Privacy Policy
- Last updated:
- 13 June 2026
- Effective:
- 13 June 2026
- Version:
- 1.0
Plain-language summary. Canvas Math is a tool for writing, typing, and speaking math and getting it transcribed, solved, explained, and read aloud. To do that, we send your handwriting and text to outside AI providers (Anthropic and OpenAI). We store your account details and your notes so they sync across your devices. We do not sell or “share” your personal information for advertising. This document tells you exactly what we collect, why, who receives it, how long we keep it, and what choices you have — including where our current handling falls short of what we are building toward. Where we are honest about a gap, we mean it: please read those parts, not just the summary.
A note on completeness. This policy was drafted carefully and is intended to be accurate to how the product actually works today. It has not yet been reviewed by a licensed attorney, and several compliance items below are launch blockers we have not finished (a working age screen, a self-serve data-export and account-deletion flow, granular consent controls, signed data-processing agreements with every provider, and a completed data-protection impact assessment). You should obtain a licensed-attorney review before relying on this document for regulated traffic (EU/UK users, California consumers, or any users who may be minors).
1. Introduction and scope
Canvas Math (“Canvas Math,” “we,” “us,” “our”) provides an AI-native mathematical canvas at canvasmath.com (currently also reachable at math-canvas-chi.vercel.app). This policy explains how we handle personal data when you visit the site, sign in, and use the product.
We are the data controllerfor the personal data described here. This policy covers the website, the signed-in application, and the AI features (auto-calculation, solve and explain, “Help me out,” “Prove It,” visualizations and animations, and Learn Mode voice tutoring).
It does not cover third-party services you reach by following links away from Canvas Math, or the separate privacy practices of the AI, identity, hosting, and payment providers we use as sub-processors (we name and link to them in Section 7).
2. Who we are and how to contact us
Controller: Canvas Math.
Privacy contact / all data-rights requests: privacy@canvasmath.com.
General / legal contact: legal@canvasmath.com.
Data Protection Officer (DPO): not appointed. We are not currently required to appoint one; if that changes, we will name them here.
EU representative (GDPR Art. 27): not yet appointed. Because we serve users in the EEA from outside the EU and have no EU establishment, an Art. 27 representative is required before we open the service to EEA traffic. Appointing one is a launch blocker, and we will list the representative and their contact details here before EEA sign-ups are enabled.
UK representative (UK GDPR Art. 27): not yet appointed; same status and commitment as the EU representative.
Until those representatives are appointed, EEA/UK users should contact us directly at privacy@canvasmath.com, and we will handle requests as described in Section 11.
3. Summary table (layered notice)
This table is the short version of what we collect, why, on what lawful basis (GDPR), who receives it, and how long we keep it. The sections after it give the detail. Where retention says “until you ask us to delete it,” please read Section 9 carefully — today deletion is handled manually and is not yet fully self-serve.
| Data category | What it is | Why we use it | Lawful basis (GDPR) | Recipients (sub-processors) | Retention (honest, as built) |
|---|---|---|---|---|---|
| Account & identity | Your name, email, profile image URL, and Google account identifier from Google sign-in; the Google OAuth tokens our login uses | Create and secure your account; sign you in; gate access to the service | Contract (Art. 6(1)(b)) | Google (identity); Neon (database); Vercel (hosting) | Retained indefinitely until we delete your account. There is currently no automatic deletion and no self-serve account-deletion button — see Section 9. |
| Your content — handwriting & notes | Raw ink strokes, plots/visualizations, the transcribed text (LaTeX) of your writing, AI responses, note titles, and version snapshots of those | Store and sync your notes; let you reopen, search, archive, and export them | Contract (Art. 6(1)(b)) | Neon (database); Anthropic and the max-proxy provider (when you trigger AI); Y-Sweet (only during live collaboration) | Retained indefinitely. “Deleting” a note today only hides it; the underlying content is not erased. Version snapshots are never pruned. See Sections 6 and 9. |
| Your content — voice/spoken topics | The text recognized from your spoken topic in Learn Mode; the narration text we send to be read aloud | Run Learn Mode (turn your spoken/typed topic into a lesson and speak the lesson) | Contract (Art. 6(1)(b)) | Your browser’s speech engine (e.g. Google for Chrome dictation); Anthropic / max-proxy (lesson generation); OpenAI (text-to-speech) | We do not store raw audio. Recognized topic text becomes part of the note (same retention as notes). Synthesized audio is streamed and not stored on our servers. |
