Skip to content
Web Canvas
Back to Web Canvas

Privacy Policy

Last updated: September 2, 2026

Curious Cat Consulting, LLC builds Web Canvas. This policy explains what the app stores, what it does not, and the services that receive limited information. The short version is that your canvases stay on your device and we never see the pages you visit.

1. Your canvases stay on your device

Web Canvas has no server of its own. There is no account to create, no sign-in, and no cloud sync. Everything the app remembers is written to storage on your phone or tablet and stays there. That includes:

  • Saved sessions, with their names and every window, image, note, connection, and color on the canvas
  • The canvas you are working on right now, including window positions and sizes
  • Your search and browsing history inside the app
  • Your preferences: theme, accent color, default search engine, grid, and the toolbar buttons you have pinned

We do not receive any of it, we cannot access it, and we cannot recover it for you. If you delete the app, it is deleted with it.

2. Browsing happens directly between you and the sites you visit

Each window on the canvas is a real web view. Pages load straight from the site you opened, exactly as they would in any other browser. Nothing is proxied through us, and we do not log, store, or read the contents of any page you open.

The sites themselves still see what any browser would show them, and their own cookies, storage, and trackers apply. Web Canvas does not add tracking to the pages you visit, and it does not remove theirs. Treat a window on the canvas the way you would treat a tab.

3. What does leave your device

Two services receive anything at all, and neither one gets the pages you visit or the contents of your canvases.

Anonymous product analytics (PostHog)

Released versions of the app send anonymous product analytics to PostHog, which is how we see which features get used and where people get stuck. It collects metadata about how the app is used: which features people reach for, and how often. The events are a fixed list in the source and each one carries a fixed set of properties, so there is no route by which your content could end up in one.

In practice that means counts, yes-or-no facts, and coarse categories: that a window was opened and roughly where from, how long a search query was and whether it was an address rather than a phrase, how many items and connections a saved canvas held.

We never send the addresses of the pages you open, the text you search for, or the text of your notes. The app does not truncate or hash them before sending. It does not collect them at all.

The app also reports crashes and errors so we can fix them, records which screen you are on by its route name, and records which control you tapped. Session replay is switched off, so no recording of your screen is ever captured. Analytics are disabled entirely in development builds.

None of this is tied to a name or an email, because the app never asks for either. Events are grouped under an anonymous identifier your operating system provides for this app on this device.

Support chat (Crisp)

If you start a support conversation, the messages you send are processed by Crisp, our support chat provider, so that we can reply. The app also sends Crisp the same anonymous device identifier, so a conversation stays continuous across sessions. Anything you type or attach in a support chat is visible to us, so please do not paste anything into it that you would not want us to read.

4. What a shared session link contains

The share option on a saved session produces a link that contains an identifier for that session and nothing else. Opening it works only on a device that already holds the session. The canvas is not uploaded anywhere, and the link does not carry your windows, notes, or history. Someone else tapping it will not see your canvas.

Sharing a URL into Web Canvas from another app works the same way in reverse: the link goes onto your canvas on your device.

5. Permissions

Web Canvas does not request camera, photo library, location, contacts, or push notification access. Images that appear on your canvas come from the web pages you open, not from your photo library.

6. How your data is protected

Because your canvases never reach a server, the main protection is your device itself. Data is stored in the app’s private storage area, which the operating system isolates from other apps and encrypts at rest when you have a passcode or biometric lock enabled. We recommend keeping one enabled.

The app does not add its own layer of encryption on top of the operating system’s. Your browsing history inside the app is stored the same way everything else is, so a device passcode is what protects it.

Because there is no cloud copy, losing your device means losing your saved sessions unless your device backup includes them.

7. What we never do

  • We do not sell your personal information, and we never have.
  • We do not display advertising, and we do not embed advertising networks in the app.
  • We do not build advertising profiles or track you across other apps and websites.
  • We do not collect the addresses of the pages you open, the text you search for, or the text of your notes.

8. Your choices and rights

You control everything the app stores. Saved sessions can be deleted from the sessions list, history entries can be deleted individually from the history screen, and deleting the app removes all of it from your device at once.

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. Most of those are already answered by how the app works, since we do not hold your canvases in the first place. For the limited data our providers process on our behalf, contact us and we will honor your request as the law requires.

9. This website

This site is a static marketing site. It sets no advertising cookies and runs no advertising trackers. It uses Vercel Analytics, which counts page views without cookies and without building a profile of you. If you open the chat on the support page, that is the same Crisp service described above. If you send us a feature request, the form is handled by Formspree and reaches us as an email, including your email address if you chose to give one.

10. Children

Web Canvas is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information through our support chat, contact us and we will delete it.

11. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects how information is handled, we will note it in the app’s release notes as well.

12. Contact us

Questions about this policy or about your data can go to support@curiouscat.consulting, or through the chat on our support page.

Curious Cat Consulting, LLC