Privacy Policy

Effective 3 October 2026

1. Overview

This Privacy Policy explains what information Orbital Softworks ("we", "us") handles when you use Qanvas and this website, and what stays on your own machine. Qanvas is local-first: the builder runs on your device, and we collect the minimum needed to sell and support it.

2. Local-First Storage

Your projects, pages, content, configuration and generated code are stored on your machine in your project directory. They are not uploaded to our servers, and we do not have access to them. You are responsible for backing up your own projects.

3. Direct BYOK Routing

AI-assisted features use an API key that you provide. The key is stored only in your browser's local storage or in a local .env.local file on your machine. Requests that use it are sent directly from your environment to the AI provider you choose; they are never routed through, copied to, or stored on our servers, and we never receive your key.

What the provider does with the content of your requests is governed by that provider's own privacy policy and terms, which you should review before use.

4. Stripe Payment Processing

Paid licenses are purchased through Stripe. Payment card details are entered on Stripe's pages and are processed by Stripe; we never see or store your full card number. From Stripe we receive confirmation of the purchase, together with the name and email address associated with the checkout, which we use to issue your license key, deliver it to you, and keep records of the sale. Stripe's handling of your data is described in Stripe's privacy policy.

5. Support Intake

If you choose to submit a support or diagnostic ticket, the contents of that ticket, including any contact details and technical information you include, are transmitted to us and used only to investigate and respond to your request and to improve Qanvas. Please do not include secrets such as API keys or passwords in a ticket. We retain tickets for as long as needed to resolve the request and to maintain a support history, then delete or anonymize them.

6. No Tracking

The local Qanvas builder sends no telemetry or usage analytics. This website does not use advertising cookies, cross-site tracking or third-party analytics, and we do not sell or share personal information for advertising.

7. Offline Licensing

A license key is validated locally on your device. Qanvas does not need to contact our servers to check a license after it has been issued, and license validation does not transmit information about you or your projects.

8. Your Choices and Rights

Depending on where you live, you may have the right to access, correct, delete or export personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, contact us through the support channel listed on this site. We will respond within the time required by applicable law.

9. Changes and Contact

We may update this policy from time to time and will change the effective date above when we do. Questions about privacy can be sent through the support channel listed on this site.