| Usage & technical | Your IP address (used as a rate-limit key), per-call usage/metering records (model, token counts, note id, user id), and standard hosting/log data | Prevent abuse, enforce rate limits, meter usage, operate and debug the service | Contract for metering tied to your plan (Art. 6(1)(b)); legitimate interests for security, abuse prevention, and IP rate-limiting (Art. 6(1)(f)) | Upstash (raw IP rate-limit key, when configured); Vercel (hosting/logs); Neon (metering records) | IP in the rate-limit store is transient (expires with the sliding window). Metering records in our database are retained indefinitely today (no pruning job). See Section 9. |
| Billing (when active) | Your email and user id passed to our payment processor; subscription/credit records | Take payment, manage subscriptions and credits | Contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) | Stripe (payments) | Dormant today (billing is not live). When active: card data is handled by Stripe and never touches our servers; billing records kept for the statutory tax/accounting period. |
| Cookies & local storage | A sign-in session cookie, a collaboration cookie for guests, and a local cache of your notes in your browser | Keep you signed in; route collaboration guests; let the app work offline-first | Contract / strictly necessary | Stays on your device / our servers | Session cookie per Auth.js expiry; local note cache stays in your browser until you clear it. No advertising cookies. |
California (CCPA/CPRA) note on the same data: the categories above map to the CCPA categories of identifiers (name, email, Google id, user id), internet/network activity (IP, usage records), user-generated content (handwriting, transcriptions, AI responses, spoken-topic text), and commercial information (billing, when live). We do not collect precise geolocation. We do notsell or “share” (for cross-context behavioral advertising) any of it. See Sections 11 and 12.
4. Information we collect
(a) Account and identity
You sign in with Google. When you do, we receive and store your name, email address, profile image URL, and Google account identifier, plus the OAuth tokens(access, refresh, and id tokens) that the sign-in uses. Your email is also how access to the service is gated. Sign-in doubles as sign-up — we create your account on first login.
(b) Your content (notes, math, and voice)
When you write, type, plot, or solve, we store the raw ink strokes, any plots/visualizations, the transcribed text (LaTeX) of your writing, the AI’s response text, and the note title. We also keep version snapshots of this content when notes are reconciled during collaboration. In Learn Mode, your spoken topic is recognized into text by your browser and that text is stored as part of the lesson; we do not store raw audio.
Important — free-form content can be sensitive. Because the canvas accepts anything you write or say, you could put personal, health, religious, or otherwise sensitive information into a note. We cannot reliably detect or block this. Please do not enter sensitive personal data, or personal data about other people, that is not necessary for your math work. If you knowingly enter special-category data (GDPR Art. 9), you are doing so on the basis of your explicit consent, and we recommend against it.
(c) Usage and technical data
On metered and rate-limited actions we read your IP address (from the x-forwarded-for header) and use it as a rate-limit key. We record per-call usage data (the model used, input/output token counts, the related note id, and your user id) for metering and cost control. Standard hosting and log data is generated by our host. We do not use advertising trackers and do not collect precise geolocation.
(d) Billing data (dormant today)
Payments are not live yet. When billing is enabled, checkout will pass your email and user id to our payment processor, and we will store subscription and credit records. Card and payment details are entered on the processor’s hosted checkout and never reach our servers.
5. How and why we use your data (purpose and lawful basis)
We tie each purpose to a specific GDPR lawful basis rather than relying on a blanket “consent”:
- Run your account and sign you in— Contract (Art. 6(1)(b)). Necessary to provide the service you signed up for.
- Store, sync, search, archive, and export your notes— Contract (Art. 6(1)(b)).
- Transcribe, solve, explain, visualize, and read aloud your math(sending your handwriting image and/or recognized text to our AI providers) — Contract (Art. 6(1)(b)). This is the core function you are asking the product to perform, so contract is the appropriate basis, not consent.
- Prevent abuse and runaway cost; IP-based rate limiting— Legitimate interests (Art. 6(1)(f)). We have assessed that these uses are necessary and proportionate and do not override your rights; you can object (see Section 11), and we maintain a documented legitimate-interests assessment. Our usage/metering records are per-user and per-note (identifiable), not an aggregate analytics product; we do not run a separate behavioral-analytics pipeline.
