xCanvas by xType

Privacy notice

Privacy Policy

This policy explains how the xCanvas Android app handles creative content, AI prompts, AI image reports, purchases, device permissions, backups, support messages, and privacy choices. xCanvas shows no ads.

Plain-language summary: xCanvas does not require an account and shows no ads. Most projects, imported files, photos, fonts, and editing activity remain on the device. Data leaves the device when an online feature needs it—for example, when a user submits an AI text prompt or reports an AI image, downloads an asset, makes a Google Play purchase, rates the App through Google Play, sends support email, opens an external link, enables Android backup, or chooses to share or print content.
01

Scope and data controller

This Privacy Policy applies to the xCanvas Android application (the “App”), its online font, image, and template catalogues, its AI image-generation and AI image-reporting features, and this privacy-policy webpage (together, the “Services”). It does not control the privacy practices of other apps or websites that a user opens from xCanvas or chooses as a sharing, printing, payment, or email destination.

xType (“xType,” “we,” “us,” or “our”) is the controller responsible for the processing described in this policy, except where a named third party acts as an independent controller for its own service—for example, Google for Google Play, Google Play services, or Google Play Services for AR, and OpenAI for its own processing.

Controller details

xType
Xrisostomou Smirnis 33
Larissa, Thessaly 41223
Greece
Email: FontsApp@protonmail.com
Phone: +30 694 974 1939
02

Privacy at a glance

No account No xCanvas sign-in or profile

The App does not ask users to create an xCanvas account or submit a name, phone number, or address to use its editing tools.

Local first Creative work stays on the device

Projects, canvas text, imported images and fonts, AI images, autosaves, and most settings are stored locally. When Android backup is on, much of it is also copied to the user's Google backup (Section 3).

No ads No advertising or ad tracking

xCanvas shows no ads, contains no advertising, analytics, or crash-reporting SDK, and does not read the advertising ID. Google libraries in the App send their own diagnostics to Google (Section 6).

AI is online AI prompts are transmitted

The submitted prompt, with any style or background wording the App adds, and the requested image size go to xCanvas's AI service on Cloudflare, which has OpenAI check the prompt and then generate the image. No account, device ID, gallery photo, camera frame, or canvas is attached.

Optional reports Reporting an AI image sends its prompt

A report sends the chosen reason, any comment, the image's prompt and file name, the App version, and the App language to xType's report database. No image, IP address, or device ID is stored with it.

Optional camera Camera and AR are optional

Camera access is requested only when the user opens the camera preview. Google Play Services for AR is used only in the optional surface-placement mode. Standard editing works without camera permission.

Clipboard Copied images are imported only on request

When xCanvas is open and the clipboard holds an image or links to files, the App checks it for an image, shows a preview, and asks before importing it. Plain text on the clipboard is never read automatically.

Payments Google Play handles payment details

xCanvas Pro is sold through Google Play. The App receives the subscription status needed to unlock features, but Google does not share a user's full card or bank details with xType.

03

Information xCanvas handles

“Personal data” or “personal information” means information that identifies, relates to, describes, or can reasonably be linked to a person or device. The categories below describe the current App's actual data flows.

