Canopy Privacy Policy
Beta notice. Canopy is in beta. This document is in effect as written and will be refined as the product grows. Material changes will be shown in the app before they take effect. It has not yet been reviewed by legal counsel; that review is planned before general availability.
Effective date: September 8, 2026 Who we are: Canopy is operated by Allen Padilla, sole proprietor ("Canopy," "we"). Contact: privacy@joincanopy.app. Applies to: the Canopy app for iOS and Android, and the joincanopy.app website.
The short version
Your private ideas ("seeds") are private. They live on your device, sync to your account if you sign in, and nothing you write is ever published unless you explicitly release it. We don't sell your data, we don't show ads, and we don't use your ideas to train AI models.
Private content leaves our systems in exactly one situation: when you ask an AI feature to read it. That means tapping Evaluate on a seed, running a Ring (a Heartwood deep-dive report), or asking for your Patterns (a Heartwood summary of your own scorecards). Each of those sends the relevant text to a third-party AI provider, only at that moment, and we tell you again in the app before your first evaluation. Content you choose to make public is screened by the same provider for safety before it goes live.
What we collect
Account data. Your email address, and, if you sign in with Apple or Google (available in the iOS app), the identifier and email those providers share. Your profile: handle, display name, and the optional "background" text you write to unlock the Right for you score.
Trying Canopy before you sign up. You can run one evaluation without creating an account. To do that, the app quietly creates an anonymous account on our servers so your seeds and that scorecard can be saved. Anonymous sessions can't release, score, comment, or do anything public. If you later add an email, the anonymous account becomes your account and nothing is lost. If you don't, it's deleted automatically: after 30 days if it holds no seeds, and after 90 days regardless.
Your seeds (private notes). Stored on your device. If you sign in, they also sync to our servers so you can access them across devices. They are private: not visible to other users, not read by moderation, not used for anything except showing them back to you, with the single exception of the AI features you invoke on them, described below.
Evaluations and Rings. The scorecards, score history, and Ring reports generated for your seeds are stored with your account. If you use "Disagree with a score?", we store which scale you disagreed with, the direction, and any note you add; that feedback is read only for calibrating the evaluator, never shown to anyone else, and never changes a score.
Released content (public). When you deliberately release an idea to the Canopy board, the released title, idea text, and your provenance answer become public, along with your handle and display name. Each released leaf also gets a public web page at joincanopy.app/leaf/… with a preview image, readable by anyone on the web without an account. Comments, comment likes, crowd scores, growth updates, follows, and catches you make on the board are also visible according to the app's own rules. If you connect GitHub and verify a repository as proof for a leaf, your GitHub username and the verified link are shown publicly on that leaf and your profile. Released content is a frozen snapshot; see the Terms for how it behaves.
Activity data. Which leaves you view and catch (viewing is attributed to you only if Incognito browsing is off; it's disclosed in the app and you can turn attributed viewing off at any time), your daily and monthly usage of metered features (evaluations, Rings, Patterns), timestamps of your content-agreement acceptance, and records of reports you file or moderation actions affecting your content. Authors on the Heartwood tier can see the handles of people who caught or viewed their leaf; Incognito browsing removes you from those lists.
Purchase data. Heartwood is sold through Apple's in-app purchase system and managed by RevenueCat, our subscription processor. We receive your entitlement status, the product you bought, its renewal or expiry date, and a RevenueCat customer identifier linked to your account. We never see your payment card or Apple ID password; Apple handles payment. (See "The Android app" below for how this works on Android.)
Technical data. A push notification token (if you enable notifications); crash reports via Sentry (device model, OS version, app version, and a stack trace; your note content, request bodies, and free-form app state are stripped from every report before it leaves the device, and excluding it is an enforced rule in our codebase, not a courtesy); your IP address, used transiently to rate-limit expensive actions (evaluations, releases, view counting) and kept only in short-lived rate-limit counters; and, on iOS, an Apple App Attest device key (a hashed identifier for your device's secure-enclave key, used to count AI usage per device so one phone can't make unlimited accounts; it isn't a serial number and can't identify you outside Canopy). The app also checks Expo's update service for over-the-air app updates; those requests carry the app's platform and runtime version, nothing about you.
Product analytics. The app sends a small set of named usage events to PostHog so we can see whether Canopy works as a product: a seed was created, a first scorecard arrived, a seed was released, the app was opened (with the number of days since install), and the paywall was shown or a purchase completed. Each event carries the device model, OS version, app version, and a random per-install identifier that is not linked to your account, email, or handle. No event ever carries the text of a seed, a title, a handle, or any content you wrote; the event vocabulary is fixed in our codebase and has no field that could hold it. We do not use session recording, screen tracking, or automatic tap capture, and we do not derive your location from your IP address.
Website. joincanopy.app is a static site with no analytics, no cookies we set, and no tracking. Our web host records standard server logs (IP address, browser user agent, requested URL, timestamp) that we use only for operating and securing the site.
What we don't collect: we run no advertising SDKs, we do not access your contacts, location, or photos, and we never log the text of your seeds on our servers; dictation uses your device's own speech recognition, and audio never reaches us; evaluation, Ring, and moderation logs record metadata (timestamps, token counts, outcome categories) only.
