Legal
Privacy Policy
Short version: we collect what the product needs to work and nothing else, we do not sell it, and you can have it deleted by asking.
Last updated 1 September 2026
1. Who is responsible
The data controller for ArchCanvas is Chan Meng, trading as ArchCanvas, contactable at hello@archcanvas.uk. Write to that address for anything in this policy, including a deletion request.
2. What we collect
- Account data — your email address and an account identifier, held so you can sign in and so your work is attached to you. Sign-in is handled by Neon Auth; if you use Google sign-in, we receive an identifier and, usually, your email.
- What you create — your project names, briefs, chat messages with the design agent, the generated floor-plan source and drawings, and any reference or sketch images you upload. We strip the embedded metadata from every image you upload before storing it, including the GPS coordinates a phone camera writes into a photo. We never wanted that data and we do not keep it. The picture itself is stored, so please do not upload photographs containing people you have not asked.
- Credits and purchases — your credit balance and a ledger of grants and spends. If you buy a pack we also store the Stripe session, payment and charge identifiers and the receipt link.
- Product telemetry — counters about how the compiler and the model performed (did the plan compile, how many repair passes, token counts, timings) and a small record of which funnel step an account has reached. These rows hold an account identifier, a timestamp and numbers. They never contain your brief, your chat or your plan.
- Newsletter — only if you subscribe: your email, held by Resend until you unsubscribe.
- Feedback — if you send in-product feedback, your message, your account identifier and email are used to open a tracking issue in our private GitHub repository.
What we do not collect: we do not store card numbers (Stripe does), and there is no advertising or cross-site tracking on this product.
3. Who processes it
To run the service we pass data to a small set of processors, each for one job:
- Neon — the database and the authentication service.
- OpenAI — receives your brief, chat messages, floor-plan source, uploaded reference images and, if you use voice input, the recorded audio, in order to generate and render designs.
- Cloudinary — hosts your uploaded reference images and generated renderings.
- Stripe — takes the payment. Your card details go to Stripe directly and never through us.
- Resend — sends our email: the sign-in and account messages such as verification and password-reset codes, and the newsletter if you subscribed.
- DigitalOcean and Cloudflare — host and front the application; standard server and CDN request logs apply. Cloudflare also stores our nightly database backup, encrypted before it leaves us so that Cloudflare cannot read it. And it counts anonymous page views — across the whole site, not just the public pages — so we can tell how many people arrive and roughly where from. It sets no cookies, records nothing about you personally, and does not track individuals across sites, which is why there is no banner asking you to agree to it.
These providers operate outside your country in some cases, including in the United States. We do not sell your data, and we do not share it with anyone else except where the law requires it.
4. Cookies
We use cookies and equivalent browser storage only to keep you signed in and to remember interface preferences. There are no advertising or analytics cookies.
5. How long we keep it
Your account, projects, designs and uploads are kept until you delete them or ask us to close your account. Payment records are kept for as long as tax and accounting rules require. Telemetry counters are retained indefinitely in aggregate; they are not tied to your content and cannot reconstruct it.
Deleting really deletes. Removing a project removes its designs, its conversation and its uploaded images — including the image files themselves at Cloudinary, not merely our record of them. Closing your account does the same for every project on it. What survives is the credit ledger, because a purchase record is something we are required to keep and is what lets us honour a refund later.
Share links expire. A link you create for a project stops working 180 days after you last shared it. Sharing again renews it, and you can revoke one at any time from the project.
6. Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete your account and its contents. Email hello@archcanvas.uk and we will action it within 30 days. Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to your data protection authority. Deleting your account removes your projects, designs and uploads; anonymous counters and legally required payment records survive it.
7. Security, honestly stated
Data is encrypted in transit, access is limited to the people running the service, and payment card data never reaches our servers. No system is perfectly secure, and ArchCanvas is a small product on modest infrastructure — export anything you would not want to lose, and do not upload material you consider highly sensitive.
8. Children
ArchCanvas is not intended for children. Do not create an account if you are under 16 (or the minimum age in your country, if higher).
9. Changes
If this policy changes, the date at the top changes with it and material changes are announced in-product or by email. See also our Terms of Service.