Category Examples and source Where it is handled
Creative content and local files Canvas text; project names; saved text designs; imported fonts and the user's notes on them; imported photos, including images pasted from the clipboard or dropped onto the App; camera snapshots; PDF project files; templates; crops; thumbnails; drawings; saved exports; and AI-generated images. Primarily in the App's private storage. Saved projects and the autosave keep their own copies of the fonts and pictures they use. Imported photos are re-encoded, so their EXIF metadata (for example, GPS location) is not kept; a cleaned-up version of the original file name is. Images saved to the gallery go to shared storage (Pictures/xCanvas). Exports saved to files, printing services, or sharing apps are controlled by the user and those destinations.
App settings and local activity Theme, vibration, and AI-notification switches; recent project; autosave session; favourites; colour palettes; canvas-size presets; crop/edit state; AI generation settings (size, background choice and colour, and any custom style text); the lists of imported image and font file names, including names of deleted items so they are not reused; and locally cached subscription status. The App language is kept by Android's per-app language setting. Stored on the device. Most of it can also be copied by Android backup or device-to-device transfer—see “Android backup and device transfer” below.
Local AI allowance and technical records The number of AI generations used in the current 30-day window and in total; the date and time reported by the AI service's last reply, with the device's uptime and boot count at that moment, used to keep the allowance clock accurate; whether camera or notification permission has been requested and how often it was denied; whether the first-run introduction was completed; a random token used by the home-screen widget; and a SHA-256 hash that records which clipboard image was last offered (the clipboard item itself is not stored). Stored on the device only and never sent to xType. The allowance counters, the start of the allowance window, the latest date and time the App has seen (from the AI service or the device clock), and the clipboard hash are included in Android backup. The server-time record tied to the device's uptime and boot count, the permission history, the first-run flag, and the widget token are not.
AI request content The text prompt the user submits; style or background wording added by the App (for example, a painting style, a transparent background, or a solid background colour); the requested width, height, and size; whether the background should be transparent; and the generated image returned by the service. Sent over HTTPS to the xCanvas AI service, which runs on Cloudflare and uses OpenAI to check the prompt and generate the image (see “AI image generation and reporting” below). The image is returned to and saved on the device, together with the prompt as typed and the full prompt that was sent.
AI image reports Sent only when the user opens Report on an AI image, chooses a reason, and taps Send report: the chosen reason (offensive or hateful, sexual content, violent or graphic, or something else); an optional comment of up to 1,000 characters; the full prompt that produced the image, including the wording the App adds; the image's file name, which contains the date and time the image was saved (in UTC; in local time for images made with older versions of the App); the App version; and the App language. No image, account, or device identifier is sent. Sent over HTTPS to the xCanvas AI service and stored in xType's report database on Cloudflare (Cloudflare D1), together with the date and time the report was received. No IP address or device identifier is stored with a report.
Network and server-log data IP address, request date and time, requested file or endpoint, response status, and technical connection or security data. Asset requests also carry standard HTTP headers, such as a user-agent naming the App's networking library (OkHttp); the template-catalogue request adds the device's current time to bypass caches. No cookies or device identifiers are added. IP address can indicate an approximate area. Processed when downloading fonts, images, templates, or AI output, when sending an AI image report, and when viewing this webpage. The AI service's code uses the IP address only briefly as a rate-limit key and does not store it. Cloudflare, Hostinger, and other providers may create security and operational logs under their own policies.
Google library diagnostics Usage and diagnostic information about the Google ML Kit and Google Play Billing libraries built into the App. Sent by those libraries to Google through Google's data-transport service and handled under Google's policies. It does not go to xType's servers.
Purchase information Product and offer identifiers for xCanvas Pro and the older Remove Watermark subscription, localized price, purchase token, acknowledgement state, subscription status, and free-trial eligibility. Processed through Google Play Billing. The purchase token is used only between the device and Google Play to acknowledge a purchase; it is not stored or sent to an xType server. xCanvas caches only whether each subscription is active and the free-trial eligibility and length, rebuilds this from Google Play each time the App starts, and excludes it from Android backup. Google handles payment credentials and the user's Google payment profile.
Support communications Email address, message, attachments, and any information the user chooses to send. The App prepares a support-email draft containing App version, Android version/API, device manufacturer/model/device name, screen resolution/density, and App language. Nothing is sent until the user sends the email. The message is then processed by the user's email provider, Proton Mail, and xType.
Camera and sensor data Live camera frames for the camera preview; motion and depth information in the optional AR surface-placement mode; and a snapshot of the camera image with the design overlaid, only when the user captures one. Processed on the device. The standard preview uses Android's camera without ARCore; Google Play Services for AR (ARCore) is used only in surface-placement mode. Snapshots are saved to xCanvas's private image library, not the gallery, and are included in Android backup. xCanvas does not upload camera frames to its asset or AI servers.

