Canvane
  • Features
  • Models
  • Pricing
  • FAQ
Canvane

Start free with 100 credits, no card required. Choose from Seedance, Kling and Veo in one clean workspace.

support@canvane.com
Product
  • Features
  • Pricing
  • FAQ
Company
  • About
  • Contact
Legal
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
  • Acceptable Use Policy
  • Refund Policy

Canvane is an independent product that provides access to third-party AI video models through its own interface. Canvane is not affiliated with, endorsed by, or sponsored by Google, Kuaishou, ByteDance, or any other model provider. Seedance, Kling, Veo and all other product names, logos and brands are the property of their respective owners and are used for identification purposes only.

© 2026 Canvane. All Rights Reserved.

Privacy Policy

What data Canvane collects, why, and what control you have over it

2026/08/18

1. Introduction

Canvane is operated by an independent sole trader trading as Canvane, who is the data controller for the personal data described in this policy. You can reach us at support@canvane.com with any privacy question or to exercise the rights in section 9.

Because Canvane is run by one individual rather than a company, our operator's full legal name and address are not published on this page. We will provide them on request within 5 business days — including where you need them in order to complain to a data protection authority. Email support@canvane.com.

This Privacy Policy explains what personal data we ("we", "us", "our") collect when you use our AI video generation service, why we collect it, who we share it with, and what rights you have.

We follow a minimal-collection approach: we process what is needed to run the Service, bill for it, keep it secure, and improve it.

2. Data we collect

Account data. Your email address, name, and profile image as provided by Google or GitHub when you sign in; your role; and session records. We never receive your Google or GitHub password.

Generation data. The prompts you submit, the model and settings you choose, and the generated video. We store all three. Your prompt is kept so we can operate and support the Service and investigate breaches of our Acceptable Use Policy; your video is copied to our own storage so that it keeps working after the model provider's own link expires, which it does within a day. A prompt is also transmitted to our routing partner and to your chosen model provider to fulfil the request, and to the moderation services to screen it. Section 7 gives how long each is kept. Prompts are the core of what this Service processes — please read section 4 on how they are shared, and do not put personal, confidential, or sensitive information in one.

Screening outcomes. When screening blocks a prompt, we record which service blocked it, the kind of decision it made, and which Acceptable Use Policy categories it matched. That record is a counter held on our own analytics instance: it carries no prompt text, no account identifier, and nothing else that ties it to you. A blocked prompt is not written to our database at all, and a prompt that passes screening leaves no screening record. Because nothing connects a block to your account, a request for human review under section 9 has to include the prompt.

Billing data. Plan and subscription status, credit balance and credit transaction history, order and payment records, and invoice identifiers. We do not receive or store your full payment card number — see section 4.

Technical and security data. IP address, device and browser information, request logs, error reports, and anti-abuse signals.

Website usage and session replay. Aggregate traffic measurement, and anonymised recordings of how pages are used — clicks, scrolling, and mouse movement — captured by Microsoft Clarity. Text you type into form fields is masked. See section 4.

Communications. Messages you send us via support or contact forms, and your newsletter subscription status.

Cookies. Used for authentication, session management, security, language preference, and analytics. See our Cookie Policy.

3. How we use data

We use the data above to:

  • Provide video generation, workspace, and account features
  • Authenticate you, maintain sessions, and support account recovery
  • Screen prompts against our Acceptable Use Policy before generation
  • Process orders, subscriptions, and credits, and provide customer support
  • Detect, investigate, and prevent fraud, abuse, and security incidents
  • Debug, monitor, and improve performance and product quality
  • Send service messages (billing, security, and account notices), and — if you have not opted out — occasional product updates
  • Comply with legal, tax, and accounting obligations

We do not sell your personal data, and we do not use your prompts or generated videos to train our own models.

4. Who we share data with

We share limited data with the service providers needed to operate Canvane:

  • AI model providers. To generate a video, your prompt and generation settings are transmitted to our model routing partner Evolink and, through it, to the model provider you selected (such as Seedance, Kling, or Veo). Their own terms and privacy practices govern what they do with that data. Do not put personal, confidential, or sensitive information in a prompt.
  • Content screening. Before generation, each prompt is screened by the OpenAI and Anthropic moderation services. They are called in sequence and both must return a pass before the prompt reaches a model, so a prompt that the first service blocks is never sent to the second. The prompt is sent to Anthropic together with a pseudonymous account reference — an internal identifier, not your email or name; OpenAI receives the prompt alone, with no account reference of any kind.
  • Payments. Waffo Pancake (Waffo.com Limited) acts as merchant of record and processes payments. Waffo receives the data needed for the transaction and for tax compliance, and handles your card details directly — your full card number never reaches our servers.
  • Infrastructure. Neon (PostgreSQL database), Vercel (application hosting), and S3-compatible object storage, which holds profile images and the copies of generated videos described in section 2.
  • Email. Resend delivers transactional email — address verification and password reset — and the opt-in newsletter.
  • Analytics. Plausible Analytics for cookieless, aggregate traffic measurement. We run it ourselves on our own domain, so those statistics stay on our infrastructure and Plausible's hosted service receives none of them; the screening record described in section 2 goes to a separate site on that same instance. Microsoft Clarity, a third party, provides anonymised session replay and heatmaps (privacy statement).

