Skip to content
Canonopy Decisions
Draft — review with counsel before launchText in [square brackets] is a placeholder to be filled in. Nothing here is final.

Privacy Policy

Last updated 25 September 2026

The short version: your data is used only for your own models. We never pool it with other customers' data and never use it for anyone else's models or our own without your written permission. You can ask us to delete it at any time.

1. Who we are

[Company legal name], [registered address], runs Canonopy Decisions. For your account details (who you are and how to reach you) we decide how the data is used. For the data you send us to make decisions, we act on your behalf and follow your instructions. [controller / processor wording and data processing agreement: counsel to confirm]

Questions or requests: [contact email].

2. What we keep

WhatWhyHow long
Account detailsYour organisation's name, the email addresses and roles of your users, sign-in times. For API keys we keep only a fingerprint, never the key itself.While your workspace is open, then deleted as described below.
Past cases you uploadTo make and improve your own model.Until you ask us to delete them or close your workspace.
Decisions and their outcomesThe states and messages you send, our answers, and the outcomes you report. Kept so you can look back at them (the decision log) and to improve your own model (for example, the unsure queue and later versions).90 days by default. You choose 30, 90 or 365 days, or until you delete them, in the console's Settings; older decisions are deleted once a day. You can also delete them yourself at any time.
Cases from your downloaded modelsOnly when you sync them: the cases a model running on your own machines couldn't send us while offline (the case, the questions, its answers and when it decided). Stored like your other decisions, for your unsure queue and later versions. Until you sync, they stay in a file on your machine that you can read or delete.As your other decisions: 90 days by default, or the period you choose.
Model versionsSo you can compare, promote, roll back and download them.Until you ask us to delete them or close your workspace.
LogsRequest details (time, IP address, endpoint, status, errors) to keep the service secure and working.About 30 days.
BackupsTo recover from failures.About 30 days, on a rolling basis.
Payment recordsInvoices and payment status. Card details are handled by Stripe; we never see your full card number.As long as tax and accounting law requires.
Waitlist sign-upsYour email, to contact you about access.Until you ask us to remove it, or access opens and you sign up.
Visits to this websiteWe count visits with our own analytics, without cookies: the page, the site that sent you here, the kind of device and browser, and steps such as trying the demo or signing up. Never what you type. We don't store your IP address, and the anonymous visitor count resets every day, so a visit can't be tied to you or to your visits on other days. If your browser sends Do Not Track or Global Privacy Control, we don't count your visit at all.Up to 400 days.

3. How we use it

  • To run the service for you: make decisions, make and improve your own models, show you reports.
  • To keep the service secure: spot abuse, enforce the fair-use rate limit, investigate problems.
  • To bill you and to send you sign-in links and important notices about your account.

Your data is used only for your own models. We never pool it with other customers' data, and we never use it for other customers' models or for our own models, unless you give us written permission. We don't sell personal data and we don't use it for advertising.

4. Sub-processors

These companies help us run the service and may process your data for that purpose only:

WhoWhat forWhat they receive
Render (US)Hosting the website, console and API.Everything the service stores and processes, as our host.
Our database host [Supabase / Postgres provider, region, if used]Storing account details and workspace data.What the service stores.
StripePayments and invoices.Billing contact and payment details. Not your cases or decisions.
Our email provider [Resend or Postmark]Sign-up and sign-in emails.The email address and the link we send.
Anthropic (Claude)Helps prepare a starter model from your set-up description. Backup AI provider for decisions your own model is still unsure about, when we use it for that.For a starter model (decisions on text, once at set-up): your decision's short description, the question, its options and their descriptions, your text fields' names and the languages you work in. No past cases, decisions or other workspace data. As the backup, only when your own model is still unsure after a message was translated to English: the question, its options, the case as you sent it, and the rules of yours that apply to it. Nothing else from your workspace. Its answers are kept with the decision and help your own model learn. A self-hosted open model may replace it as the backup.
TypeSafe AI (Jev)Backup AI provider for decisions your own model is still unsure about, when we configure it for that (with our own TypeSafe account, not yours).Only when your own model is still unsure after a message was translated to English: the question, the options your rules allow for that case, and the case as you sent it. No rules text and nothing else from your workspace. Its answers are returned to you, kept with the decision and help your own model learn, as with the other backup provider. Your real outcomes and your answers in the unsure queue always take precedence.

If you connect your own day-one backend (your own key for another AI service), we send decisions to that service on your behalf; it is your choice and covered by your agreement with it, not listed here.

Before we add or replace a sub-processor, we'll give notice on this page and by email, at least [30] days in advance, so you can object or cancel.

5. Deleting your data

  • Ask us at [contact email], or close your workspace. We delete your data within 30 days. Copies in backups roll off within a further 30 days.
  • You can archive a decision model at any time, which stops it being served.
  • You can delete your uploads yourself, one at a time or all at once, in the console or through the API. Their cases are deleted from our database straight away; copies in backups roll off within 30 days. Model versions already trained from them are kept until you ask us to delete them.
  • Decisions are kept for your workspace's retention period: 90 days unless you choose 30 or 365 days, or to keep them until you delete them (console Settings, or the API). Once a day, decisions older than that are deleted from our database, including those with outcomes or answers from the unsure queue; later versions of your model no longer learn from them, while versions already trained are kept. You can also delete one decision, or every decision before a date, yourself in the console or through the API, and export them first (CSV or JSON Lines). Copies in backups roll off within 30 days.
  • Deleting a decision model or its model versions is done on request for now: ask us at [contact email].
  • Models you have downloaded are yours and are not affected: we can't reach them.
  • Payment records are kept as long as the law requires, even after the rest is deleted.

6. Security

Traffic is encrypted in transit. API keys are stored only as fingerprints. Access to customer data is limited to the people who need it to run the service. If a breach affects your data, we'll tell you without undue delay. [security details and breach notice period]

7. Where data is processed

The service is hosted in the United States. If you send us data from elsewhere, it is transferred there. [transfer safeguards, e.g. standard contractual clauses]

8. Your rights

Depending on where you live, you may have the right to see, correct, export or delete personal data we hold about you, and to object to how we use it. Write to [contact email]. If your data reached us through one of our customers (for example, a support message you sent to a company that uses us), please contact that company first; we'll help them respond. You may also complain to your data protection authority.

9. Cookies and local storage

The console uses one essential cookie to keep you signed in. The website remembers your light or dark theme in your browser's local storage. We don't use advertising cookies. We count visits to the website with our own cookieless analytics: no cookies, no stored IP addresses, and nothing at all when your browser sends Do Not Track or Global Privacy Control (see What we keep, above).

10. Children

The service is for organisations and is not meant for children. [minimum age]

11. Changes to this policy

If we change this policy in a way that matters, we'll email you before the change takes effect and update the date at the top. See also the Terms of Service.

Also see: Terms of Service · Acceptable Use Policy