1. Who this policy covers
This policy explains how ForwardCanon LLC, a Colorado company, handles personal information in connection with forwardcanon.com, direct communications, and services we agree to provide, including invited pilots.
For privacy questions or requests, email cordwilson@forwardcanon.com.
Our public site includes product previews. Screens identified as previews do not themselves create accounts, verify phone numbers, authorize AI connections, submit inquiries, or process purchases. Where real account creation is enabled, the account handling described below applies. Creating an account does not connect private sources or start a paid subscription. You can contact us directly to discuss a pilot. When an additional service is enabled, we will explain its relevant data handling before collecting new categories of information.
This policy covers information under ForwardCanon's control. Your independent use of ChatGPT or another AI service, GitHub, cloud storage, banking, or payment services is also subject to those providers' policies. We do not receive all of your AI conversations merely because you work with ForwardCanon.
2. Information we handle
| Context | Information and purpose |
|---|---|
| Visiting the website | Our hosting provider processes request and connection information, which may include IP address, browser/device information, requested page, time, and security or error information, to deliver and protect the site. |
| Using a preview | The current website can store a temporary flag in your browser tab to display the account preview. It does not establish a real identity or account. Preview form entries are handled locally by the current page and are not submitted to ForwardCanon by that form. |
| Contacting us | We receive the contact details, organization, message, attachments, and related correspondence that you choose to send. We use them to respond, scope work, provide help, and maintain the relationship. |
| Participating in an agreed pilot | We may receive authorized source files, Canon records, roles and permissions, project information, instructions, corrections, and support records needed for that work. The accepted scope identifies the relevant sources and access. |
| Paying for an agreed service | Stripe handles payment details submitted through its payment surfaces. We receive relevant billing and transaction records, such as payer details, invoices, amounts, status, and limited payment-method information. We do not ask you to send full payment-card credentials through chat or email. |
| Creating or using an enabled account | Clerk handles your email address, password, phone number, verification messages, recovery factors, session information, and security-related connection/device information for authentication. ForwardCanon verifies your identity, email, phone-verification and session status. Cloudflare D1 holds the provider identity reference, account status, a personal-scope identifier, creation/update timestamps, and policy versions, content hashes, acceptance time and session reference. Passwords, verification codes and recovery codes are not stored in our operational database. A personal-scope identifier does not mean a repository has been created or connected. |
| Using future enabled integrations | Depending on the actual feature, we may process authorization tokens, permitted source data, and change history. These are conditional categories, not a statement that website previews collect them. |
We receive information directly from you, from people authorized to act for your organization, from sources you authorize, and through the necessary operation of our service providers. We aim to collect only what is needed for the agreed work. Please avoid sending unrelated personal information.
3. How we use information
We use information to respond to requests; establish and deliver agreed services; maintain authorized Canon and its history; manage identity and access where enabled; process billing; investigate errors and security issues; meet applicable legal obligations; and communicate about your service.
We may use operational measurements and feedback to improve reliability and usability. This does not give us permission to reuse private customer content for unrelated purposes. We do not sell personal information or share it for targeted advertising. We do not claim a license to use private Canon to train general-purpose AI models or to provide it to others for that purpose.
If a materially different use requires your permission, we will explain it and obtain the required permission first. Accepting the Terms or joining a pilot is not blanket consent to unrelated data uses.
4. AI services and connected sources
When you choose an AI service or authorize an integration, information needed for the requested task may pass between that service, ForwardCanon, and your approved sources. Its access should be limited to the agreed scope. Connecting one source does not authorize access to unrelated accounts or private records.
Your AI provider's own terms, account settings, and privacy controls govern information you submit to that provider. ForwardCanon cannot promise that an independent provider never retains information, uses it for training, or keeps a copy of a conversation. Review the settings for the account and product you actually use.
If ForwardCanon uses an AI tool to help perform your service, the tool and permitted content must be covered by the agreed service scope and appropriate confidentiality and data-use arrangements. We will not silently route private material to an unrelated provider. We will identify material limitations before using a source or tool that cannot support the needed restrictions.
A revoked connection stops future authorized access through that connection. It does not erase information already saved in an AI conversation, another provider's system, or an authorized recipient's records. Deletion requests for those independent copies may need to be made to that provider or recipient.
5. Human access and organizational boundaries
ForwardCanon is currently founder-led. Cord Wilson, and any appropriately authorized personnel supporting an agreed engagement, may need to review the information you provide to perform setup, support, troubleshooting, security work, or other agreed services. Human access is limited to the relevant purpose and scope; it is not unrestricted permission to browse your information. People acting on our behalf must protect confidential information.