AI processing: the part to actually read
All AI features currently use a third-party AI provider, Google (Gemini). Here is exactly what is sent, and when:
- Evaluate. Your seed's title and text (and your background, if you've written one) are sent to produce your scorecard. On the Heartwood tier the same content goes to a more capable model.
- Rings (Heartwood). The idea text of the seed or leaf you choose is sent to produce a deep-dive report (competitor scan, market sizing, risks, validation plan). To research it, the provider runs web searches derived from your idea and reads public web pages; that means search queries based on your idea are made on your behalf. If you run a Ring on your own released leaf, its growth log is included only if you explicitly opt in. The finished report is stored with your account.
- Patterns (Heartwood). Your own scorecards and recorded outcomes are summarized to describe patterns across your ideas. This reads your evaluations, not your raw seed text, and the summary is returned to you rather than stored.
- Safety screening. When you release an idea, post a comment, or log a growth update, that content is screened for safety before it becomes visible.
Some further points:
- This happens only when you take those actions. Private seeds you never evaluate, ring, or release are never sent to an AI provider.
- We use these providers under API terms that do not permit your content to be used to train their models.
- Providers may change (the app is built to support Google, Anthropic, and OpenAI); this policy will name any new provider before it is used.
- We cap our own daily AI spending. When the cap is reached, AI features pause until the next day rather than failing silently; the app tells you.
Where your data lives
Our backend runs on Supabase (database, authentication, file storage, and the server functions that power evaluations, moderation, and the public leaf pages). Push notifications are delivered via Expo's push service and, from there, Apple's (iOS) or Google's (Android) notification systems; Expo also delivers over-the-air app updates. Purchases are processed by Apple and RevenueCat. Crash reporting is Sentry; product analytics is PostHog (hosted in the United States). Sign-in providers you choose (Apple, Google, GitHub) process your authentication per their own policies, and if you connect GitHub we call GitHub's API once to verify the connection and any repository you link; the temporary GitHub token is used for that check and never stored. Reports you file are emailed to our moderator via Resend; those emails contain a preview of the reported content and your report details, so a human can act on them. These are all processors acting on our instructions; we don't sell or rent your data to anyone, ever.
These processors may store and process data outside your country, including in the United States.
The Android app
The Android app is the same product with the same data practices, with a few differences in what's available today:
- Sign-in on Android is by email code only; Sign in with Apple and Google Sign-In are currently offered in the iOS app.
- Purchases are not yet available in the Android app. A Heartwood subscription bought on iOS applies to your Canopy account on every device you sign into, including Android.
- Device attestation (App Attest) is an iOS feature; the Android app doesn't use Google's Play Integrity yet.
- Push notifications on Android are delivered through Google's Firebase Cloud Messaging.
- Depending on how you installed it, the Android app comes from Google Play or as a direct test build; Google Play's own data practices apply to the download itself.
Deletion and your choices
- Delete your account any time from Settings (Privacy & safety). Your private seeds, scorecards, and Ring reports are erased outright. Content you released publicly is replaced with "[deleted]" rather than removed, so other people's comment threads and scores aren't silently corrupted; your scores survive only inside anonymous aggregates. This is irreversible.
- Export your seeds any time from Settings (Notebook), as Markdown or JSON, including each seed's latest scorecard. This is free and always will be. For a copy of anything else we hold about you, email privacy@joincanopy.app and we'll provide it within 30 days.
- Incognito browsing stops attributed view tracking, server-side, immediately.
- Blocking hides you and another account from each other entirely.
- Push notifications can be turned off in the app or in your device's notification settings.
- Anonymous sessions delete themselves on the schedule above.
Retention
Account data, synced seeds, scorecards, and Ring reports are kept while your account exists and deleted with it (public tombstones excepted, as above). Anonymous accounts are deleted after 30 days if empty and after 90 days at most. App Attest challenges are deleted within a day; the device key persists while the device uses Canopy. Rate-limit and usage counters roll over daily or monthly. Crash reports, analytics events, and server logs are retained on our providers' standard rolling windows (typically 90 days). Moderation records (reports, actions, and the moderator emails they generate) are retained for 12 months to enforce our zero-tolerance policy.
Children
Canopy is not for children under 13, and we don't knowingly collect their data.
Your rights
Canopy is operated from Canada, and we handle personal information in accordance with PIPEDA (Canada's Personal Information Protection and Electronic Documents Act): you can ask what we hold about you, ask us to correct it, and withdraw consent (by deleting your account or stopping use), and you may complain to the Office of the Privacy Commissioner of Canada. Depending on where you live (e.g., EEA/UK GDPR, California CCPA), you may have additional rights to access, correct, delete, or port your data, and to object to processing. The in-app tools above cover most of these directly; for anything else, contact privacy@joincanopy.app. We don't discriminate for exercising rights, and we have no "sale" or "sharing" of personal information to opt out of.
Changes
We'll post changes here with a new effective date, and for material changes we'll tell you in the app before they apply.