Privacy Policy
Effective: September 24, 2026 · CanyonAI (canyonai.io)
1. The short version
CanyonAI services are designed to need almost no personal data. You call an API, pay per call, get a result. We store the minimum needed to deliver your call, prevent abuse, and keep the books — and we delete on schedule.
2. What we collect
- Request content. The payloads you send (JSON/Markdown for PDF generation, URLs for scraping or audits, PDFs for extraction). Processed to fulfill the call.
- Generated outputs. Rendered PDFs and reports, stored on Cloudflare R2. Download URLs are HMAC-signed and expire after 24 hours; outputs are removed on the same schedule.
- Payment records. For x402/USDC payments: the transaction hash, amount, and wallet address that paid. Blockchain payments are public by design. For Stripe payments: Stripe handles card data; we receive only a payment reference, amount, and email if you provide one at checkout. We never see or store card numbers.
- Operational logs. Timestamps, status codes, and Cloudflare edge logs (short retention, used for abuse prevention and debugging).
- Email, if you send it. Only if you contact us by email; used to reply.
We do not run advertising trackers, sell data, or build user profiles.
3. Retention
- Generated outputs and download tokens: ~24 hours, then deleted.
- Request logs: short edge-retention windows set by Cloudflare.
- Payment records: retained as long as needed for accounting and dispute handling.
4. Third parties
- Cloudflare — hosting, storage (R2), edge network.
- Base blockchain / USDC (Circle) — public settlement ledger for x402 payments.
- x402 facilitator (PayAI) — verifies payment signatures for paid calls.
- Stripe — card payment processing, where offered.
- Discord webhook — a private sales notification channel (service, amount, transaction hash). Contains no customer personal data beyond the on-chain payment record.
5. Machine customers
Many callers are autonomous agents with no human behind them. Where no personal data exists, there is nothing to subject-access — we simply process and expire the call data as described above.
6. Security
Tokens and download URLs are HMAC-SHA256 signed with a server-side secret. Secrets are stored as Cloudflare Worker secrets, never in source. Payment verification happens before any service executes. If you believe you found a security issue, email hello@canyonai.io.
7. Your rights
Depending on your jurisdiction you may have rights to access, correct, or delete personal data. Because we hold almost none, the practical response to most requests is: we don't have it. Contact hello@canyonai.io and we'll handle it in good faith within applicable timeframes.
8. Changes
We'll post changes on this page with a new effective date. Material changes affecting paying customers will also be announced on the service discovery endpoints.
This policy describes the Services as built. It is not legal advice; jurisdiction-specific review (GDPR/CCPA exposure grows with consumer card traffic) is recommended before scale.
← Back to canyonai.io