Privacy Policy
Last updated: 2026-08-27. See also: Trust · Cookies · Terms
Who we are
QualCanvas is a qualitative-coding workspace for academic and applied researchers. Contact: [email protected]. For EU data-subject requests: [email protected].
What we collect
Account data: name, email, hashed password, sign-in provider (e.g. Google OAuth identity only — no scopes that share content).
Research content: transcripts, codes, codings, memos, cases, analysis runs, and any files you upload. This is the data you are entrusting to us; we treat it as the user's data, not ours.
Usage data: feature-interaction telemetry (which buttons, which analyses you ran), error logs, request IDs, hashed IP, billing events.
Training videos: the training centre serves preview images directly from QualCanvas and does not contact YouTube until you choose Play. After that choice, the privacy-enhanced YouTube player may receive your IP address, browser information and viewing activity under Google's privacy terms.
Research-pilot feedback: role, sector, prior product experience, task outcomes, rating and any optional comments submitted on the pilot page. Feedback is not linked to a QualCanvas account. An email address is collected only when you explicitly consent to one follow-up contact.
AI provider keys: If you BYOK an OpenAI / Anthropic / Google API key, it's stored AES-256-GCM encrypted at rest. The backend decrypts the key only when sending your requested AI call to the selected provider; the provider receives the prompt and relevant research excerpts needed for that call.
Lawful basis (GDPR Art. 6)
- Contract (Art. 6(1)(b)): for paid subscriptions, the processing is necessary to perform the contract with you.
- Legitimate interest (Art. 6(1)(f)): for free / academic users, our legitimate interest is providing the service and improving it (security, fraud prevention, aggregate analytics).
- Consent (Art. 6(1)(a)): for analytics cookies and lifecycle / product-update emails. It also applies to an optional pilot follow-up email. Withdraw at any time via the cookie banner, your account preferences, or by emailing [email protected].
Data subject rights
EU / UK customers have the following rights under GDPR / UK GDPR:
- Access (Art. 15): request a copy of your data. Self-service via Account → Export.
- Rectification (Art. 16): correct inaccurate data. Most fields are editable in-app.
- Erasure (Art. 17): delete your account from Account → Delete account. Hard deletion removes the live account and related project records. Encrypted backup copies expire under the hosting provider's backup lifecycle.
- Portability (Art. 20): export to CSV, QDPX, JSON via the canvas Export menu.
- Objection (Art. 21) / restriction (Art. 18): email [email protected].
Retention
| Category | Retention |
|---|---|
| Account + research content | While the account/project is active. A canvas moved to Trash is permanently deleted after 30 days; account deletion removes live projects immediately. Provider-managed encrypted backups expire separately |
| Audit / access logs | While needed for account security, support and the project audit trail |
| Billing records | 7 years (tax / accounting requirement) |
| Error / telemetry events | According to the configured Sentry and analytics workspace retention |
| Research-pilot feedback | 12 months. Optional contact email is used for one follow-up only and may be deleted earlier on request |
Sub-processors
Full list with locations and DPA status at qualcanvas.com/trust. We notify institutional customers of new sub-processors at least 30 days before they go live, per our DPA.
International transfers
Most processing occurs in the US (Railway, Cloudflare, Stripe, Resend). For EU customers, we transfer personal data under the transfer mechanisms documented by the relevant providers and our applicable agreements. An EU-resident application database is not currently available.
Children
QualCanvas is intended for researchers aged 18+ and is not directed at children. If you believe a child has created an account, contact us and we'll delete it promptly.
Complaints
You may also lodge a complaint with your local data-protection authority (e.g. the ICO in the UK, CNIL in France, BfDI in Germany).
Changes
Material changes will be announced via in-app notice and email to active users at least 30 days before taking effect.