Canvasby GlueCode

Privacy Policy

Last updated 27 July 2026 · Canvas by GlueCode

The short version

We collect your mobile number so you can sign in, and we store the canvases you create. We do not sell your data, we do not run advertising, and we never make a canvas public unless you publish it yourself.

What we collect

Mobile number and country code, verified by one-time password.
A GlueCode account identifier, the app that created your account, and the GlueCode apps you have access to.
Canvas content: titles, notes, colours, template choice, publish settings and password hashes.
Basic technical data: device type, browser, IP address and timestamps, kept for security and abuse prevention.

What we do not collect

We do not ask for your name, email or address to use Canvas. We do not read your contacts, location or files. We do not use third-party advertising or cross-site tracking cookies.

How we use it

To authenticate you and keep you signed in.
To store, sync and display your canvases.
To deliver service notifications you have asked for, over SMS or push.
To diagnose faults, prevent abuse and meet legal obligations.

Processors we rely on

Authentication, notifications and account records are handled by Google Firebase (Firebase Authentication, Cloud Firestore, Cloud Messaging) on Google Cloud infrastructure. SMS one-time passwords are delivered by Firebase and its telecom partners. These providers process data on our instructions under their own security commitments.

Sharing across GlueCode apps

GlueCode apps share one identity layer so a single sign-in works everywhere. Your account record notes which app created it and which apps you have entitlements for. Canvas content is stored in a database dedicated to Canvas and is not readable by other GlueCode apps.

Published canvases

When you publish, we create a read-only page behind a password you choose. Passwords are stored hashed, never in plain text. We do not index published canvases in search engines. Unpublishing removes the page immediately.

Retention

We keep your canvases while your account is active. Delete a canvas and it goes to trash for 30 days, then is permanently removed. Delete your account and all associated content is removed within 30 days, except records we must keep for legal or accounting reasons.

Your rights

You can access, correct, export or delete your data from within the app, or by writing to support@gluecode.in. If you are in the EEA or UK you also have the right to object to processing and to lodge a complaint with your supervisory authority. If you are in India, you may contact our Grievance Officer at the address below.

Security

Data is encrypted in transit and at rest. Access to production systems is limited to named engineers with two-factor authentication. Database rules restrict every read and write to the owner of the record or a valid published-link session.

Children

Canvas is not directed at children under 13, and we do not knowingly collect their data.

Changes and contact

We will post material changes on this page and, where the change is significant, notify you in the app. Contact: support@gluecode.in · GlueCode, Bengaluru, India.

Canvas
A GlueCode app. One account across Canvas, Clear and everything else we build.
© 2026 GlueCode · canvas.gluecode.inLean Canvas and Business Model Canvas are adapted under CC BY-SA 3.0.