AI image generation and reporting

When a user asks for an AI image:

  1. The App checks that the device is online and then sends the request from a background task with a progress notification. It does not queue a request to send later. While the task runs, the prompt is held in Android's WorkManager job data on the device; that data is not backed up and is cleared after the result is handled.
  2. The xCanvas AI service, which runs on Cloudflare Workers, uses the requester's IP address (for IPv6, the /64 network prefix) as a key for Cloudflare rate limiting, to prevent abuse and control cost. Generation and reports are limited separately. The service's code does not store the IP address.
  3. The service sends the prompt alone to OpenAI's moderation service. If the prompt is flagged, or the check cannot be completed, no image is generated.
  4. The service then sends the prompt, image size, and background setting to OpenAI to generate the image and returns the image to the App. The prompt therefore reaches OpenAI twice. The App sends the AI service no account, device ID, advertising ID, or purchase token, and the service sends OpenAI no user identifier.

The AI service's own error logs record only technical details such as HTTP status codes, OpenAI error codes, and OpenAI request IDs. They never contain prompts, report text, or IP addresses. Cloudflare's own request logs for the AI service can include technical request details such as the IP address and an approximate location derived from it; Cloudflare and OpenAI keep their own records under their settings and policies.

Reporting an AI image is optional, and the report dialog in the App lists what is sent. xType uses reports to review reported images and to improve the App's AI content filtering. Deleting an AI image in the App does not delete a report already sent. Because reports carry no account or device identifier, xType can find a specific report only from details the user provides, such as the prompt or the date and time the image was generated or reported.

Android backup and device transfer

xCanvas allows Android backup. When the user has Android backup or device-to-device transfer turned on, Android can copy the following to the user's Google backup or to a new device:

  • saved projects and the autosave, including the fonts and pictures they contain; text designs; imported fonts and photos, including camera snapshots and clipboard imports; and AI images; and
  • all of the App's settings files, which include both saved versions of each AI prompt, the custom AI style text, the AI usage counters, font notes, favourites, palettes, canvas-size presets, the display, vibration, and notification switches, the lists of image and font file names, and the clipboard hash.

Android backup excludes the cached subscription status, the first-run flag (so the introduction shows again after a fresh install or on a new phone), in-progress AI work, the allowance-clock record and boot count, the widget's state and token, the permission-request history, downloaded catalogue fonts, images, and templates, temporary edit and import files, and the App's cache. Android's cloud backup accepts up to 25 MB per app; if xCanvas's data is larger, Android may not back it up to the cloud. Device-to-device transfer is not limited in this way.

Information xCanvas does not request or read

The App has no xCanvas account system and does not request location, microphone, contacts, call-log, SMS, advertising-ID, or broad storage or media permissions. It does not read the device's Android ID, advertising ID, app-set ID, phone identifiers, install referrer, location, or list of installed apps. The Google Play Billing library includes a Google location component, but xCanvas holds no location permission, so it cannot read the device's location. xCanvas shows no ads and contains no advertising SDK and no first-party analytics, attribution, or crash-reporting SDK. Error messages are written only to the device's own system log and are not sent to xType.

If the user allows Android to share usage and diagnostics data with Google, Google Play may give xType crash and app-not-responding reports through the Google Play Console. These reports contain technical details such as the stack trace, device model, Android version, App version, and time. They do not include an account identifier.

