Legal

Privacy notice

What we collect, when we collect it and why. Canvas is a WordPress theme, so most of what it does happens on your own server and never reaches us.

Last updated .

1. Who we are

Canvas is published by SemiColonWeb, which is the controller of the information described here.

This notice covers three things: this website, your Canvas dashboard account, and the parts of the Canvas theme and plugin that talk to our servers. It does not cover the WordPress site you build with Canvas. There you are the controller, and the data your visitors leave stays in your own database.

2. This website

There are no accounts on canvaswp.com, no forms and nothing to sign in to. The only data collected here is usage measurement through Google Analytics 4, with anonymised usage data.

That means the pages you view, how you arrived, an approximate location derived from a truncated IP address, and your device and browser type. It is used in aggregate to see which pages help and which do not. We do not use it to identify you and we do not sell it.

3. Your dashboard account

Buying Canvas creates an account on your dashboard. It holds:

  • The details you give when you register, which are your name and your email address, with your password stored in hashed form.
  • Your purchases, your plan, your renewal dates and your invoices.
  • Your licence keys and the sites each key is activated on.
  • Anything you post in the support forum, which is tied to your account.

Payments are handled by our payment provider. Card numbers and bank details never reach our servers. We receive confirmation that a payment succeeded, along with the billing details that appear on your invoice.

4. What a licensed WordPress site sends

When you activate a licence key, and periodically afterwards when the licence is checked, your WordPress site sends us:

  • The licence key.
  • The site domain.
  • An instance identifier that tells one installation apart from another, so a staging copy is not mistaken for a new site.
  • The Canvas theme version, the Canvas Core plugin version and the WordPress version.

That is what counting seats and offering the right update need, and it is all that is sent. Your pages, your posts, your media, your visitors, your user accounts and the rest of your database stay on your server.

We record the result of each check so that we can support your account and detect misuse of a key.

5. Canvas AI

Canvas AI only runs when you ask it to. When you generate or improve something, your site sends:

  • The text you asked it to write or improve, or the prompt you typed.
  • The settings you chose, such as tone, audience and image size, together with the business description and audience you saved in Theme Options.

Requests pass through the Canvas API and on to the AI model provider that generates the result. We count the credits used against your plan. Generated images are saved straight into your own media library.

Nothing else on your site is sent. Because prompts leave your server, do not paste personal data or confidential material into an AI field.

6. Demo package downloads

When you import a demo, your site asks our API for the package. The request carries your licence key and site identifier, and what comes back is a signed link that expires after a short time and is tied to your licence.

We record which demo was requested and when, for support and to detect abuse of the download service.

7. Cookies

  • This website sets the cookies Google Analytics needs to count a visit and to tell a returning browser from a new one. There are no advertising cookies and no cross-site tracking pixels here.
  • The dashboard sets a session cookie so that you stay signed in. It is required for the dashboard to work at all.
  • Your own site is yours. Canvas does not add advertising or cross-site tracking cookies to the sites you build with it.

You can block or delete cookies in your browser settings. Blocking analytics cookies has no effect on how this website works.

8. How long we keep it

  • Account and purchase records are kept while your account exists, and afterwards for as long as tax and accounting law requires us to keep them.
  • Licence activation and check records are kept while the licence is active and for a limited period afterwards, for support and abuse prevention.
  • Analytics data is kept for the retention period set in our Google Analytics account.
  • AI prompts and results are processed to produce your result and to count your credits. The model provider's own retention terms apply to the request it receives.

9. Your rights

Depending on where you live, you have the right to ask for a copy of the personal data we hold about you, to have it corrected, to have it deleted, to receive it in a portable form, and to object to or restrict how we use it.

To exercise any of them, ask from the account that holds the data in the support forum. We will need to be sure the request comes from you before we act on it.

If you ask us to delete your account, we delete your account and personal details apart from the records that tax and accounting law requires us to keep. Deleting an account also ends its licences.

You can also complain to the data protection authority in your country if you think we have handled your data badly.

10. Changes to this notice

We update this notice when the product changes, for example when a new service starts sending or storing something. The date at the top of the page shows the current version, and changes that matter are noted in the changelog.

11. Contact

Privacy questions go to the support forum. Every route is listed on the contact page. The wider agreement is the Terms of Service.