PRIVACY

What we keep, and what we don’t.

This describes the data CanvasFlow actually stores, written against the database itself rather than from a template. Two different people are covered here: someone with an account, and someone answering a form built by one.

Last updated 31 July 2026

The short version

  • 01We store what you create and what people send you. We don't sell it, and we don't use it to advertise to anyone.
  • 02People answering your forms are not tracked with cookies, and we never record their IP address.
  • 03You can export every response to CSV at any time, and deleting a form or an account really deletes the data underneath it.

The detail below is the whole of it. If the summary and the detail ever disagree, the detail is what we do.

Who is responsible for a response

The form’s owner

They decide what to ask, why, and what to do with the answers. For the responses collected through their form, they are the party responsible — the controller, in data-protection terms. What they ask for is their call, not ours.

CanvasFlow

We store and process those responses on the owner’s behalf, and nothing more. For account data — your email and your sessions — we are the responsible party ourselves.

If you have an account

All of this exists to sign you in and keep your work. Nothing more.

Identity
Your name, email address, whether that email is verified, and a profile image if your sign-in provider supplies one.
Sign-in credentials
Either a password — stored hashed, never in readable form — or the tokens your OAuth provider issues, plus which provider you used.
Sessions
A session token, its expiry, and the IP address and browser user-agent the session was created from. This is how we keep you signed in and how you can tell a stranger's session from your own.
What you build
Your forms: titles, descriptions, questions, options, and settings such as expiry dates and submission caps.
Collaborators
If you share a form, we record who has access, their role, and who added them.
Support reports
If you send feedback or report a bug, we keep the subject and message, your email, and the page URL and browser user-agent from the moment you reported it — the last two are what make a bug reproducible.

If you’re answering a form

You don’t need an account to answer a form, and we don’t create one for you. Here is everything recorded when you do.

Your answers
Everything you type or select, and the time you submitted. These go to the form's owner, who decides what they are for.
Partial answers
Each answer is saved as you move to the next question, so an answer you gave is kept even if you close the form and never submit it. This is what tells an owner which question people give up on.
A per-form identifier
A random value your own browser stores in localStorage — not a cookie — scoped to that single form. It exists only to stop the same browser submitting twice. It cannot link you across different forms or across other websites, and it never leaves your browser except alongside your submission.
Device category
Whether you submitted from a desktop, tablet, or phone. Not a device fingerprint.
How you arrived
The referring page, and any utm_source, utm_medium or utm_campaign values present in the link you followed. This tells the owner which of their channels is working.
Time taken
How long the form was open before you submitted it.

A form’s owner writes their own questions, so a form can ask you for anything they choose. What you type is between you and them — read the form before you answer it.

What we don’t do

These aren’t intentions. Each one is a property of how the product is built.

  • 01No IP address is recorded for people answering a form. IP addresses are only stored for signed-in account sessions.
  • 02No cookies are set on respondents, and no third-party analytics or advertising scripts run on public form pages.
  • 03No cross-form or cross-site identifier. Nothing links a person who answered one form to a person who answered another.
  • 04No page-view or visitor tracking. We removed it — the only records that exist are of answers actually given.
  • 05We do not sell personal data, share it with data brokers, or use responses to train models.

How long we keep it

While your account is open
Forms and their responses are kept until you delete them, because they are the product — an analytics view of a form you deleted last year isn't something we can reconstruct or would want to.
When you delete a form
Its questions, every submission, every partial answer, and the collaborator list are removed with it. This cascades at the database level, so there is no orphaned copy left behind.
When you delete your account
Your forms and everything underneath them are removed, along with your sessions and sign-in credentials. Support reports you sent are kept but detached from your account, so we don't lose the record of a bug while still unlinking it from you.
Sessions
Expire on their own and are removed after expiry.

Encrypted backups may hold a copy for a short window after deletion, which is a consequence of having backups at all. They age out on their own and are not used for anything but recovery.

Who else sees it

Anyone the form’s owner adds as a collaborator can see that form’s responses, at the level their role allows. Owners can also hand ownership to someone else.

Beyond that, we rely on a small number of infrastructure providers to run the service — application hosting, a managed database, and email delivery for things like verification links. They process data only to provide that infrastructure, under contract, and never for their own purposes.

We will disclose data if the law genuinely requires it. If we receive such a request and are permitted to tell you, we will.

Getting your data back

Get a copy
Export any form's full response set to CSV from the analytics view, whenever you like, without asking us.
Correct or delete
Edit or delete forms and responses directly. Deleting your account removes the rest.
If you answered someone's form
The form's owner controls your answers, not us — we hold them on their behalf. Ask them first. If you can't reach them and you contact us, we will help identify the right owner, but we won't hand over or delete another person's response data without a lawful basis for doing so.

Depending on where you live you may have further rights over your personal data, including the right to complain to a supervisory authority. Exercising any of them costs you nothing and we won’t degrade your account for asking.

Security, and who this is for

How it’s protected

Traffic is encrypted in transit. Passwords are hashed, never stored readably. Access to a form’s responses is checked on every request against ownership or an explicit collaborator role. No system is perfect, and we won’t pretend otherwise — but if we ever discover a breach affecting your data, we will tell you rather than wait to be asked.

Children

CanvasFlow isn’t intended for children, and we don’t knowingly create accounts for them. If you believe a child’s personal data has reached us through an account or a form, tell us and we will remove it.

Changes, and reaching us

When we change what we collect, we update this page and move the date at the top. For a change that materially affects your data, we’ll do more than move a date — we’ll tell you.

For anything about your data — a question, a correction, or a deletion request — use the feedback option inside the app, which reaches us directly.