04

Device permissions and local processing

Permission or feature Why xCanvas uses it User control
Camera To show a live camera preview with the design overlaid, optionally place the design on a surface using ARCore, and let the user capture a snapshot. Camera content is not sent to xType's servers. Optional. Requested when the user opens the camera preview; grant or revoke it in Android Settings. Camera features will not work when denied.
Photos, images, fonts, and PDFs xCanvas uses Android's photo picker, file picker, “Open with,” share sheet, and drag and drop to access only files a user selects, sends, or drops into the App. It does not request broad access to storage or an entire media library. Saving to the gallery uses Android's media store without a storage permission. The user chooses each source file and each export or sharing destination.
Clipboard When the user returns to xCanvas, or the clipboard changes while xCanvas is open, the App checks the clipboard's description. If the clipboard holds an image, or links to files, the App reads it to check for an image, shows a preview, and asks whether to import it into the user's images. Plain text on the clipboard is never read automatically. Android may show a notice that xCanvas accessed the clipboard. Pressing Ctrl+V also imports a clipboard image. Apart from normal copy and cut in text fields, xCanvas writes to the clipboard only when the user copies a colour code or an AI prompt. Nothing is imported unless the user taps Add Photos. The clipboard item itself is not stored; only a hash recording which item was offered is kept.
Notifications To show a “Generating image…” progress notification with a Cancel action while an AI image is being made and, if AI image notifications are on, to announce when the image is ready (with a preview of the image) or why it failed. Notifications never show the prompt, and the contents of the result notifications are hidden on a secure lock screen. Optional. Turn off AI image notifications in xCanvas Options to stop the result notifications, or deny notification permission in Android Settings.
Internet and network state To download fonts, images, and templates; generate AI images and send AI image reports; communicate with Google Play Billing and Google Play In-App Review; and open online links. The network state is checked so an AI request is not started while offline. All of the App's own connections use HTTPS; unencrypted connections are disabled. Online features require a connection; local editing remains available subject to assets already stored on the device.
Foreground service, wake lock, and restart after reboot To let a user-requested AI generation continue while the App is in the background, shown by its progress notification. The wake-lock and start-after-reboot permissions are added by Android's WorkManager library, which keeps a running task alive and can reschedule work after the device restarts. The user starts each generation and can cancel it from the notification.
Billing To offer, acknowledge, restore, and manage the optional xCanvas Pro subscription, and the older Remove Watermark subscription for existing subscribers, through Google Play. Purchases are optional and can be managed in the Google Play subscription centre.
Vibration To provide optional haptic feedback for controls. Turn off Vibration in xCanvas Options.
Internal library permission A signature-level permission added by the AndroidX Core library that only xCanvas itself can hold. It is used inside the App and gives no access to user data. No user action is needed.

The App also declares the Google Play Billing and ARCore services it connects to, as Android requires. It does not read the list of installed apps.

On-device subject segmentation

xCanvas uses Google ML Kit subject segmentation to remove image backgrounds and isolate subjects for effects. The selected image is processed on the device, and xCanvas does not upload it anywhere for this feature. The App asks Google Play services to download the segmentation model when xCanvas is installed, although the download may happen later; if the model is not available yet, the App says so. ML Kit sends its own usage and diagnostic metrics to Google (Section 6). See Google's ML Kit subject segmentation information.

Google Play Services for AR

This application runs on Google Play Services for AR (ARCore), which is provided by Google and governed by the Google Privacy Policy.

The standard camera preview does not use ARCore. In the optional surface-placement mode, xCanvas uses ARCore on the device with plane detection turned off, instant placement, and depth information where the device supports it. When that mode is chosen, the App may ask Google Play to install or update ARCore. xCanvas does not use ARCore Cloud Anchors, the Geospatial API, Augmented Faces, or Augmented Images. Camera access is requested when the user opens the camera preview, and the screen stays on while the preview is open.

Home-screen widget

The optional widget, added from xCanvas Options or the home screen's widget list, shows a thumbnail of the most recently saved project on the home screen, with the project's name in its accessibility description, and shortcuts to import a font or image. Anyone who can see the home screen can see that thumbnail. Opening a project from the widget uses a random token that stays on the device. The App's launcher shortcuts use fixed labels only.

Google Play In-App Review

Each time the dialog of a successful save closes, xCanvas asks Google Play to show its in-app review sheet. xCanvas shows nothing of its own first and keeps no record of the request. Google Play decides whether the sheet appears and does not tell xCanvas whether it was shown or whether the user left a review. Any rating or review is sent to Google Play under the user's Google account and may be shown publicly on Google Play.

