Private by design
Your seeds are yours.
The whole product depends on you writing your realest ideas down. That only works if the notebook is genuinely private — so these aren’t policies that could change with a settings toggle. They’re how Canopy is built.
-
Private by default
A seed is yours alone until the moment you release it. There is no “almost public”, no discovery feed of drafts, no visibility slider to get wrong.
Your notebook lives on your device and syncs to your account. On the server, row-level security lets exactly one account read a private seed: yours. There is no public read path to build a leak on.
-
Nothing is ever released for you
You release an idea. The app never does it on your behalf — not after an evaluation, not after inactivity, not as a default you forgot to untick.
Releasing is its own deliberate flow: you see exactly what will become public, you answer the provenance question yourself, and only that explicit action can create a public leaf. No background job, sync pass, or setting publishes anything.
-
Private seeds are never read by moderation
There is no queue where a person reviews your notebook. Moderation applies to what you chose to make public — never to what you didn’t.
When an automated safety check runs on a private seed, what Canopy keeps is a category and a timestamp — never your words. The moderation tooling has nothing else to read, because nothing else is stored.
-
Never used to train AI models
Your ideas are not training data. Not for Canopy’s benefit, not for anyone else’s.
Canopy trains no models. Scoring uses third-party AI providers under API terms that do not permit training on your content, and your seed’s text is sent only when you tap Evaluate — the app tells you so before your first evaluation, and the privacy policy names the provider.
-
Exportable, anytime, free
Everything you have written, out in one tap, in a format you can actually read somewhere else. Leaving is always allowed — that’s what makes staying a choice.
Export lives in the app, free, as Markdown or JSON — your seeds and their scorecards, handed to the share sheet, saved wherever you want. No paywall will ever be put in front of it.
-
Releasing is a deliberate act — and a permanent record
When you do go public, the idea text freezes at release, so every score anyone gives is about the exact words they read. Your timestamped provenance is part of the leaf.
A released leaf cannot be quietly edited — the database refuses it, not just the interface. Updates happen in the open, as growth log entries on the leaf’s timeline.
The one time a private seed’s text leaves Canopy’s systems: when you tap Evaluate, it is sent to an AI provider to be scored, and the app says so in plain words before your first evaluation. The details — and the provider’s name — are in the privacy policy.