- Take payment and manage subscriptions/credits (when live)— Contract (Art. 6(1)(b)) and, for retaining billing records, legal obligation (Art. 6(1)(c)).
- Anything optional and non-essential(for example, future participation in model improvement, or marketing email) — Consent (Art. 6(1)(a)), asked for separately and granularly, and withdrawable at any time. We do not bundle these into sign-in. (See Section 15 on the single sign-in and your choices.)
6. AI processing and third parties
This is the most important section for understanding where your work goes.
Solve, explain, recognize, “Help me out,” “Prove It,” visualize, animate. When you trigger these, an image of your handwriting (a PNG) and/or the recognized text of your math is sent from your device, through our server, to a vision-capable AI model. By default the model is reached through our self-hosted “max-proxy” provider; in some configurations it is the Anthropic API directly. Both paths send the same content (the handwriting image and your instruction/recognized text). The provider that is live can change; we keep this policy and the sub-processor table (Section 7) accurate to the active configuration.
Learn Mode voice. Learn Mode generates a lesson (text, via the same AI path above) and then reads it aloud. To produce the audio, the narration text is sent to OpenAI’s text-to-speech model. The audio is streamed back to you and is not stored on our servers. OpenAI is used only for text-to-speech, never for tutoring or solving.
Dictation.When you speak a topic in Learn Mode, your browser’s built-in speech recognition converts it to text. In some browsers (for example, Chrome), this may send your microphone audio to the browser vendor’s servers (e.g. Google). That happens in your browser, outside our control, and is governed by your browser’s and that vendor’s privacy terms. The recognized text is what reaches us.
On training.Canvas Math does not train AI models on your data. Anthropic’s and OpenAI’s commercial API terms state that inputs and outputs sent through their APIs are not used to train their models, and both apply short default retention for abuse monitoring (broadly, on the order of up to ~30 days, with shorter or zero-retention options for eligible customers). We are pursuing zero-data-retention / no-logging arrangements with our providers to strengthen this. Honest caveat:the default tutoring path runs through our self-hosted max-proxy, which sits on top of a consumer-grade subscription whose data-handling terms differ from the commercial API terms. We will not assert a blanket “never used to train” promise that the active provider mix does not actually back; before we open the service to regulated traffic we will confirm the live path’s terms and update this section to state precisely what applies.
AI output can be wrong, and no significant decision is made about you.The AI assists with math. Its output can be incorrect — verify anything you rely on, especially for graded coursework (see the Terms of Service on academic integrity). The AI does not make any legal or similarly significant decision about you by automated means (see Section 15).
7. Sharing, disclosure, and sub-processors
We do not sell your personal information and do not “share”it for cross-context behavioral advertising. We disclose data only to the service providers (“sub-processors”) below, each acting on our instructions to deliver the features you use. All of these providers are in the United States, which means international transfers apply for EEA/UK users (Section 8). Before opening the service to regulated traffic we will have a data-processing agreement (and, where needed, transfer safeguards) in place with each.
- Anthropic— runs the solve/explain/recognize/visualize AI models; receives your handwriting image and instruction text. (US)
- Max-proxy provider (self-hosted, onto a Claude-family model) — the default tutoring path; receives the same image and text as Anthropic. (US-hosted)
- OpenAI— text-to-speech for Learn Mode narration; receives the narration text only. (US)
- Google— sign-in (OAuth identity); also the likely backend for in-browser dictation in Chrome. (US)
- Neon— PostgreSQL database hosting all stored data (account, notes, metering, billing records). (US)
- Upstash — Redis store holding your raw IP address as a rate-limit key (when configured). (US)
- Vercel— application hosting; serverless functions terminate all requests, and hosting logs/observability run here. (US)
- Y-Sweet— real-time collaboration sync server; receives the live note content while a collaborative session is active. Dormant until collaboration is configured. (US)
- Stripe— payment processing. Dormant until billing is enabled. (US)
We may also disclose data where legally required (for example, in response to a valid legal request), or in connection with a merger, acquisition, or asset sale (we would notify you and this policy would carry over or be updated).
8. International data transfers
We are based outside the EEA/UK, and all the sub-processors above are in the United States. Using Canvas Math therefore involves transferring your personal data to the US. Where a provider is certified under the EU-US Data Privacy Framework (and the UK extension), we rely on that certification. Otherwise we rely on the European Commission’s Standard Contractual Clauses (2021/914), plus the UK International Data Transfer Addendum/IDTA for UK data, supported by a transfer impact assessment. You can request a copy of the relevant safeguards by emailing privacy@canvasmath.com. Status: putting these safeguards in place with every sub-processor is a launch blocker before EEA/UK sign-ups are enabled.
