Privacy Policy

Last updated 16 August 2026

Who we are

This policy is published by the operator of Canonhouse. We have not named a legal entity or mailing address on this site. For privacy questions or requests, use the contact page.

The contact form does not currently send email or store your message. We still treat that page as the designated channel for requests and will improve delivery as the product matures.

What the service is

Canonhouse is a writing studio. An organization owns books (chapters and pages) and an org-wide wiki for notes, lore, references, and worldbuilding. People in an organization collaborate with drafts, reviews, and comments — not live co-editing.

You can sign in with Google or a magic link emailed to you. An organization admin can create an unlisted link that lets anyone with the URL read a published book without signing in.

Canonhouse is in development. We do not charge for a plan, run product analytics, offer AI writing help, or operate a public book storefront. This policy describes the product as it works today and will change before we bill for the service.

Information we collect

Account information. When you sign in we store your name, email address, and optional profile image (from Google if you use Google). We keep database sessions and email verification timestamps so you can stay signed in.

Workspace content. We store organization names and slugs; memberships and roles; invitation emails and tokens; book, chapter, and page content (including the editor document and a plain-text copy used for search); wiki entries and links between pages and lore; drafts, change requests, reviews, comments; and page version snapshots.

Share links. If someone with admin access creates an unlisted book preview, we store a random token that is the key to that URL.

Operational logs. Our host (Vercel) and database (Neon) may record request metadata such as IP address, user agent, and timestamps as part of running and securing the service.

The marketing contact form does not collect or store the name, email, or message you type there.

Google user data

When you choose Continue with Google, we use Google Sign-In (OpenID Connect) with the openid, email, and profile scopes. Google sends us your name, email address, and optional profile image. We do not request access to Gmail, Drive, contacts, Calendar, or any other Google API.

We use that Google user data only to authenticate you, create your personal organization on first sign-in, and display your name and avatar in the Canonhouse workspace.

We store those fields on your user record in our Neon database, along with the Auth.js database session that keeps you signed in.

We do not sell Google user data or use it for advertising. Google processes the sign-in on our behalf. Resend, Neon, and Vercel may process the same account fields as described under When we share it. People in an organization you join can see your name and avatar according to their role.

You can revoke Canonhouse’s access from your Google Account permissions. Revoking access does not by itself delete your Canonhouse account or writing. See Your choices and requests.

How we use it

We use this information to provide the studio: authenticate you, create your personal organization on first sign-in, let you write and review work, send magic-link and invitation emails, honor share links you create, and keep the service secure.

We do not use your writing to train a public AI model. We do not sell personal information or show advertising.

When we share it

Processors. We use Google for OAuth sign-in, Resend to send magic links and organization invites, Neon to store application data, and Vercel to host the app and operational logs. They process data on our behalf to run those functions.

Organization members. People you add to an organization can see that workspace’s books, wiki, drafts, reviews, and comments according to their role.

Unlisted share links. Anyone who has the token URL can read that book’s published pages. Drafts, wiki entries, comments, and membership details are not included in the public reader.

We may disclose information if we believe we must do so to comply with law, protect the service, or respond to a valid legal request.

Cookies and sessions

Canonhouse uses essential cookies for your Auth.js database session so you can stay signed in. We do not set advertising or analytics cookies, and we do not show a cookie banner for these essential cookies.

Retention

We keep account, session, and workspace data while your account and organizations exist so the studio can function. Invitation tokens expire. Revoking a share link deletes that token so the old URL stops working.

Host and database logs follow those providers’ ordinary retention. If you ask us to delete an account, we will remove or de-identify personal data we control except where we must keep a record (for example, to complete a request or meet a legal obligation).

Your choices and requests

You can edit or delete books, pages, wiki entries, drafts, and share links from inside the studio, subject to your organization role.

Account deletion and organization deletion are not self-serve yet. To request access, correction, or deletion of your account or personal data, use the contact page. We may need to verify that the request comes from you.

If you signed in with Google, you can also revoke the app’s access from your Google account settings. That does not by itself delete your Canonhouse account or writing.

Children

Canonhouse is not directed at children under 13. Do not create an account if you are under 13. If we learn that we have collected personal information from a child under 13, we will delete it.

International transfers

The service is hosted on Vercel and Neon. We do not promise that your data will stay in a particular country or region. If you use Canonhouse from outside the place those providers store data, your information may be processed in another country.

Changes and a plain note

We will update this policy when the product changes — especially before we charge for a plan or add features that collect new kinds of data. The date at the top of this page is the latest revision. Continued use after a change means you accept the updated policy. Questions: contact us.

This page is a good-faith description of current practices. It is not legal advice and has not been reviewed by a lawyer.