05

Why information is used and the legal bases

Depending on the feature and applicable law, xType processes information to:

  • provide editing, saving, importing (including the optional clipboard image check), exporting, sharing, printing, backup/restore, widget, camera and AR, AI generation, AI image reporting, content-download, and purchase features;
  • remember local preferences, restore the user's workspace, and keep track of the AI generation allowance on the device;
  • check AI prompts with a moderation service before an image is generated, review AI image reports that users send, and improve the App's AI content filtering;
  • verify and restore purchase entitlements;
  • let users rate xCanvas through Google Play's in-app review;
  • respond to support messages and privacy requests;
  • operate, troubleshoot, secure, and prevent abuse of the Services, including rate-limiting AI requests;
  • comply with law, enforce rights, and protect users, xType, providers, and the public; and
  • manage a merger, financing, reorganization, sale, or transfer of all or part of the Services, subject to applicable law and notice requirements.

EEA, United Kingdom, and Switzerland

Where those laws apply, the legal bases are:

  • Performance of a contract or steps requested by the user: providing the App, requested AI output, asset downloads, xCanvas Pro subscriptions, exports, and support.
  • Consent: optional device permissions such as camera and notifications. Consent may be withdrawn for future processing without affecting earlier lawful processing.
  • Legitimate interests: operating and securing the Services; preventing fraud, abuse, and excessive cost of the AI service, including checking prompts with a moderation service and using the IP address as a short-term rate-limit key; reviewing AI image reports that users choose to send and improving AI content filtering; maintaining limited technical logs; troubleshooting; and responding to ordinary support—balanced against user rights.
  • Legal obligation: tax, accounting, regulatory, court, law-enforcement, and valid legal-process requirements.
  • Protection of vital interests: only in an exceptional situation involving safety.

Third parties such as Google and OpenAI may determine their own legal bases for processing they perform as independent controllers. Their notices provide further information.

06

When data is shared and third-party providers

xType does not sell personal information and does not share it for targeted or cross-context behavioural advertising; xCanvas shows no ads. The App does disclose data to providers when needed for the functions described below.

Google Play Billing and Google Play

Process purchases of xCanvas Pro and the older Remove Watermark subscription, localized pricing, purchase status, acknowledgements, and restoration. Google keeps payment credentials; xType receives only the transaction information needed to provide the purchased entitlement, and purchase tokens are not sent to an xType server. Google Play also runs the in-app review sheet and receives any rating or review the user submits. The Play Billing Library sends its own usage and diagnostic data to Google. If the user allows Android to share usage and diagnostics data with Google, Google Play passes crash and app-not-responding reports to xType through the Google Play Console.

Google Play services, ML Kit, and Google Play Services for AR

Provide the on-device segmentation model and AR camera and sensor functionality, and install or update ARCore when the user chooses the AR surface mode. ML Kit sends usage and diagnostic metrics about its features to Google through Google's data-transport service. Images used for xCanvas subject segmentation remain on the device.

OpenAI

Checks each AI prompt with its moderation service and then generates the requested image. OpenAI receives the prompt, including any wording the App adds, the image size, and the background setting, but no account, device, or other user identifier. Do not include confidential information or personal data in a prompt unless it is necessary and the user has the right to provide it.

Cloudflare (AI service, report database, and content servers)

Hosts the xCanvas AI service and applies its rate limiting; stores AI image reports in xType's Cloudflare D1 database; and hosts and delivers the online font, decorative image, and template catalogues and files (assets.xcanvasassets.com, using Cloudflare R2 storage and Cloudflare's content-delivery network). Asset requests carry only the requested file path and standard HTTP headers, and Cloudflare sees the IP address; the template-catalogue request also carries a timestamp. Cloudflare may create security and operational logs.

