What we keep,
and what we don’t.
This describes the data CanvasFlow actually stores, written against the database itself rather than from a template. Two different people are covered here: someone with an account, and someone answering a form built by one.
Last updated 14 September 2026
The short version
- 01We store what you create and what people send you. We don't sell it, and we don't use it to advertise to anyone.
- 02No analytics or advertising scripts run on a public form. Answering one sets nothing beyond what it takes to stop abuse and to stop the same browser submitting twice.
- 03You can export every response to CSV at any time, and deleting a form or an account really deletes the data underneath it.
The detail below is the whole of it. If the summary and the detail ever disagree, the detail is what we do.
Who is responsible for a response
The form’s owner
They decide what to ask, why, and what to do with the answers. For the responses collected through their form, they are the party responsible — the controller, in data-protection terms. What they ask for is their call, not ours.
CanvasFlow
We store and process those responses on the owner’s behalf, and nothing more. For account data — your email and your sessions — we are the responsible party ourselves.
If you have an account
All of this exists to sign you in and keep your work. Nothing more.
If you’re answering a form
You don’t need an account to answer a form, and we don’t create one for you. Here is everything recorded when you do.
A form’s owner writes their own questions, so a form can ask you for anything they choose. What you type is between you and them — read the form before you answer it.
Keeping the service standing
A public form is a public endpoint, so some of it has to be defended. Three things are processed for that reason and no other. None of them reaches a form’s owner.
What we don’t do
These aren’t intentions. Each one is a property of how the product is built.
- 01No IP address is stored with a form response, and no owner is ever shown one. Addresses appear only in your own account sessions and in the short-lived rate-limit counters described above.
- 02No analytics, advertising, or third-party tracking scripts run on a public form page. The only cookie a respondent meets is our own rate-limiting one.
- 03No cross-form or cross-site identifier. Nothing links a person who answered one form to a person who answered another.
- 04No page-view or visitor tracking. We removed it — the only records that exist are of answers actually given.
- 05We do not sell personal data, share it with data brokers, or use responses to train models.
How long we keep it
Encrypted backups may hold a copy for a short window after deletion, which is a consequence of having backups at all. They age out on their own and are not used for anything but recovery.
Who else sees it
Anyone the form’s owner adds as a collaborator can see that form’s responses, at the level their role allows. Owners can also hand ownership to someone else.
Beyond that, we rely on a small number of infrastructure providers to run the service: application hosting, a managed database, a cache, a media host that stores the files people attach to a form, and email delivery for things like password reset links. They process data only to provide that infrastructure, under contract, and never for their own purposes.
Menti runs as its own service. If you present with it, the deck and the answers your audience gives are held there rather than alongside your forms, and the two are not joined up.
We will disclose data if the law genuinely requires it. If we receive such a request and are permitted to tell you, we will.
Getting your data back
Depending on where you live you may have further rights over your personal data, including the right to complain to a supervisory authority. Exercising any of them costs you nothing and we won’t degrade your account for asking.
Security, and who this is for
How it’s protected
Traffic is encrypted in transit. Passwords are hashed with a slow, salted algorithm and never stored readably. Session tokens are held in cookies your browser won’t hand to a script. Access to a form’s responses is checked on the server on every request, against ownership or an explicit collaborator role, so a link alone never grants it. No system is perfect, and we won’t pretend otherwise — but if we ever discover a breach affecting your data, we will tell you rather than wait to be asked.
Children
CanvasFlow isn’t intended for children, and we don’t knowingly create accounts for them. If you believe a child’s personal data has reached us through an account or a form, tell us and we will remove it.
Changes, and reaching us
When we change what we collect, we update this page and move the date at the top. For a change that materially affects your data, we’ll do more than move a date — we’ll tell you.
CanvasFlow is operated by DevClub NST.
For anything about your data — a question, a correction, or a deletion request — write to [email protected], or use the feedback option inside the app. Either reaches us directly.