PRIVACY

What we keep, and what we don’t.

This describes the data CanvasFlow actually stores, written against the database itself rather than from a template. Two different people are covered here: someone with an account, and someone answering a form built by one.

Last updated 14 September 2026

The short version

  • 01We store what you create and what people send you. We don't sell it, and we don't use it to advertise to anyone.
  • 02No analytics or advertising scripts run on a public form. Answering one sets nothing beyond what it takes to stop abuse and to stop the same browser submitting twice.
  • 03You can export every response to CSV at any time, and deleting a form or an account really deletes the data underneath it.

The detail below is the whole of it. If the summary and the detail ever disagree, the detail is what we do.

Who is responsible for a response

The form’s owner

They decide what to ask, why, and what to do with the answers. For the responses collected through their form, they are the party responsible — the controller, in data-protection terms. What they ask for is their call, not ours.

CanvasFlow

We store and process those responses on the owner’s behalf, and nothing more. For account data — your email and your sessions — we are the responsible party ourselves.

If you have an account

All of this exists to sign you in and keep your work. Nothing more.

Identity
Your name, email address, whether that address has been confirmed, and a profile image if your sign-in provider supplies one.
Sign-in credentials
Either a password — stored hashed, never in readable form — or the tokens your OAuth provider issues, plus which provider you used.
Sessions
A session token, its expiry, and the IP address and browser user-agent the session was created from. This is how we keep you signed in and how you can tell a stranger's session from your own. Sessions last seven days.
What you build
Your forms: titles, descriptions, questions, options, segments, branching rules, and settings such as the closing date and who is allowed to answer.
Collaborators
If you share a form, we record who has access, their role, and who added them.
Live presentations
If you use Menti, your decks and the answers your audience gives are held by a separate presentation service rather than alongside your forms.
Support reports
If you send feedback or report a bug, we keep the subject and message, your email, and the page URL and browser user-agent from the moment you reported it — the last two are what make a bug reproducible.

If you’re answering a form

You don’t need an account to answer a form, and we don’t create one for you. Here is everything recorded when you do.

Your answers
Everything you type or select, and the time you submitted. These go to the form's owner, who decides what they are for.
Files you attach
If the form asks for a file, its contents, name, type, and size are stored with your response and handed to the owner. A file you pick but never submit is not attached to anyone's response.
A saved draft
On a form that requires signing in, your answers so far and your position in the form are saved against your account as you go, so a closed tab doesn't lose your progress. It is replaced by your submission when you send it.
Your account and email
Only if the owner turned it on. A form can be set to require signing in, to record the respondent's account email with the response, to allow one response per account, or to accept only certain email domains. On a form with none of those switched on, you answer anonymously.
A per-form identifier
A random value your own browser stores in localStorage — not a cookie — scoped to that single form. It exists only to stop the same browser submitting twice. It cannot link you across different forms or across other websites, and it never leaves your browser except alongside your submission.
Device category
Whether you submitted from a desktop, tablet, or phone. Not a device fingerprint.
How you arrived
The referring page, and any utm_source, utm_medium or utm_campaign values present in the link you followed. This tells the owner which of their channels is working.
Time taken
How long the form was open before you submitted it.

A form’s owner writes their own questions, so a form can ask you for anything they choose. What you type is between you and them — read the form before you answer it.

Keeping the service standing

A public form is a public endpoint, so some of it has to be defended. Three things are processed for that reason and no other. None of them reaches a form’s owner.

A rate-limiting cookie
Requests to our API carry a random cf_visitor_id, set by us and readable only by us. It holds no information about you and is used for one thing: counting requests so a script can't flood the service. It is not written into any response.
Your IP address, briefly
Rate limits are also counted against the address a request came from, because that is the one identifier a script cannot simply change. Those counters live in a short-lived cache keyed on the address and roll over on the minute. Your IP address is never written into a form response and never shown to a form's owner.
Duplicate suppression
A submission carries a one-time key generated by your own browser so that a double-click or a retried request is recorded once rather than twice.

What we don’t do

These aren’t intentions. Each one is a property of how the product is built.

  • 01No IP address is stored with a form response, and no owner is ever shown one. Addresses appear only in your own account sessions and in the short-lived rate-limit counters described above.
  • 02No analytics, advertising, or third-party tracking scripts run on a public form page. The only cookie a respondent meets is our own rate-limiting one.
  • 03No cross-form or cross-site identifier. Nothing links a person who answered one form to a person who answered another.
  • 04No page-view or visitor tracking. We removed it — the only records that exist are of answers actually given.
  • 05We do not sell personal data, share it with data brokers, or use responses to train models.

How long we keep it

While your account is open
Forms and their responses are kept until you delete them, because they are the product — an analytics view of a form you deleted last year isn't something we can reconstruct or would want to.
When you delete a form
Its questions, segments, branching rules, every submission, every saved draft, every uploaded file, and the collaborator list are removed with it. This cascades at the database level, so there is no orphaned copy left behind.
When you delete your account
Your forms and everything underneath them are removed, along with your sessions and sign-in credentials. Support reports you sent are kept but detached from your account, so we don't lose the record of a bug while still unlinking it from you.
Sessions and links
Sessions expire on their own after seven days and are removed after expiry. A password reset link is valid for one hour and works once.
Rate-limit counters
Held in a cache for the length of the limit window — a minute or so — and then gone. They are never copied into the database.

Encrypted backups may hold a copy for a short window after deletion, which is a consequence of having backups at all. They age out on their own and are not used for anything but recovery.

Who else sees it

Anyone the form’s owner adds as a collaborator can see that form’s responses, at the level their role allows. Owners can also hand ownership to someone else.

Beyond that, we rely on a small number of infrastructure providers to run the service: application hosting, a managed database, a cache, a media host that stores the files people attach to a form, and email delivery for things like password reset links. They process data only to provide that infrastructure, under contract, and never for their own purposes.

Menti runs as its own service. If you present with it, the deck and the answers your audience gives are held there rather than alongside your forms, and the two are not joined up.

We will disclose data if the law genuinely requires it. If we receive such a request and are permitted to tell you, we will.

Getting your data back

Get a copy
Export any form's full response set to CSV from its Responses tab, whenever you like, without asking us.
Correct or delete
Edit or delete forms and responses directly. Deleting your account removes the rest.
If you answered someone's form
The form's owner controls your answers, not us — we hold them on their behalf. Ask them first. If you can't reach them and you contact us, we will help identify the right owner, but we won't hand over or delete another person's response data without a lawful basis for doing so.

Depending on where you live you may have further rights over your personal data, including the right to complain to a supervisory authority. Exercising any of them costs you nothing and we won’t degrade your account for asking.

Security, and who this is for

How it’s protected

Traffic is encrypted in transit. Passwords are hashed with a slow, salted algorithm and never stored readably. Session tokens are held in cookies your browser won’t hand to a script. Access to a form’s responses is checked on the server on every request, against ownership or an explicit collaborator role, so a link alone never grants it. No system is perfect, and we won’t pretend otherwise — but if we ever discover a breach affecting your data, we will tell you rather than wait to be asked.

Children

CanvasFlow isn’t intended for children, and we don’t knowingly create accounts for them. If you believe a child’s personal data has reached us through an account or a form, tell us and we will remove it.

Changes, and reaching us

When we change what we collect, we update this page and move the date at the top. For a change that materially affects your data, we’ll do more than move a date — we’ll tell you.

CanvasFlow is operated by DevClub NST.

For anything about your data — a question, a correction, or a deletion request — write to [email protected], or use the feedback option inside the app. Either reaches us directly.