Legal
Privacy Policy
Last updated 28 July 2026
This policy explains what CanvasFlow does with personal data. It is written to be read, not to be survived. If anything here is unclear, ask and we will explain it — and if the explanation is bad, that is a bug in this document.
The short version
- We collect your email address so you can have an account, and whatever you put on your boards.
- We do not sell your data, we do not run ads, and we do not use your board content to train machine learning models.
- Your boards are private by default. Nobody at Northem reads them except when you ask us to look at something, or when we are legally compelled to.
- You can download everything we hold about you, or delete your account outright, from Settings.
The rest of this page is the same thing said carefully enough to be enforceable.
Who is responsible
Northem, established in Norway, is the data controller for personal data processed through CanvasFlow. That means we decide what is collected and why, and we are the ones you hold to account.
You can reach us at admin@northem.no. We answer data protection requests at the same address; there is no separate form to fill in.
Norway is not an EU member state but is part of the EEA, so the General Data Protection Regulation applies to us, implemented domestically through the Personal Data Act. Our supervisory authority is Datatilsynet (the Norwegian Data Protection Authority).
We have not appointed a Data Protection Officer. Northem is small, does not carry out large-scale monitoring, and does not process special categories of data as a core activity, so Article 37 does not require one. If that changes we will say so here.
What we collect
Four kinds of thing, and nothing else.
Account data
Your email address, and — if you sign in with Google — the name and profile picture on your Google account. If you sign up with a password, we store a hash of it, never the password. We also record which plan you are on and when the account was created.
Content you create
Boards, cards, notes, tasks, links, drawings, tags, connections between cards, and any files or images you upload or clip from the web. This is the substance of the service. It can contain personal data about other people if you choose to put it there, which is a decision you are making, and one this policy expects you to make responsibly.
Technical data
When your browser talks to our servers it necessarily reveals an IP address, a user agent string, and which page it asked for. Our hosting provider keeps these in request logs. We use them to keep the service up and to investigate abuse, not to build a profile of you.
We do not run analytics, advertising pixels, session recording, heatmaps, or any third-party tracking script. There is nothing on the page watching where your mouse goes.
Payment data
If you subscribe, PayPal handles the payment. We receive a subscription identifier, the plan, the status and the billing period. We never see your card number and could not retrieve it if we wanted to.
Why we use it, and on what legal basis
The GDPR requires a specific lawful basis for every processing purpose. Ours:
| What we do | Why | Lawful basis |
|---|---|---|
| Create and maintain your account | You cannot have private boards without an identity to attach them to | Contract (Art. 6(1)(b)) |
| Store and serve your board content | This is the product | Contract (Art. 6(1)(b)) |
| Process subscription payments | To charge you for a paid plan | Contract (Art. 6(1)(b)) |
| Keep request and error logs | To keep the service running and diagnose faults | Legitimate interests (Art. 6(1)(f)) |
| Investigate abuse and enforce our terms | To protect other users and the service | Legitimate interests (Art. 6(1)(f)) |
| Send service emails — sign-in links, security notices, billing | You need to be told when your account changes | Contract and legal obligation |
| Keep records required by accounting law | Norwegian bookkeeping rules | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests we have weighed them against your rights and concluded that keeping a service online and free of abuse is something users expect and benefit from. You can object to this processing; see your rights below.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile you.
The browser extension
The CanvasFlow Web Clipper deserves its own paragraph because browser extensions have earned their reputation.
- It ships with access to no website at all. The permission to read a site is asked for the first time you try to clip from that site, and you can withdraw it from the extension’s options page.
- It reads a page only when you act — a right-click, a keyboard shortcut, or a click on the save badge. It does not run in the background collecting what you browse.
- What leaves your browser is exactly what you chose to save: the image, link or selected text, plus the address of the page it came from so the card can link back.
- It does not read your browsing history, your cookies, your form inputs, or any page you did not ask it to clip.
- Your sign-in session is stored in the browser’s extension storage. Signing out removes it.
We do not sell or transfer extension data to third parties, do not use it for anything unrelated to saving things to your boards, and do not use it to determine creditworthiness or for lending. Those three sentences are the Chrome Web Store’s required disclosures, and they are true.
Where your data lives
Your account and board content are stored in the European Union.
Two of our providers involve the United States: our hosting provider operates a global content delivery network, and Google processes a sign-in if you choose that method. Those transfers rely on the EU–US Data Privacy Framework where the recipient is certified, and otherwise on the European Commission’s Standard Contractual Clauses together with the technical measures described on the Security page.
If you would rather not involve Google at all, sign up with an email address and password instead.
How long we keep it
| Data | Kept for |
|---|---|
| Account and board content | As long as your account exists |
| Deleted boards and cards | Removed immediately; purged from backups within 30 days |
| A deleted account | Erased within 30 days, backups included |
| Server request logs | Up to 30 days |
| Billing and accounting records | Five years, as Norwegian bookkeeping law requires |
Backups are the honest complication in every retention promise: deleting a row from the live database does not reach into a snapshot taken yesterday. Ours roll over on a 30-day cycle, which is why that number appears twice above.
Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you. Settings has a one-click export that produces a machine-readable JSON file containing everything.
- Rectification — correct anything inaccurate. Most of it you can edit directly.
- Erasure — have your account and its contents deleted. Settings does this; it is immediate and it is not reversible.
- Restriction — ask us to stop processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive your data in a structured, commonly used, machine-readable format. That is what the export produces, and you may send it wherever you like.
- Objection — object to processing based on legitimate interests, on grounds relating to your particular situation.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting what was lawful beforehand.
Write to admin@northem.no. We will respond within one month, as Article 12 requires, and we will not charge you for it. If a request is complex we may extend that by two months and will tell you why.
If you think we have got it wrong, you can complain to Datatilsynet (the Norwegian Data Protection Authority) at https://www.datatilsynet.no, or to the supervisory authority where you live. We would rather you told us first, but that right does not depend on us.
Keeping it safe
Everything travels over TLS. Passwords are hashed. Every table in the database enforces row-level security, so a request for someone else’s board is rejected by the database itself rather than by application code that might have a bug in it. Uploaded files are namespaced per user and the storage policy checks that against your session.
The Security page has the detail, including how to report a vulnerability.
If a breach occurs that is likely to risk your rights and freedoms, we will notify Datatilsynet within 72 hours and tell you directly without undue delay.
Children
CanvasFlow is not directed at children. You must be at least 16 to use it, which is the age Norway sets for a child’s own consent to information society services. If you believe a child has an account, write to admin@northem.no and we will remove it.
Changes to this policy
We will update this page when the product changes. If a change materially affects how your personal data is used, we will email you before it takes effect rather than quietly editing the page and changing the date.
Contact
Northem, Norway — admin@northem.no