Canvas privacy policy
Last updated: September 15, 2026.
Canvas is a private iPad photo frame. No account or login is required for the Apple Photos workflow or the included Landscapes, Cityscapes, and Abstract albums.
What Canvas accesses
- Only the Apple Photos albums and media you authorize. For an explicit Google Photos import, Full Photos access also lets Canvas add a non-destructive copy to a verified Canvas-owned Apple Photos album. Canvas never adopts an existing album solely because its title matches and never deletes or replaces Apple Photos assets or albums.
- Bundled Landscapes, Cityscapes, and Abstract albums of public-domain U.S. National Park Service and NASA photographs that stay on the device and do not require Photos access.
- Local settings, exclusions, imported audio, and selected Google Photos media in the app container.
- Optional Google Photos Picker authorization and the media you explicitly select. OAuth tokens stay in the iPad Keychain. Limited or denied Photos access keeps a local Google import intact and leaves its Apple Photos copy pending until Full Access is granted.
- Photo location metadata already present in an authorized photo. When you opt into current weather, Canvas requests When In Use location permission and sends the current coordinates to Apple's WeatherKit only when no personal weather station is connected. For AQI, Canvas rounds coordinates to two decimal places (approximately one-kilometer precision) before sending them to ClimateIQ's secure public API, which selects the nearest active U.S. AirNow monitoring site. No AirNow credential is shipped in Canvas. The last combined weather snapshot is stored locally for an explicitly labelled offline fallback.
Canvas has no Canvas-operated media server and includes no analytics, advertising, tracking, or data brokerage.
Storage and deletion
Disconnect Google Photos to remove its saved authorization. Deleting Canvas removes its local settings, exclusions, imported audio, downloaded Google Photos media, and stored tokens; it does not remove Apple Photos or Google Photos items. Deleting a saved Canvas Google copy does not remove its Apple Photos album or assets.
Third parties
If you choose an Ambient Weather station, Canvas stores your personal Ambient API key in the iPad Keychain and sends that key and the selected station identifier to ClimateIQ’s secure proxy to retrieve your station readings. The shared Ambient application key stays on the server. A connected station is the sole weather source; Canvas does not fetch Apple Weather alongside it. Optional AQI still describes air quality near the iPad.
Apple system frameworks provide Photos, media playback, Keychain, local storage, and WeatherKit. Google receives information necessary for the optional Google Photos Picker and OAuth flow when you choose that feature. ClimateIQ receives the approximate coordinates needed to select the nearest AirNow monitoring site and fetches AirNow's public data server-side. Canvas does not send your media to any Canvas-operated service or directly to AirNow.