9. Data retention
We are being deliberately honest here, because our current behavior does not yet match a normal retention promise.
- Account and identity (including Google OAuth tokens): retained indefinitely. There is currently no automatic deletion and no self-serve account-deletion control. We will delete on request (Section 11), manually, until the self-serve flow ships.
- Notes, transcriptions, AI responses, and version snapshots: retained indefinitely. “Deleting” a note today only hides it from your list — the underlying content is not actually erased, and historical version snapshots are never pruned. We will hard-delete on request, manually, until the real erasure flow ships. Building automatic and self-serve erasure (with a defined post-deletion purge window) is a launch blocker we are tracking.
- Usage/metering records: retained indefinitely today (no pruning job). When billing goes live, billing-related records will be kept for the applicable statutory tax/accounting period and then purged.
- IP rate-limit data (Upstash):transient — it expires automatically with the rate-limit window. We do not write your IP to our database, and our application logs are not designed to record your IP alongside your identity. Honest caveat: the IP we send to the rate-limit store is the raw, un-truncated address; truncating or hashing it is an improvement we have identified and not yet made.
- Synthesized voice audio: not stored.
- Session cookie: expires per the Auth.js session lifetime.
When we do delete your data at your request, we will also ask our AI providers to purge any copy held within their retention windows, to the extent they support such requests.
10. Security
- In transit: all traffic is over TLS (HTTPS).
- At rest: data is stored in our managed PostgreSQL database (Neon). Note that Google OAuth tokens are stored at rest in that database; protecting them is part of our security program, and we have identified token rotation/erasure as an area to harden.
- Access controls:every note and account operation is scoped to the owning user, so one user cannot read or write another’s data. AI-provider keys and tokens are held only server-side and never reach your browser.
- Platform protections: TLS termination, DDoS mitigation, and web-application-firewall protection are handled by our host (Vercel).
- Program (in progress): we are formalizing a written information-security program and a written data-retention policy. These are not yet complete: as Section 9 describes, retention is currently indefinite with no pruning job, and the security program is still being documented. The amended COPPA Rule requires both to be in place in writing, with a compliance deadline of 22 April 2026; completing them is a tracked launch blocker, and we will update this section to state they are in place once they are.
No system is perfectly secure. We cannot guarantee absolute security, and you use the service understanding that risk.
11. Your rights and how to exercise them
If you are in the EEA or UK, you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability (a machine-readable copy); withdraw consent (where we relied on consent), without affecting prior processing; and to lodge a complaint with your data-protection supervisory authority(and, in the UK, the Information Commissioner’s Office). The AI features make no significant automated decision about you (Section 15).
If you are in California or another US state with a comparable law, you have the right to: know/access the personal information we hold about you; delete it; correct it; obtain a portable copy; opt out of any sale or “sharing” (we do neither); limit the use of sensitive personal information; and not be discriminated against for exercising these rights.
How to exercise any of these rights: email privacy@canvasmath.com from the email tied to your account, or use the in-app data controls once they ship. We verify your identity by reference to your signed-in session and the email on your account.
Honest status of self-serve. A self-serve data-export and account-deletion flow is not built yet. Until it ships, we handle all access, export, correction, and deletion requests manuallyat privacy@canvasmath.com. We do not claim self-serve capability that does not exist. There is a notes-export feature in the app today, but it exports notes cached in your browser — it is a convenience backup, not a complete account export, and does not by itself satisfy a data-access request.
Response times. We aim to respond within one month (GDPR) and within 45 days (CCPA/CPRA), with extensions only where the law allows and with notice to you.
12. Do-Not-Sell/Share and opt-out signals
We do not sell your personal information and do not “share” it for cross-context behavioral advertising, so we are not required to post a “Do Not Sell or Share My Personal Information” link — but you have, and we honor, the right to opt out regardless. Status:we do not yet detect or act on the Global Privacy Control (GPC) browser signal automatically — that detection, and a visible “GPC opt-out honored” confirmation, are part of the consent layer we are building and are not live yet. Until they are, the practical effect is unchanged because we do not sell or share. If we ever introduce any advertising-related sharing, we will honor GPC, add the homepage opt-out link, and surface the GPC confirmation before doing so.