We may also disclose data where legally required, to enforce our Terms, or to protect the rights, safety, and property of Canvane, our users, or the public. If we are ever involved in a merger, acquisition, or asset sale, data may transfer as part of that transaction; we will notify you if that happens.

5. Newsletter

We do not subscribe you to marketing email when you create an account. The product newsletter is opt-in: you can subscribe from your notification settings, and unsubscribe at any time from there or via the link in any newsletter email.

Unsubscribing does not affect service, billing, or security emails, which are necessary to operate your account and are sent regardless of your newsletter preference.

6. International transfers

Our providers operate in a number of countries, so your data may be processed outside the country where you live, including in jurisdictions with different data-protection laws. Where required, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — for those transfers.

7. How long we keep data

  • Account data (email, name, profile image, role) — while your account is open. If you delete your account, we delete or anonymise it within 180 days of closure.
  • Sessions — expire 7 days after they are issued; expired records are removed on our normal cleanup cycle.
  • Prompts — 30 days from submission. A scheduled job runs at least once a day and erases the prompt text from the generation record on its first pass after those 30 days are up, so erasure can trail the deadline by up to a day. We keep prompts this long to operate and support the Service and to investigate breaches of our Acceptable Use Policy. Where an enforcement action, abuse report, or legal claim is still unresolved, we may keep the prompts it concerns until it is closed.
  • Generated videos — 30 days from generation, after which the video is marked expired and we stop serving it. The file itself is deleted from our storage by a lifecycle rule set to 31 days — a day later on purpose, so that the record reports expiry before the bytes go — and that rule can take up to a further day to run. The model provider that produced the video holds its own copy under its own retention rules, and its link stops working within a day, which is why we keep one.
  • Generation records (the model and settings you chose, status, timing, and credit cost — what is left once the prompt is erased and the video deleted) — while your account is open. If you delete your account, they go with your account data above.
  • Screening outcomes (which service blocked a prompt, the kind of decision, and which policy categories it matched, with no prompt text and no account identifier) — kept indefinitely on our own analytics instance as aggregate statistics with no personal identifiers.
  • Billing and order records (payments, invoices, credit transactions) — 7 years from the transaction, as tax and accounting law requires. These are kept even after you close your account.
  • Security and abuse logs (IP address, request and error logs, anti-abuse signals) — 24 months from the event.
  • Support and abuse-report correspondence — 24 months from the last message, or longer where an enforcement action or legal claim is still unresolved.
  • Newsletter subscription status — until you unsubscribe, then 24 months so we can honour your opt-out.
  • Analytics data — our Plausible instance keeps aggregate statistics indefinitely with no personal identifiers; Microsoft Clarity retains session recordings for 30 days.
  • Database backups — age out on our normal backup cycle within 30 days.

When a retention period ends, data is deleted or irreversibly anonymised.

8. Security

We use encrypted connections (HTTPS/TLS) throughout, restrict internal access to personal data, delegate authentication to Google and GitHub, and never handle raw payment card data. No system is perfectly secure, and we cannot guarantee absolute security.

Breach notification. If a breach affects your personal data, we will notify any relevant supervisory authority and — where the breach is likely to put your rights at high risk — you directly, within 168 hours (7 days) of becoming aware of it. Where a shorter statutory deadline applies, we meet that instead: under the GDPR, notification to a supervisory authority is made within 72 hours.

9. Your rights

Subject to applicable law, you may:

  • Access the personal data we hold about you, or receive a copy
  • Correct inaccurate account information
  • Delete your account and eligible personal data
  • Export account-related information in a portable form
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent, including unsubscribing from the newsletter
  • Not be subject to a decision based solely on automated processing that significantly affects you. We screen every prompt automatically, which can block a generation and, on repeated or serious breaches, lead to account suspension. You can contest any such decision and ask for human review by emailing support@canvane.com

You can do much of this directly in your account settings. For anything else, email support@canvane.com. We respond within 30 days — the period the GDPR allows. Where a request is complex, or where you have made several, we may extend that by up to two further months; if we do, we will tell you within the first month and explain why. We usually reply sooner.

Some data must be retained despite a deletion request, for tax, accounting, fraud-prevention, dispute-resolution, or other legal-compliance reasons.

If you are in the EEA or UK, you have the right to complain to your local data protection authority.

10. Legal bases (EEA/UK)

Where the GDPR applies, we rely on:

  • Contract — to provide the Service, your account, generations, and billing
  • Legitimate interests — security, abuse prevention, debugging, analytics, and product improvement, balanced against your rights
  • Legal obligation — tax, accounting, and lawful requests
  • Consent — where we ask for it, such as certain cookies; you can withdraw it at any time

11. Children

The Service is not intended for children under 13, and we do not knowingly collect their personal data. In the EEA and the UK, where national law sets a higher age for consenting to online services — between 13 and 16 depending on the country — users below that age need their parent or guardian's consent. If you believe a child below the applicable age has given us personal data, contact support@canvane.com and we will delete it.

12. Changes to this policy

We may update this Privacy Policy. Material changes will be posted here with a revised date at least 30 days before they take effect, and where the change significantly affects your rights we will also make a reasonable effort to notify you by email.

13. Contact

Questions, requests, or complaints about privacy: support@canvane.com.