Android Auto Backup and device transfer

Because backup is enabled for xCanvas, Android may back up the items listed in Section 3 to the user's Google Drive account or transfer them to another device, subject to device, account, storage quota, and backup settings. xType cannot read the user's private Google Drive backup.

Email and web hosting

Proton Mail processes support and privacy correspondence sent to xType. Hostinger hosts this static policy page and may process standard web-server log data. The page itself contains no advertising, analytics scripts, third-party fonts, or tracking cookies.

User-directed disclosure

When a user shares, prints, emails, exports, opens, or saves content through another app or service, xCanvas sends the selected content to that destination at the user's direction. The destination's own privacy policy then applies. Shared images normally include the caption “Made with xCanvas App” and a link to xCanvas on Google Play. Sharing or exporting a project creates a PDF file that contains the whole project—all of its text and every font and image it uses, including imported fonts, photos, and AI images—so that xCanvas can reopen it; the PDF also contains a Google Play link. Temporary share files are cleaned up from the App's cache after 24 hours. Printing passes the image to Android's print framework and the print service the user chooses. Users should review content before sharing because projects and images may contain personal or sensitive information.

Legal and organizational disclosures

Information may be disclosed when reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, security, or technical issues; enforce terms or protect legal rights and safety; or complete a corporate transaction. If ownership of the Services changes, this policy or a replacement notice will govern the transferred data as required by law.

07

Retention, security, and international transfers

How long information is kept

  • Local projects, files, prompts, generated images, and settings: kept on the device until the user deletes the item, clears App storage, or uninstalls xCanvas. Deleting a photo, font, or AI image from the App's library does not remove copies bundled inside saved projects or the current autosave; those copies are removed when the project is deleted or the canvas no longer uses the item. The file names of deleted photos and fonts stay in a list on the device, and in Android backups, so they are not reused; the list is removed when App storage is cleared or the App is uninstalled. Temporary edit and share files are cleaned up automatically. Files exported to the gallery or another location must be deleted separately.
  • Android backups: controlled and retained by Android/Google under the user's backup settings and Google's policies. A backup made before an item was deleted may still contain it until Android replaces that backup, and a restored or retained backup may outlast an App installation.
  • Local purchase entitlement: only whether each subscription is active and the free-trial eligibility and length are cached on the device; no purchase token is stored. They are refreshed from Google Play each time the App starts and are never included in Android backup. Google independently retains transaction records under its policies and legal obligations.
  • AI image reports: kept in xType's report database for up to 12 months after they are received, then deleted.
  • AI, asset-server, security, and webpage logs: the AI service's own code does not store IP addresses or the prompts of generation requests, and its error logs contain only technical details. Cloudflare's request logs for the AI service, which xType can view, may keep technical request details, possibly including the IP address and approximate location, for a short period set by Cloudflare. Other logs are retained only for the period reasonably necessary to deliver requests, secure and troubleshoot the service, prevent abuse, meet provider requirements, and comply with law. OpenAI, Cloudflare, and Hostinger apply their own retention rules to data they process.
  • Support and privacy correspondence: retained while needed to answer the request, maintain appropriate support and compliance records, resolve disputes, and meet legal requirements, then deleted or anonymized when no longer needed.

Retention can vary when a longer period is required by tax, accounting, consumer, regulatory, litigation-hold, fraud-prevention, or other law. When deletion is not immediately possible—for example, in protected backups—data is isolated from ordinary use until deletion or expiry where reasonably practicable.

Security

xCanvas uses Android app-private storage for local data, scoped system pickers for user files, and HTTPS for all of its own connections; unencrypted (cleartext) connections are disabled in the App. The Android file provider that the App uses to share project files exposes nothing but the App's temporary share folder. Access to support email and hosted services is restricted to people and providers who need it for the purposes in this policy. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.

International data transfers

xType is based in Greece. Google, OpenAI, Cloudflare, Hostinger, Proton, and their subprocessors may process data in the European Economic Area, the United States, or other countries. Those countries may have different data-protection laws. Where required, transfers are made using an applicable adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism described by the relevant provider.

