← Back to AI Canvas

Privacy Policy

Last updated: April 5, 2026

AI Canvas ("we," "us," or "our") operates this web application (the "Service"). This Privacy Policy explains what information we collect when you use AI Canvas, how we use it, and your rights regarding that information.

1. Information We Collect

Account Information. When you register for an account, we collect your username and optionally your email address. Passwords are stored as salted cryptographic hashes — we never store your password in plain text.

Project Data. Canvas content you create and save is stored on our server and associated with your account. This includes project names, section text, and canvas type selections.

Session Data. We use server-side session tokens (stored in a local file) to keep you logged in. Sessions expire automatically after a period of inactivity.

AI Inputs. When you use AI-powered features (Restate with AI, Generate from all fields), the text you have entered in canvas sections is transmitted to a third-party AI provider for processing. Please do not enter sensitive personal information in canvas fields.

Usage Logs. Our server logs basic request information (IP address, timestamp, HTTP method and path) for security and debugging purposes. These logs are not shared with third parties.

2. How We Use Your Information

We do not use your information for advertising, behavioral profiling, or any purpose unrelated to operating this Service.

3. Third-Party AI Services

AI Canvas routes AI requests to third-party large language model providers. Text you submit for AI processing is governed by the terms and privacy policies of those providers. We do not control how third-party AI providers store or use submitted text. Do not include confidential, sensitive, or personally identifiable information in AI prompts.

4. Data Storage and Security

Your account data and project files are stored on a server operated by IMB Innovation. We take reasonable precautions to protect this data, including password hashing, session token management, and server-level access controls. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

5. Data Retention

Your account and project data are retained for as long as your account is active. If you request account deletion, your user record and associated project files will be removed. Server logs are retained for a limited period for security purposes and then deleted.

6. Account Administration

Administrators can view usernames, email addresses, account status, and creation dates. Administrators cannot view your password or the content of your canvas projects. Administrators may approve, reject, or delete accounts.

7. Children's Privacy

This Service is not directed to children under 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected such information, we will delete it promptly.

8. Your Rights

You may request access to, correction of, or deletion of your account data by contacting the administrator. You may also delete individual projects at any time from within the application.

9. External Links

The Service may include links to external sites. We are not responsible for the privacy practices or content of those sites.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects when changes were last made. Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

11. Contact

Questions about this Privacy Policy may be directed to the IMB Innovation Team through imb.org.