Who is responsible
CANOPY digital is an Ontario-based engineering studio and the organization responsible for the personal information described here. Privacy questions, access requests, corrections, and complaints can be sent to hello@canopydigital.ca.
Information we collect
We collect information you provide, information needed to operate an account or workspace, and limited technical records needed to secure and improve the service.
- Account details such as your name, email address, profile image, preferences, and linked sign-in provider identifiers.
- Workspace content such as projects, conversations, prompts, files, research requests, SEO inputs, and saved library items.
- Operational records such as route receipts, model/provider selection, token usage, run timing, errors, security events, and consent choices.
- Project-intake, support, and billing details. Stripe processes payment-card data; CANOPY digital does not store complete card numbers.
How we use information
We use personal information to create and secure accounts, provide requested workspace and AI features, preserve projects and conversations, process subscriptions, respond to support or project requests, prevent abuse, diagnose failures, and meet legal obligations.
Sign-in, service providers, and AI routing
If you choose a third-party sign-in method, Google, GitHub, Microsoft, or X provides the identity information needed for that sign-in. Stripe provides payment processing. AI requests may be sent to the model provider identified in the route receipt for that run, including providers operating outside Canada.
We send the minimum information reasonably needed for the selected feature. Provider processing is also governed by that provider’s terms and privacy practices. A Canadian-controlled service does not guarantee Canada-only inference.
Storage, safeguards, and retention
Signed-in Canadian Fusion account and workspace records are stored in encrypted EFSDB storage outside the public web root. Browser storage may temporarily hold local preferences or unsigned-in drafts. We use access controls, secret isolation, transport encryption, and operational logging appropriate to the sensitivity of the information.
We keep information while it is needed to provide the service, protect accounts, resolve disputes, or meet legal requirements. Retention can vary by record type. Deletion requests may be subject to security, billing, backup, and legal retention requirements.
Your choices and rights
You may request access to or correction of your personal information, ask about its use and disclosure, withdraw optional consent, ask us to unlink a sign-in provider when another sign-in method remains, or request account deletion. We may need to verify your identity before completing a request.
Updates and children
The services are intended for people who can form a binding agreement and are not directed to children. We may update this policy as the product, providers, or legal requirements change; the effective date above identifies the current version.