08

Your choices and controls

  • Delete local content: delete projects, text designs, imported fonts and images, AI images, palettes, canvas-size presets, font notes, the custom AI style text, or other supported items inside xCanvas. Copies of fonts and images inside a saved project or the autosave go when that project is deleted or the canvas stops using them. Clear xCanvas storage in Android Settings or uninstall the App to remove all of its private local data. Separately delete gallery exports, shared copies, printed copies, or files saved elsewhere.
  • Advertising: there is nothing to opt out of. xCanvas shows no ads, does not use the advertising ID, and does not sell or share personal information for targeted advertising.
  • Manage permissions: revoke camera or notification permission in Android Settings, and turn AI image notifications on or off in xCanvas Options. The related optional feature may stop working.
  • Clipboard images: an image found on the clipboard is imported only if the user taps Add Photos; otherwise, decline the prompt.
  • Manage AI prompts: avoid entering personal, confidential, or sensitive information. Deleting an AI image in the App also deletes both of its locally saved prompts, but not a copy in an existing Android backup or in an AI image report already sent. Provider-side logs may remain for the limited purposes and periods described in provider policies.
  • AI image reports: reports are optional. To ask for a report to be deleted, email xType with details that identify it, such as the prompt or the date and time the image was generated or reported, because reports contain no account or device identifier.
  • Manage subscriptions: use the Google Play subscription centre to view, cancel, or manage an xCanvas Pro or Remove Watermark subscription; the manage options in xCanvas Options open it too. Uninstalling xCanvas does not cancel a subscription.
  • Ratings and reviews: rating xCanvas is optional. Google Play decides whether and how often its review sheet appears.
  • Home-screen widget: remove the widget from the home screen if a project thumbnail should not be visible there.
  • Manage Android backup: use the device's Google backup settings to control cloud backup and device restore. Backups include AI prompts, AI images, and imported files (Section 3). Availability and menu names vary by Android device.
  • Choose what to send to support: review and edit the pre-filled diagnostic details and message before sending email.
  • Make a privacy request: email FontsApp@protonmail.com with “xCanvas Privacy Request” in the subject.

Because xCanvas has no user accounts, xType may hold little or no information that can be matched to a particular person. We may request limited information to verify a privacy request, but we will not ask for more than reasonably necessary.

This policy webpage

This static webpage does not use advertising, analytics scripts, third-party fonts, or tracking cookies. The web host may still create standard access and security logs. Because neither this page nor the App engages in targeted advertising or a sale or sharing of personal information, browser Do Not Track or Global Privacy Control signals do not change their behaviour.

09

Regional privacy rights

EEA, United Kingdom, and Switzerland

Subject to applicable law and exceptions, users may have rights to be informed; access personal data; correct inaccurate data; delete data; restrict processing; receive portable data; object to processing based on legitimate interests or direct marketing; withdraw consent; and lodge a complaint with a competent data-protection authority. xType does not use App data to make decisions that produce legal or similarly significant effects solely by automated means.

A request can be sent to the contact in Section 12. Users may also contact the data protection authority in the country where they live, work, or believe an infringement occurred. General information is available from the European Commission.

California and other U.S. states

Where a state privacy law applies to xType and the requester, users may have the right to know or access categories and specific pieces of personal information, receive a portable copy, delete or correct information, opt out of sale/sharing or targeted advertising, limit certain uses of sensitive information, and receive equal service without unlawful discrimination. Some rights do not apply to information handled solely on the user's device or to data a provider processes as a separate business/controller.

California notice at collection

The current Services may collect the following California categories: identifiers (IP address, used briefly for rate limiting and possibly recorded in providers' server logs); internet or other electronic activity (requests for assets, AI generation, and AI image reports); geolocation (only an approximate area that could be inferred from an IP address, not device location); commercial information (xCanvas Pro subscription status through Google Play); device and App details the user sends (App version and language in AI image reports, and device model, Android version, and screen details in support email); technical device and App details in crash and app-not-responding reports that Google Play passes to xType when the user allows Android to share diagnostics; and content a user provides (AI prompts, AI image reports and comments, and support messages). Sources are the user, the user's device, Google services, and service providers. Purposes and recipient categories are described in Sections 5 and 6.

