CANON

Privacy

Last updated: August 12, 2026 · Operated by VaultSpark Studios LLC

This notice describes CANON's current private-beta data practices across the website and mobile clients. Authentication is in a hybrid transition: web sign-in uses Obelisk Passport, while web account creation and current mobile authentication use Supabase.

1. Data CANON stores

CANON stores account and profile information, including your email address, username, display name, biography, avatar, privacy settings, and subscription state. It also stores the Canon content you create: favorites, rankings, ratings, notes, lists, follows, activity, predictions, and other product interactions.

When you use identity or discovery features, CANON may store generated artifacts such as Taste DNA dimensions, archetypes, recommendations, compatibility results, and genealogy or memory-related results needed to show those features again.

2. Public and private content

Public profiles and public Canon entries can be viewed by other people, exposed through public feeds or agent-readable surfaces, and indexed by search engines. Profile visibility and Ghost Mode control whether profile content is presented publicly. Do not put sensitive personal information in content you choose to make public.

3. How data is used

Data is used to operate account and social features, preserve your curated Canon, generate requested identity and discovery features, process billing, provide support, protect the service, and understand product performance. AI-generated results may be incomplete or inaccurate and are product output, not professional advice.

4. Service providers

Supabase provides current database, file-storage, session, and parts of the authentication system. Obelisk Passport handles the current web sign-in entry point and bridges verified identity into the CANON session. Stripe handles paid subscription checkout and billing-portal requests.

When the relevant feature is invoked and configured, CANON sends bounded feature requests to Anthropic for generated text and to Voyage AI for embeddings. Catalog searches and enrichment can query providers such as TMDB, Spotify, Google Books, and IGDB. Identified product events are sent to PostHog only when analytics is configured; CANON does not enable anonymous PostHog capture or session replay in its lightweight web adapter.

5. Cookies and local device storage

CANON uses cookies for Supabase sessions, the signed Obelisk identity handoff, and your selected theme. The web and mobile experiences also use local device storage for interface preferences and dismissible product prompts. Disabling required session storage can prevent account features from working.

6. Exports, correction, and deletion

You can update profile and visibility settings in the product. Settings → Account provides a JSON account export. Account deletion uses a 30-day grace period before permanent removal, as described in the Terms of Service.

7. Security and beta availability

CANON uses access controls and signed, secure session mechanisms where the current architecture supports them. No internet service can promise absolute security. During private beta, monitoring and third-party integrations depend on environment configuration; unavailable providers can reduce feature availability without changing ownership of your Canon content.

8. Age limits

CANON is not intended for children under 13, or under 16 in the European Economic Area, consistent with the account eligibility terms.

9. Contact

For privacy questions or an account-data request, use the contact page or email hello@whatsyourcanon.com.

Privacy — CANON