13. Children’s privacy
Canvas Math is a general-audience study tool. It is intended for users aged 13 and older (and 16 and older in the EEA/UK, or the applicable local digital-consent age where lower). It is not directed to children under 13.
We do not knowingly collect personal data from children under that age. Because using the AI features sends content to third-party AI providers, and because we do not operate verifiable parental consent, our intended approach is a neutral age screen at sign-up that blocks underage self-signup rather than collecting more data from minors to verify them.
Honest status: the age screen is not built yet— there is no age gate in the product today. Implementing it is a launch blocker before we open the service to general public or minor traffic.
If we learn that we have collected personal data from a child below the applicable age without the required consent, we will delete it promptly. A parent or guardian can request deletion of a child’s data by emailing privacy@canvasmath.com.
Schools. We do not currently market to, or operate under school-consent agreements with, K-12 schools or under-13 classrooms. If we pursue classroom deployment, we will do so only under a written school agreement that limits use to school-authorized educational purposes, with no advertising or unrelated secondary use, deletion on request, and clear disclosure to the school of exactly what is shared with our AI providers and why.
The amended COPPA Rule requires a written data-retention policy and a written information-security program, with a compliance deadline of 22 April 2026. As noted in Section 10, we are still formalizing both; completing them is a tracked launch blocker regardless of our not-directed status.
14. Data we collect indirectly (GDPR Art. 14)
Some personal data reaches us not from the person it is about, but from one of our users. Under GDPR Art. 14, we tell you the source, what we hold, why, and the notice window that applies.
- Collaboration guests who open a share link. Source: the Canvas Math user who created the share link. When you open a collaboration link without an account, we process the live note content you and others edit during the session (via Y-Sweet) and a transient collaboration cookie that carries only the note and your role (never your real identity), plus your IP address as a rate-limit key for any AI action you trigger. Why: to run the shared session and prevent abuse (Contract / legitimate interests, Art. 6(1)(b)/(f)). The collaboration feature is dormant until configured.
- Third parties named or depicted in a note. Source:the user who wrote the note. Because the canvas is free-form, a user could write another person’s name or personal data into a note, which would then be stored and (if AI is triggered) sent to our AI sub-processors. We ask users not to enter other people’s personal data (see Section 4(b)); where it nonetheless occurs, the user is the source and we process it only to provide the service to that user.
If you are an individual whose personal data reached us this way and you want to know what we hold or ask us to erase it, contact privacy@canvasmath.com. Where Art. 14 applies, we will provide this notice (or act on your request) within one month of becoming aware that we hold your data, consistent with the response times in Section 11.
15. Automated decision-making and AI transparency
Canvas Math uses AI to transcribe, solve, explain, visualize, and narrate math. This processing does not make any decision that produces legal or similarly significant effects on you, so the GDPR Art. 22 / CCPA automated-decision rules on significant decisions do not apply. The AI assists with math; it does not grade, place, admit, or otherwise make a significant decision about you. AI output can be inaccurate — verify it before relying on it, especially for graded work.
16. Cookies and local storage
We use a small number of strictly necessary cookies and browser storage:
- a sign-in session cookie to keep you logged in;
- a collaboration cookie to route a guest into a shared note (it carries only the note and role, never your real identity);
- local storage in your browser to cache your notes so the app works offline-first.
We do not use advertising or cross-site tracking cookies.
17. Changes to this policy
We may update this policy. For material changes we will update the “Last updated” date and version above and, where appropriate, notify you in-app or by email before the change takes effect for you. Continued use after a change means you accept the updated policy, except where your prior consent is still legally required.
18. Contact and complaints
- Privacy and data-rights requests: privacy@canvasmath.com
- General/legal: legal@canvasmath.com
- EEA/UK:you may also lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner’s Office, ico.org.uk).
- California: you may contact the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General (oag.ca.gov).
This policy is intended to be accurate to how Canvas Math works as of the effective date, including its current limitations. It has not been reviewed by a licensed attorney; obtain that review before relying on it for regulated traffic. The launch blockers noted throughout (EU/UK representatives, signed data-processing agreements and transfer safeguards, the age screen, self-serve export/erasure, the granular-consent and GPC layer, the written information-security and data-retention programs, and the completed data-protection impact assessment) must be in place before the service is opened to EU, California, or minor users.