Legal

Privacy Policy

Last updated August 28, 2026 · Optinewsai LLC d/b/a Canu AI

1. Who we are

Canu AI is operated by Optinewsai LLC, doing business as Canu AI. This policy explains what data we handle when you use the Canu website, workspace, and MCP endpoint, and what choices you have.

2. Data we collect

We collect three categories of data:

  • Account data — name, work email, company name, workspace role, and authentication identifiers.
  • Connection data — financial and operational records retrieved from systems you connect, such as charges, invoices, subscriptions, vendors, transactions, and cloud spend.
  • Usage data — product events, page views, agent commands, approvals, and technical logs such as IP address, browser, and timestamps.

3. How we use data

We use data to operate the Service: to authenticate you, compute burn and runway, generate findings and forecasts, execute approved actions, maintain an audit trail, provide support, secure the platform, and bill your account.

We do not sell your data, and we do not share it with advertisers.

4. AI processing

Canu sends the minimum necessary context to model providers to answer your questions and generate findings. Prompts are scoped to your workspace and are never mixed across customers.

Model providers process this data as our subprocessors under contract, limited to delivering the response.

5. Credentials and connections

Where possible we use OAuth so we never see your passwords. Tokens and API keys are encrypted at rest and are only decrypted at the moment a request is made on your behalf.

You can revoke any connection from the Connections page at any time. Revoking stops all future access immediately.

6. Sharing and subprocessors

We share data only with service providers who help us run Canu — cloud hosting and database infrastructure, authentication, model providers, integration middleware, error monitoring, and payment processing — each bound by contractual confidentiality and security obligations.

We may also disclose data if required by law or to protect the rights and safety of our users.

7. Retention and deletion

We keep connection data for as long as your workspace is active. When you disconnect an integration we stop syncing and remove the associated records on our standard deletion cycle.

When you close your account we delete workspace data, except records we are legally required to retain, such as billing history.

8. Security

Data is encrypted in transit and at rest, access is scoped per workspace with row-level authorization, and privileged operations are logged. More detail is on our Security page.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.

To exercise any of these rights, email hello@usecanu.com and we will respond within the timeframe required by applicable law.

10. International transfers

Canu is operated from the United States. If you access the Service from elsewhere, your data may be transferred to and processed in the United States under appropriate safeguards.

11. Children

The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy. Material changes will be announced by email or in-product before they take effect.

13. Contact

Privacy questions: hello@usecanu.com — Optinewsai LLC d/b/a Canu AI.