and comply with law. We do not use it for advertising, creditworthiness, lending, or an unrelated purpose.

4. How we use information

We use information to:

  • provide, secure, maintain, and improve the Services;
  • authenticate users and preserve authorized account access;
  • store, synchronize, render, and share workspace content as directed;
  • complete user-confirmed Canvas Clipper captures;
  • send transactional messages and respond to requests;
  • diagnose failures, measure performance, and prevent fraud or abuse; and
  • comply with legal obligations and enforce our Terms of Use.

Where applicable, we rely on performance of a contract, our legitimate interests in operating and securing Canvas, consent where required, and compliance with legal obligations.

5. How information is disclosed

We may disclose information in these limited circumstances:

  • At your direction: to collaborators, guests, workspace owners, or the public when you choose sharing or publishing features.
  • Service providers: Cloudflare for app hosting, delivery, storage, security, and selected AI infrastructure; PlanetScale for hosted database infrastructure; Mailgun for transactional email; and Datadog for performance, diagnostics, and session replay. They process information for us under contractual or technical restrictions.
  • Legal and safety: when reasonably necessary to comply with law, legal process, or a valid government request; protect users, the public, or the Services; or investigate fraud, abuse, or security incidents.
  • Business transition: in connection with a financing, reorganization, acquisition, or sale, subject to appropriate safeguards and notice when required.

We do not sell personal information. We do not transfer personal information for cross-context behavioral advertising, determine creditworthiness, or provide lending services. Human access to private user content is limited to what is necessary for support you request, security or abuse investigation, legal compliance, or internal operations where access is strictly necessary.

6. Retention

We retain information only for as long as needed for the purposes described here, subject to technical, legal, security, backup, and dispute-resolution needs. Current product windows include:

  • authentication challenges generally expire after 10 minutes;
  • web sign-in sessions generally expire after 14 days;
  • new guest continuity records may remain for up to 90 days;
  • Canvas Clipper connection credentials generally expire after 15 minutes;
  • Datadog diagnostic logs are configured for a 15-day retention period; and
  • active Canvas Clipper captures remain until you remove or archive them; archived captures are scheduled for purge after 30 days.

Workspace content otherwise remains while the account or workspace is active or until it is deleted through an available product control. Browser-local data may remain until it expires, you clear it, or the browser evicts it. Canvas does not currently provide a fully automated account-erasure workflow; deletion requests are reviewed and completed using available technical controls. Limited copies may remain temporarily in backups or where retention is required by law, security, fraud prevention, or an unresolved dispute.

7. Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport, restricted authorization, secure session cookies, short-lived extension credentials, provider access controls, and diagnostic-data scrubbing. No system is completely secure, and we cannot guarantee absolute security.

8. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. You may also have the right to appeal a denied request or complain to a privacy regulator. We do not discriminate for exercising a privacy right.

To make a request, email privacy@startwithcanvas.com. We may need to verify your identity and authority. Workspace owners may need to handle requests concerning an organization-controlled account.

9. International use

Canvas is based in the United States. If you use the Services elsewhere, information may be processed in the United States and other countries where our providers operate. Where required, we use legally recognized safeguards for international transfers.

10. Age requirement

The Services are for people who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. Contact us if you believe a person under 18 has provided information to Canvas.

11. Changes to this policy

We may update this Privacy Policy as Canvas changes. We will post the revised policy here, update the effective date, and provide additional notice when a change materially affects your rights and applicable law requires it.

12. Contact

Privacy questions and requests: privacy@startwithcanvas.com
General support: support@startwithcanvas.com
Bruce Stenberg, doing business as Canvas
Philadelphia, Pennsylvania, United States

Your use of Canvas is also governed by the Terms of Use.

© 2026 Canvas

PrivacyTerms of UseContact