An organization's authorized administrators can manage its shared environment within the agreed controls. Membership alone does not expose your private Personal Canon. Content you deliberately contribute to a shared workspace may remain available to authorized organizational users when you leave. We will distinguish that content from private personal records.
Where an organization determines why its customers' or employees' data is processed, it is responsible for its own notices, authority, and instructions. ForwardCanon may process that information on its behalf. We will establish any required data-processing agreement before the applicable processing; this general policy does not substitute for one. You may need to direct requests about an organization's source records to that organization.
Individual work areas and private Canon
When organizational service is enabled, records created or contributed within an organization's individual work areas and shared Canon are handled within its organizational scope. Restricted visibility to one member does not make an organizational work area a separate private Personal Canon. Before participation, the agreed scope and notices must identify organizational administration, access, retention, and departure consequences. Administrators receive only the access supported and authorized for their roles; not every administrator or member automatically sees all records.
A separate private Personal Canon does not become available to an organization because it pays for a seat, invites a user, or controls the user's email domain. Moving records across these boundaries requires appropriate authority. Neither topic classification nor an ownership allegation alone authorizes copying private records into an organization. These distinctions describe the supported scope of an agreed service; automated routing, shared access controls, and offboarding remain subject to actual implementation and validation.
Requests for disputed or legally required records
We do not give an organization access to separate private Canon solely because it claims the records concern its business. We evaluate consent and other applicable authorization, or legal process, before disclosure. Legal requests are reviewed for validity, service, jurisdiction, scope, and applicable obligations, with legal advice as needed. We may seek clarification or narrowing or contest a request where appropriate and permitted.
Any disclosure is limited to the records properly authorized or legally required. We use restricted handling and an appropriate delivery method rather than automatically granting ongoing workspace or account access. We notify affected users before disclosure where legally permitted and appropriate. A legal preservation requirement may change deletion timing for specified records; it does not itself authorize disclosure or retention of unrelated Canon. Access to request records and preserved material is restricted to the relevant purpose.
6. When information is shared
Information may be disclosed to:
- providers needed to host, secure, communicate about, store, or deliver your agreed service;
- Stripe and relevant financial institutions for authorized payments and business records;
- AI services or source providers within your authorized workflow;
- people you authorize, including appropriate members of a shared workspace;
- professional advisers when necessary and subject to appropriate confidentiality;
- authorities or other parties where reasonably necessary to comply with law, protect rights, or respond to fraud or a security incident.
Cloudflare hosts the website and, when accounts are enabled, the operational account database. Clerk provides enabled account authentication and verification delivery under its agreement with ForwardCanon. This policy covers our use of your end-user account data; Clerk’s separate Privacy Policy covers its own website and direct customer relationships. Stripe is the established payment processor. The planned hosted Canon service uses GitHub-managed private repositories and restricted Cloudflare R2 storage for saved attachments and recovery copies. Repository hosting, attachments, and automated Canon recovery remain implementation work; account creation does not activate them. Business email and any tools used for an engagement also involve service providers. We identify the actual storage, tools, and manual responsibilities for an agreed pilot before receiving its private Canon. Providers receive information only for their relevant role, subject to the applicable arrangements. Some providers also have independent duties and uses, such as fraud prevention or legal retention.
If a business transfer affects personal information, we will require the recipient to respect applicable commitments and provide notice or obtain consent where required. We do not treat a transfer as permission for unrelated data use.
Hosted Canon and operational records
For the hosted Canon service, ForwardCanon manages the repositories used to hold your Canon. Customer-specific records, curated identity, and roles remain in the authorized destination repository; the separate Boot Git contains verification/bootstrap material and ForwardCanon agent principles. Hosting does not transfer ownership of your content to ForwardCanon.
When enabled, operational records needed for accounts, memberships, authorized connections, repository routing, billing references, and audit history are stored separately from Canon. Sensitive credentials are protected separately. Routine audit records should identify the actor, resource, time, operation, outcome, and relevant policy revision rather than store full prompts or Canon contents by default. A task or authorized support request may require relevant content; it does not authorize collecting your entire AI chat history.
Our approved hosted-service recovery plan uses restricted encrypted backups and automated restore checks. It remains implementation work. Each agreed pilot identifies its actual backup/recovery handling and any manual limitations before private data is accepted. Backups are for recovery, not ordinary browsing, unrelated reuse, or model training. We do not promise uninterrupted service or a guaranteed restoration time. When restored, current deletion requests and access revocations must be reapplied before affected data is served.
7. Cookies, browser storage, and communications
Account previews use temporary browser-tab storage for presentation. Enabled authentication uses Clerk scripts, necessary cookies and browser storage to maintain and protect sign-in. Hosting and security services may also use technologies needed to operate and protect the site. Clearing browser storage may sign you out or reset preview behavior; it does not delete your account or information already sent to us through email or another service. Verification texts, recovery messages and sign-in notices are used for account security, not marketing.