In the 12 months before this update, versions of xCanvas that showed Google ads let Google Mobile Ads collect identifiers (IP address, advertising ID, and app-set ID), an approximate location inferred from the IP address, and ad interactions. California law may treat this as sharing for cross-context behavioural advertising. It stopped with the versions of xCanvas from which ads were removed in September 2026. An older version that is still installed keeps showing Google ads until it is updated; in that version, ad personalisation can be limited through xCanvas → Options → Privacy options when that entry is displayed, through Android's ad-privacy settings, or through Google's My Ad Center.

The current version of xCanvas does not sell personal information and does not share it for cross-context behavioural advertising. xType does not knowingly sell or share the personal information of consumers under 16. More information about California rights is available at privacy.ca.gov.

Submitting and appealing a request

Send requests to FontsApp@protonmail.com. Describe the right being exercised, the relevant xCanvas feature, and the jurisdiction. xType will respond within the period required by applicable law. If a request is denied, the response will explain the reason and, where required, how to appeal. An authorized agent may submit a request where permitted, subject to proof of authority and identity verification. Requests may be limited or refused where an exception applies or the request cannot reasonably be verified.

10

Children's privacy

xCanvas is a general-audience creative tool and is not designed to knowingly collect personal information from children. The App does not ask for a user's age and has no separate mode for children. A child who is below the minimum age for independently consenting to online data processing in their country should use the App only with a parent or guardian's permission and supervision. Children should not put their own or another person's private information into AI prompts, AI image report comments, project text, or support email.

If xType learns that a child provided personal information through the AI, reporting, or support features without valid authorization, xType will take reasonable steps to delete it where it can be identified. A parent or guardian can contact FontsApp@protonmail.com. Google and other providers apply their own child and age-related rules to data they process.

11

Changes to this policy

xType may update this policy when xCanvas features, providers, data practices, or legal requirements change. The “Last updated” date at the top identifies the current version. Material changes will be communicated through the App, this page, the Google Play listing, or another appropriate method when required. Continued use after an update is subject to the revised policy, but an update does not retroactively replace consent where new consent is legally required.

September 25, 2026 update

This version takes effect on September 25, 2026. It makes these changes:

  • Advertising removed: xCanvas no longer contains Google Mobile Ads or the Google User Messaging Platform. Ads were removed in September 2026, together with the advertising-ID permission and the related ad-privacy options. Before then, Google could collect IP address, advertising identifiers, and ad interactions through those ads. Older versions that are still installed keep showing ads until they are updated; Section 9 explains the choices available in them.
  • AI image reports added: in versions of xCanvas that include the Report option, users can report an AI image; what a report contains and how long it is kept are described in Sections 3 and 7.
  • AI safeguards described: every AI prompt is checked by OpenAI's moderation service before an image is generated, and AI requests are rate-limited using the IP address, which the AI service's code does not store.
  • Clarified: the clipboard image check, what Android backup includes and excludes, local AI allowance records, notifications, the camera and AR modes, the home-screen widget, Google Play In-App Review, diagnostics sent by Google libraries, Cloudflare as the host of the content servers, and the contents of shared project files.
12

Contact xType

For questions, complaints, privacy requests, or concerns about this policy, contact xType using the details below. Please write “xCanvas Privacy” in the subject so the request can be routed correctly.

xType — xCanvas Privacy
Xrisostomou Smirnis 33
Larissa, Thessaly 41223
Greece
FontsApp@protonmail.com
+30 694 974 1939

Have a privacy question?

Email xType and include “xCanvas Privacy” in the subject.

Email privacy contact

Google Play listing: xCanvas on Google Play