Legal · Last updated 20 August 2026

Privacy policy

cnvs.app stores what is needed to operate shared boards, excludes board content from limited product analytics and AI training, and removes inactive or deleted boards from the live service.

What this policy covers

This policy covers the cnvs.app website, hosted Model Context Protocol endpoint, REST API, WebSocket service, and installed web app. cnvs.app is operated by CODER AI. Questions can be sent through support.

cnvs.app has no user accounts. A board URL or board ID acts like a bearer credential: anyone who knows it can access an unlocked board. Keep links private when the content is sensitive. Optional board locks can require a short access key for writes or for both reads and writes.

Data we process

  • Board content: drawings, text, links, images, diagrams, columns, tasks, coordinates, item IDs, author labels, and timestamps supplied by collaborators or MCP/API clients.
  • Board security data: the board ID, lock mode, and a salted one-way hash of an optional access key. The plaintext access key is not stored by the service.
  • Operational connection data: Cloudflare and our service may process IP address, request headers, timing, and security/rate-limit signals needed to deliver and protect the service.
  • Limited analytics: Google Analytics currently loads automatically on service pages that contain its tag, including the main app and informational pages, without an in-product consent prompt. Browser privacy controls or a content blocker can prevent it from loading, and the board continues to work. Google Analytics may set the _ga cookie, which contains a browser/client identifier, and _ga_GEE4LMKTYL, which holds session state. It may receive the sanitized page location, page title and referrer, engagement and session statistics, approximate location derived from network information, and browser, device and operating-system details. Coarse product events cover opening the todo landing page, switching board mode, and creating a column or creating/moving a task; their parameters describe only the selected mode or whether a task crossed columns.
  • Analytics URL and content safeguards: on the main app, before Google Analytics is configured and whenever browser history or the hash changes, the app explicitly sets page_location to the current origin, path and query string without the URL fragment. Because the board ID is carried in that fragment, it is not sent as the analytics page location. On informational pages, URL fragments are not board credentials. We do not add board IDs, board URLs, access keys, text, task names, descriptions, images, drawings, or other board content to analytics events.
  • Support submissions: information you choose to send through the feedback form or support email.

How we use data

We use board and connection data to synchronize collaborators, render previews and exports, execute requested MCP/API operations, enforce quotas and access locks, prevent abuse, diagnose failures, and maintain the service. Aggregate analytics helps us understand basic feature usage.

We do not use board content to train AI models, sell personal data, build advertising profiles, or run a public board directory. MCP clients chosen by a user may separately process tool inputs and outputs under their own terms and privacy policies.

Sharing and processors

Board content is shared with people and agents that possess the board URL and any required access key. Service providers process limited data on our behalf:

  • Cloudflare provides edge delivery, Workers, Durable Objects, D1 storage, security, and rate limiting.
  • Google Analytics provides aggregate page and coarse product-usage measurement.
  • CODER AI feedback service receives support information you intentionally submit.

We may disclose information when legally required or when necessary to protect users, the service, or the public.

Retention and deletion

Boards are retained for up to 30 days of inactivity. A qualifying read, such as opening the board or fetching its structured state, refreshes activity. Writes, preview fetches, and long-poll waits do not. After 30 inactive days, board content is purged and the ID may be reused.

Holding the delete control removes a board's content from the live service. The deleted ID remains tombstoned for 30 days so stale links show an erased state. The board is unavailable through cnvs.app, and we do not provide a user-facing recycle bin or individual-board recovery.

Cloudflare D1 Time Travel is always on and may retain historical state of the whole database for disaster recovery for a limited window: currently up to 7 days on Workers Free or 30 days on Workers Paid. This platform history is not a user-facing board backup or recovery service. See Cloudflare's Time Travel documentation.

Browser-local recent-board references, snapshots, and offline caches remain on each collaborator's device until that browser clears or evicts them; the app removes known deleted boards from its managed cache.

Your choices

  • Do not share a board URL beyond the intended collaborators.
  • Use a write lock or full read/write lock for additional protection.
  • Block Google Analytics with browser privacy controls or a content blocker; the board continues to work.
  • Delete a board when it is no longer needed.
  • Contact support@coderai.dev for privacy questions. Because there are no accounts, include only the minimum information needed and never email an access key.

Changes

We may update this policy as the service changes. The current version and update date are always published at this URL. Material changes will not retroactively authorize use of board content for AI training.