Skip to the content
Subcanvas

Privacy Policy

Effective September 19, 2026

The privacy of your data (and it is your data, not ours!) is a big deal to us. In this policy, we lay out: what data we collect and why; how your data is handled; and your rights with respect to your data. We promise we never sell your data: never have, never will.

This policy applies to this Subcanvas service, which is operated by Trevin Lee ("we", "us"). It applies to our handling of information about site visitors and people with accounts. We refer collectively to these categories of individuals as "you" throughout this policy.

What we collect and why

Our guiding principle is to collect only what we need. Here's what that means in practice:

Identity and access

When you sign up, we ask for your email address, and you can add a name and a profile picture that display in the product. That's so you can personalize your account, the people you work with can tell who is who, and we can send you sign-in links, confirmations, password resets, invitations, and other essential information. If you set a password, it is stored only as a salted hash by our authentication provider; we never see it. We do not send marketing email.

We'll never sell your personal information to third parties, and we won't use your name or company in marketing statements without your permission either.

Sign-in with Google or GitHub

If you choose to sign in with Google or GitHub, we receive your name, email address, and profile picture from that provider, and nothing else. We use them only to create your account, sign you in, and show your name and picture to the people you collaborate with.

We do not request access to any other Google data. We do not use Google user data for advertising, do not sell it, do not use it to train machine-learning models, and do not transfer it to anyone except the providers listed below as needed to run the service, or as the law requires. The same applies to GitHub.

Billing information

If you sign up for a paid plan, you will be asked to provide your payment information and billing address. Credit card information is submitted directly to our payment processor, Stripe, and doesn't hit our servers. We store the Stripe customer and subscription identifiers and the state of your plan, for purposes of account history, invoicing, and billing support.

Product interactions

We store on our servers the content that you create or maintain in your account: whiteboards, documents, folders, projects, and orgs, which orgs you belong to and your role in each, and the email addresses of people you invite. This is so you can use the product as intended. We keep this content as long as your account is active. If you delete your account, we'll delete the content within 60 days. We do not use your content to train machine-learning models.

Public projects and reports

If you make a project public, anyone on the internet with the link can read everything in it. While someone views a document, a random identifier that is not tied to their identity is kept briefly so that others can see how many people are watching. If you report a public project, we keep the reason you give and, if you choose to leave it, your email address, so we can follow up.

General Geolocation data

Our hosting providers log requests to the service by full IP address, along with browser type, the address requested, and the time, for security and fraud prevention purposes. We do not use this to build a profile of you.

Cookies

A cookie is a piece of text stored by your browser. We use first-party cookies to keep you signed in, and your browser's local storage to remember your light or dark theme. We do not use advertising cookies, third-party cookies, or analytics scripts. You can block cookies in your browser settings, although the application won't work if you turn them off.

Voluntary correspondence

When you email us with a question or to ask for help, we keep that correspondence, including your email address, so that we have a history of past correspondence to reference if you reach out in the future.

When we access or disclose your information

To provide products or services you've requested. We use some third-party subprocessors to help run the application and provide the service to you:

Members of your orgs can see your name, email address, and picture, what you create and edit there, and your cursor while you work.

No human looks at your content except for limited purposes with your express permission, for example, if an error occurs that stops an automated process from working and requires manual intervention to fix. These are rare cases, and when they happen, we look for root cause solutions as much as possible to avoid them recurring. We may also access your data if required in order to respond to legal process (see "When required under applicable law" below).

To help you troubleshoot or squash a software bug, with your permission. If at any point we need to access your content to help you with a support case, we will ask for your consent before proceeding.

To investigate, prevent, or take action regarding restricted uses. Accessing a customer's account when investigating potential abuse is a measure of last resort. We want to protect the privacy and safety of both our customers and the people reporting issues to us, and we do our best to balance those responsibilities throughout the process. If we discover you are using our products for a restricted purpose, we will take action as necessary, including notifying appropriate authorities where warranted.

When required under applicable law. This service is operated from the U.S. and all data infrastructure is located in the U.S.

Finally, if the service is acquired by or merges with another company, we'll notify you well before any of your personal information is transferred or becomes subject to a different privacy policy.

Your rights with respect to your information

We strive to apply the same data rights to all customers, regardless of their location. Some of these rights include:

Many of these rights can be exercised by signing in and updating your account information. Please note that certain information may be exempt from such requests under applicable law. For example, we need to retain certain information in order to provide our services to you.

In some cases, we also need to take reasonable steps to verify your identity before responding to a request, which may include, at a minimum, verifying your name and email address. If we are unable to verify you, we may be unable to respond to your requests. If you have questions about exercising these rights or need assistance, please contact us at legal@subcanvas.app. If an authorized agent is corresponding on your behalf, we will need written consent with a signature from the account holder before proceeding.

Depending on applicable law, you may have the right to appeal our decision to deny your request, if applicable. We will provide information about how to exercise that right in our response denying the request. You also have the right to lodge a complaint with a supervisory authority. If you are in the EU or UK, you can contact your data protection authority to file a complaint or learn more about local privacy laws.

How we secure your data

All data is encrypted via SSL/TLS when transmitted from our servers to your browser. Data is encrypted at rest by our database provider, and database rules limit each account to the orgs it belongs to.

What happens when you delete content

Documents you trash stay in the project's trash, where you can restore them, until you delete them for good. If you ask us to delete your account, your content will become immediately inaccessible and should be purged from our systems in full within 60 days.

Data retention

We keep your information for the time necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and your choices, after which time we may delete and/or aggregate it. We may also retain and use this information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Location of site and data

This service is operated in the United States. If you are located in the European Union, UK, or elsewhere outside of the United States, please be aware that any information you provide to us will be transferred to and stored in the United States. By using the service and/or providing us with your personal information, you consent to this transfer.

Children

The service is not meant for children under 13, and we do not knowingly collect their information. If you believe a child has given us information, write to legal@subcanvas.app and we will delete it.

Self-hosted copies

Subcanvas is open source. This policy covers only this service. A copy that someone else runs is governed by their policy, and we receive no information from it.

Changes and questions

We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change to our policies, we will refresh the date at the top of this page and take any other appropriate steps to notify users. See also the Terms of Service.

Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Please get in touch with Trevin Lee by emailing legal@subcanvas.app and we'll be happy to try to answer them!

Adapted from the Basecamp open-source policies / CC BY 4.0