1. Scope and operator
This policy applies to structcanvas.com and its visual business-planning workspace. “StructCanvas,” “we,” and “us” refer to the service operator. Until the formal operator details are published here, the product must be treated as a private beta rather than a completed commercial service. Privacy questions can be sent to privacy@structcanvas.com.
2. Information we handle
- Account data: name, email address, password verifier, verification state, workspace membership, roles, and preferences.
- Workspace content: project titles, descriptions, graph nodes and relationships, budgets, notes, drawings, comments, revisions, and sharing settings supplied by users.
- Service and security data: request timestamps, hashed network/browser signals, rate-limit counters, audit events, errors, and operational logs.
- Billing data: Stripe customer/subscription identifiers, selected plan, and subscription state. Full card numbers are entered on Stripe-hosted pages and are not stored by StructCanvas.
- Optional analytics: approved product events and a temporary session identifier only after analytics consent. Sensitive project content is excluded from analytics properties.
3. Why we use information
We use information to authenticate users, save and recover projects, enforce workspace permissions and plan limits, provide requested AI features, process subscriptions, deliver account and invitation messages, prevent abuse, support users, and understand consented product usage. StructCanvas does not sell personal information or use private plan content for targeted advertising.
4. AI processing
When a user requests AI generation, StructCanvas sends the prompt, budget, and relevant structured graph context to OpenAI. Users should not include unnecessary sensitive or regulated personal data. AI output can be inaccurate and must be reviewed before financial, legal, hiring, or operational decisions.
5. Service providers
The current service uses Vercel for the website and related operational delivery, Cloudflare Workers and D1 for the application API and database, OpenAI for requested AI generation, and Stripe for subscription billing. Cloudflare Email Routing forwards the listed support addresses. Production outbound transactional delivery is not considered active until its sending-domain setup is completed.
6. Retention and recovery
Active projects remain until the account owner deletes them. Projects moved to Trash are scheduled for permanent deletion after 30 days. Project-revision counts depend on the workspace plan. Expired sessions, used authentication links, invitations, and rate-limit records are removed through scheduled maintenance. Operational provider logs and backups follow provider-controlled retention. Users should export independent copies of business-critical plans.
7. Security
StructCanvas uses HTTPS, secure HttpOnly session cookies, salted password verifiers, server-side authorization, rate limits, signed Stripe webhooks, restricted server-side secrets, audit logs, and origin checks. No online service can guarantee absolute security. Security reports can be sent to security@structcanvas.com.
8. Your choices and requests
Account settings let users update their profile and password, export projects, choose optional analytics, and delete their account and owned workspaces. Depending on location, additional access, correction, deletion, restriction, portability, or objection rights may apply. Submit a request through the contact form or email the privacy address above.
9. Children and changes
StructCanvas is a business-planning service and is not directed to children under 13. Material policy changes will be presented through the service or account email when delivery is available.
Last updated: August 22, 2026.