Privacy
This page explains what information we collect for Canvas (the macOS product) and the website at canvas.eighteenhq.com. Brand: Eighteen. Contact: [email protected].
What we collect today
- Waitlist email. When you join the waitlist, we store your email address, the time you signed up, and a basic user-agent string (for abuse prevention). We use this only to tell you when Canvas is ready and for related product updates you can opt out of.
- Support mail. If you email [email protected], we keep that correspondence to reply and improve the product.
We do not sell your email or share waitlist data with advertisers. We do not run third-party advertising trackers on this site.
What we do not collect on this site
- No account passwords on the waitlist form.
- No payment card numbers (checkout, when enabled, is handled by our payment provider — see below).
- No intentional product telemetry from this marketing page.
When you buy Canvas (later)
Paid licenses will be sold through Paddle as Merchant of Record. Paddle processes payment details and issues receipts. We receive what we need to fulfill your order (for example email, purchase status, and license entitlement) — not your full card number. Paddle’s own privacy terms apply to payment processing.
The Canvas macOS app
Canvas runs locally on your Mac. Widget folders under
~/CanvasWidgets, API keys you store in Keychain, and Sign in
with ChatGPT / Codex auth are handled on your machine and by those
providers’ terms — not scraped by this website.
On launch (and at most every few hours), Canvas sends a small usage heartbeat to our license servers so we can operate Free/Pro licensing and keep the product working. That ping includes:
- An anonymous install identifier stored in your Mac’s Keychain
- App version and build number
- macOS version and CPU architecture
- Your license key, only if you have activated Canvas Pro
We use this to see how many installs are active, when they last opened, and which app versions are in use. It is not advertising telemetry, and we do not sell it. Heartbeat failures never turn off a valid license.
If a widget build fails, Canvas may offer Report a problem. Nothing is uploaded automatically. If you explicitly choose Send, the report includes your build prompt, a redacted build transcript and local diagnostic timeline, the failure message, app/macOS/Codex versions, and Codex thread/turn identifiers and affected widget folder names. You may optionally add an email and note. Reports do not include widget file contents, Keychain data, license keys, or Codex authentication files. Known secrets and email addresses found in diagnostic text are redacted before upload and checked again by the server.
Hosting
The site and waitlist API are hosted on Cloudflare (Pages / KV). Cloudflare may process requests as needed to deliver the service (including standard security and CDN logs).
Retention & your choices
- Waitlist entries stay until we launch and notify you, or until you ask us to remove them.
- Opt-in Builder failure reports expire automatically after 30 days. You can request earlier deletion using the report ID or optional contact email.
- To unsubscribe or delete your waitlist email, write [email protected] with the address to remove.
Children
Canvas and this waitlist are not directed at children under 16. Do not submit personal information if you are under 16.
Changes
We may update this page as the product ships. The “Last updated” date above will change when we do.
Questions: [email protected] · Terms of Sale