Privacy Policy

Effective: September 24, 2026 · CanyonAI (canyonai.io)

1. The short version

CanyonAI services are designed to need almost no personal data. You call an API, pay per call, get a result. We store the minimum needed to deliver your call, prevent abuse, and keep the books — and we delete on schedule.

2. What we collect

We do not run advertising trackers, sell data, or build user profiles.

3. Retention

4. Third parties

5. Machine customers

Many callers are autonomous agents with no human behind them. Where no personal data exists, there is nothing to subject-access — we simply process and expire the call data as described above.

6. Security

Tokens and download URLs are HMAC-SHA256 signed with a server-side secret. Secrets are stored as Cloudflare Worker secrets, never in source. Payment verification happens before any service executes. If you believe you found a security issue, email hello@canyonai.io.

7. Your rights

Depending on your jurisdiction you may have rights to access, correct, or delete personal data. Because we hold almost none, the practical response to most requests is: we don't have it. Contact hello@canyonai.io and we'll handle it in good faith within applicable timeframes.

8. Changes

We'll post changes on this page with a new effective date. Material changes affecting paying customers will also be announced on the service discovery endpoints.

This policy describes the Services as built. It is not legal advice; jurisdiction-specific review (GDPR/CCPA exposure grows with consumer card traffic) is recommended before scale.

← Back to canyonai.io