We do not use personal information for targeted advertising. If optional analytics or marketing technologies are introduced, we will first update the relevant disclosures and provide any required choices. We will honor applicable opt-out signals where relevant processing and law require them.
We may send service, billing, and security communications relevant to your relationship with us. We will provide a way to stop optional marketing communications if we send them. Necessary service notices are separate from marketing.
8. Retention, cancellation, and deletion
We retain information only for the purposes described here, including service delivery, security, recordkeeping, and legal obligations. The appropriate period depends on the type of record, whether the relationship remains active, and whether a specific legal or security need applies.
For ordinary inquiries that do not become an engagement, our operating period is up to 12 months after the last meaningful contact, unless a longer period is needed for a particular legal matter or you request earlier deletion.
For Canon content held by ForwardCanon, our default after the final paid access period or agreed pilot closes is:
- a 30-day opportunity to request an authorized export of customer Canon and supporting data; this does not include Canon View or its product-specific configuration/presentation curation, private product implementation, or records you lack authority to receive;
- removal from active ForwardCanon-controlled storage within 60 days of closure;
- removal or expiry of remaining ForwardCanon-controlled backup copies within 90 days of closure.
An earlier valid deletion request will ordinarily be completed in active storage within 30 days after the necessary identity and authority checks, with backup copies removed or expired within 90 days of that verified request. We will meet any shorter legally required deadline. Restricted backup copies are not used for ordinary service; if restored for recovery, outstanding deletions and access revocations must be applied again before affected information is served.
These content-deletion periods do not require us to erase records that must be retained for tax, billing, a specific dispute, fraud prevention, or another applicable legal obligation. We retain only the information needed for that purpose, restrict its use, and remove it when that need ends. An exception for an invoice is not permission to keep unrelated Canon content indefinitely.
Hosting and security records are retained according to their operational purpose and the applicable provider settings, with longer retention limited to a specific investigation or legal need. Customer-controlled source accounts and providers acting independently follow their own retention rules. We cannot promise deletion of copies outside our control; we can help identify where a separate request is needed.
Account-only closure and deletion requests can be made through the contact address below. After the required ownership checks, we remove the active authentication account and operational profile ordinarily within 30 days of a valid request, subject to the specific legal and security exceptions above. Policy-acceptance evidence may be retained as needed to establish the agreement or resolve a dispute, with restricted access. Signing out or deleting local browser storage is not an account-deletion request.
Canceling one capability does not delete information still needed for an active capability. Leaving an organization does not automatically delete its authorized records, including records in individual organizational work areas. Membership removal does not itself close the organization's service or start its closure deletion timetable. Separate private Canon follows its own service status. Ask us if you want to close your individual service, revoke a connection, obtain an export, or request deletion; these requests have different effects.
9. Your choices and requests
Email cordwilson@forwardcanon.com to ask what personal information we hold, request access or correction, request an authorized export, request deletion, withdraw a permission, or raise a concern. These requests can be handled manually during a pilot; an account settings page is not required.
We will verify identity and authority in a way proportionate to the request and will not ask you to put passwords or recovery codes in ordinary chat. We may need to protect another person's information, preserve an organization's authorized records, or retain information required by law. We will explain material limits or a denial and respond within applicable legal deadlines.
Your statutory rights depend on your location and the laws that apply. Where available, they may include access, correction, portability, deletion, withdrawal of consent, objection or opt-out, and appeal. To appeal a denied request, reply to our response or email us with the subject “Privacy appeal.” You may also contact the relevant privacy regulator. Exercising an applicable privacy right will not result in unlawful discrimination.
10. Security, location, and children
We use safeguards appropriate to the actual service, including limited access and secure authorization where supported. The safeguards and storage arrangements needed for a pilot must be established before private information is accepted. No service can guarantee perfect security. We will address incidents and provide notices as required by applicable law.
ForwardCanon operates from the United States. Information may be processed in the United States and other countries where approved providers operate. We do not promise a specific storage region unless it is expressly agreed and technically supported. Where required, appropriate transfer arrangements must be in place.
Our services are intended for adults aged 18 and older. We do not invite children to provide personal information. If you believe a child has supplied information directly to us, contact us so we can investigate and take appropriate action. The initial pilot scope excludes patient records and other sensitive datasets requiring safeguards or agreements not yet established.
11. Policy updates
We will date published versions and give appropriate notice of material changes. If new processing requires consent, we will obtain it before beginning that processing. A changed policy does not retroactively authorize an unrelated use of information already collected.
Questions can always be sent to cordwilson@forwardcanon.com.