Trust & Privacy Center
We build products that use context, AI, and user feedback to make decisions easier. This center explains how we handle data, AI-assisted outputs, user contributions, beta features, privacy choices, and product-specific safeguards.
CanonIQ is in beta. This page is designed to help users understand and manage privacy choices, and will continue to evolve as the product develops.
Overview
We design every surface with privacy-by-default principles: collect only what is useful and necessary, explain why, ask for consent where appropriate, and separate essential functionality from analytics and personalization.
Where our products build a profile, you should be able to correct, suppress, delete, export, or limit what the product uses.
Privacy choices
Use the controls below to set your preferences. Essential product functionality is always on. Everything else is opt-in.
Your privacy choices
Essential product functionality is always on. Everything else is opt-in. Preferences are stored on this device.
Preferences are stored on this device. If a server-side consent record exists for your account in the future, it will take precedence.
Data we may collect
Categories below describe what we may collect across CanonIQ surfaces. We do not claim to collect data we do not collect. Items marked planned are not currently collected.
| Category | Optional | Sensitive | Used for personalization |
|---|---|---|---|
Account data Basic identifiers needed to sign in and keep your data with you. Required for the product to function. | No | No | No |
Consent preferences Your choices about analytics, personalization, and partner use. So your preferences are honored across surfaces. | No | No | No |
Usage data Coarse interaction signals such as page views and event counts. Helps us understand which features are useful. Only with analytics consent. | Yes | No | No |
Profile signals Structured slices that describe your preferences and context. Powers surface-personalization when you approve it. | Yes | No | Yes · cross-product only with consent |
Feedback and corrections When you tell us something is wrong or should not be used. So the product respects your corrections. | Yes | No | Yes · cross-product only with consent |
Inquiry intent Content you submit through demo or privacy request forms. So we can respond to your request. | Yes | No | No |
Uploaded or pasted content Planned Documents or free text you choose to share with a product. Used only by the product surface you provided it to. | Yes | Yes | No |
How we use data
- To run essential product features you actively use.
- To remember your consent and personalization preferences.
- To improve features in aggregate using coarse, sanitized signals.
- To personalize a surface only when you have approved it.
- To respond to privacy or support requests you submit.
Analytics and personalization
We avoid sending raw private content or sensitive profile details to analytics. Analytics events should use coarse categories, reason codes, counts, and consent-safe properties only.
- Raw free text, uploaded content, or parsed medical/legal/financial details
- Names, emails, phone numbers, child/family details, precise location
- Sensitive identity/community context or private profile facts
- Full CanonIQ outputs or raw profile answers
Status: analytics is consent-gated in this surface; non-essential analytics do not fire until analytics consent is granted. Legacy events are being reviewed.
Sensitive data
We treat the following as sensitive or restricted by default. Sensitive context is optional unless required for the product to function. We aim to use the minimum information needed and avoid exposing sensitive details unnecessarily.
- Health or medical context
- Legal context
- Financial hardship or benefits context
- Child or family context
- Precise location
- Identity or community context
- Sexuality, gender identity, race, ethnicity, religion
- Biometric or identity verification data
- Raw uploaded documents
- Free-text private notes
- Mental health or crisis-related context
- Employment or income vulnerability
- Immigration or citizenship context
User rights and requests
You can request to:
- Access your data
- Correct your data
- Delete your data
- Export your data
- Suppress or do not use a specific signal
- Restrict cross-product use
- Opt out of sale, share, or targeted advertising where applicable
- Limit sensitive data use where applicable
- Ask a privacy question
Privacy laws vary by location. This page is designed to help users understand and manage privacy choices.
AI and automated assistance
Some product experiences may use AI or automated systems to summarize, rank, classify, parse, recommend, or generate drafts. AI-assisted outputs may be incomplete or wrong. Important outputs should be reviewed before relying on them.
- Not medical advice, diagnosis, or treatment.
- Not legal advice.
- Not financial advice.
- Not identity verification.
- Not a guarantee of outcomes.
CanonIQ is not biometric authentication, legal identity verification, or a mental health diagnosis. It is a personal context and surface-personalization layer.
Product profiles and CanonIQ
Product-specific profiles (such as a Taste Profile, Resource Fit Profile, Work Profile, or Style Profile) help a single product work better. They are not the same as the full CanonIQ.
The full CanonIQ is a deeper personal context profile. No user receives the full CanonIQ output unless they purchase or are granted access to the full CanonIQ product.
Contributions and user-submitted content
Some areas of the experience are still being built. If you have feedback, context, examples, sources, stories, corrections, or requests that would make this more useful, tell us. User-submitted content is treated as the property of the user and is used only to improve the surface it was submitted to, unless you grant broader consent.
Regional privacy readiness
We design our data systems around privacy-by-default principles, data minimization, consent controls, user correction, deletion and export request paths, sensitivity labeling, and regional privacy-readiness. We are designing with strict privacy regions in mind, including:
- California (United States)
- European Union / EEA
- South Korea
- Brazil
We do not currently claim compliance with CCPA/CPRA, GDPR, South Korea PIPA, Brazil LGPD, HIPAA, or SOC 2.
Data processing and storage locations may vary by vendor and product. We are reviewing our systems as products move from prototype to public beta.
Vendors and processors
A working inventory of the third-party tools that may process data on our behalf. Entries marked "Needs review" are being verified as products move from prototype to public beta.
Policy links
We are updating our public policy center as products move from prototype to public beta.
Per-policy pages (Terms, AUP, AI Use, Data & Security, Cookies) are in development. For privacy questions or requests in the meantime, use the contact path below.
Contact
Questions, privacy requests, or feedback? We respond through our inquiry form.