Privacy Policy
Last updated September 21, 2026
HitCanvas is a tool for making YouTube thumbnails, run by Core Access Technologies (“we”, “us”). This policy says what we collect when you use hitcanvas.com and app.hitcanvas.com, where it is kept, who helps us run the service, and how to have your data deleted. It describes what the product actually does. If that changes, this page changes with it.
The short version
- We store your email address and a hashed password. You do not sign in with Google, and we do not collect your Google profile.
- Connecting your YouTube channel is optional and read-only. We keep an encrypted access token and nothing we read with it.
- Reference photos you upload are sent to the image model to make your thumbnail and are not stored by HitCanvas, unless you choose to save that person as a persona.
- The thumbnails you make are kept privately for your workspace until you delete them.
- We use cookies only to keep you signed in. We run no advertising or analytics trackers.
- We do not sell your data.
What we collect
Your account
Accounts use an email address and a password. We store your name, your email address and a one-way hash of your password; we never store the password itself and cannot read it. We send email to that address to confirm it, to reset a password when you ask, and to deliver workspace invitations. We do not offer sign-in with Google or any other social account. If you choose to connect a YouTube channel, that is a separate, optional step, described below.
Your workspace
We store your workspaces, any clients inside them and who is assigned to each, their members and roles, pending invitations, API keys (stored hashed, shown to you once), brand kits including any logo you upload, your plan and monthly limits, and counters of how much of your allowance has been used: image generations, niche analyses and thumbnail concepts. We also record an estimate of what each paid model call cost us, by workspace, so we can price the service.
What you make
When you generate or save a thumbnail we keep the image, the editable text layers, and a record of how it was made: the description and headline you typed, the settings you chose, the niche analysis that guided it, the model used, the exact prompt sent to the model, and the time. The image files are held in private file storage; our database holds the record and the path to the file, not the file. Only members of your workspace, and API keys belonging to it, can retrieve them.
Reference photos of people
If you upload a photo of a person so the AI can put them in a thumbnail, that photo is sent to the image generation provider for that one request and, by default, is not stored by HitCanvas. It is not written to our database or our file storage, and it is not added to your library or to a brand kit. We record only how many photos were used. The resulting thumbnail, which shows that person, is stored like any other thumbnail you make. The provider processes the photo under its own terms, described below. Whoever the photo shows, you, an athlete, a guest, you must have the right to use it and their permission; the studio asks you to confirm that each time, and we record that you did.
Personas: saved people (optional)
So that you need not upload the same photos for every thumbnail, you can choose to save a person as a persona: yourself, or someone your videos are often about. This is the one case in which HitCanvas stores photos of a person, and it never happens on its own: it takes a separate click and a tick box confirming that the photos are of you, or that you have that person’s permission to keep them. We store the two or three photos you chose, of the front and sides of the face, the name you gave, who saved them and when they confirmed. The photos are held in private file storage, are available only to members of the workspace and the client that holds them, and are sent to the image generation provider only when you use that person in a thumbnail. An owner or admin can move a persona to another client, or name where a removed client’s work should go, which changes who can see it; nothing moves on its own. We do not create face templates or any other biometric identifier from them, we do not use them to recognise anyone, and we do not use them for anything except making your thumbnails. Deleting the persona deletes the photos immediately.
What we collect automatically
Our hosting provider keeps standard server logs, such as IP address, time, the page or endpoint requested and the response, for a limited period, for security and troubleshooting. We do not use Google Analytics, Mixpanel, PostHog or any similar product, and we do not build advertising profiles.
Cookies
We set cookies for authentication and your session only: they keep you signed in and remember which workspace you are in. We set no advertising cookies and no third-party tracking cookies.
YouTube data
HitCanvas uses YouTube API Services to retrieve public video and channel data: search results for the niche you name, and for those videos their titles, thumbnails, view counts and publication dates, and their channels’ subscriber counts. We use it to find which videos outperformed their channels and to describe what their thumbnails have in common. None of that touches your YouTube account.
- By using HitCanvas you are also agreeing to be bound by the YouTube Terms of Service.
- Google’s handling of data is described in the Google Privacy Policy.
- The figures we show, such as views and subscribers, are cached public data and may be out of date. They are not official YouTube analytics, and they are not click-through rates.
- If you ask HitCanvas to watch a video you have published, we store that video’s id, which of your thumbnails you tied it to, and one reading a day of its public view count.
- We keep public YouTube data for no longer than 30 days before it is refreshed or deleted.
If you connect your YouTube channel
An owner or admin of a workspace can choose to connect a YouTube channel by signing in with Google. This is optional, and HitCanvas works without it. We ask for one read-only permission: to view the channel’s YouTube Analytics reports (yt-analytics.readonly). We do not ask to see the account’s videos, comments, subscriptions or playlists. We cannot upload, edit or delete anything, and we do not receive your Google password.
- What we read: for a video you ask us to watch, and only if it belongs to the connected channel, its daily views, watch time, average percentage watched and the sources its views came from, over the last 28 days.
- What we use it for: only to show those numbers to the members of your workspace, beside the thumbnail you gave the video, so you can judge how it did. We do not use it for advertising, we do not sell or transfer it, and no person at HitCanvas reads it except with your permission for support, for security, or where the law requires.
- What we store: which channel is connected (learned from the first of its videos you watch), who connected it, and a refresh token encrypted with a key kept apart from the database. The analytics we read are fetched when someone opens the page and are not stored.
- How to stop: press Disconnect on the Published page. We revoke our access at Google and delete the token immediately. You can also remove HitCanvas at any time from your Google Account’s permissions page, after which the stored token no longer works, and we delete it when we next find that it fails or when you ask.
HitCanvas’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Who helps us run HitCanvas
We share data with these providers only so they can provide their part of the service:
- Vercel: hosts the website and the application, runs our servers, keeps server logs, and holds generated images and logos in private file storage (Vercel Blob). Requests to some image models pass through Vercel’s AI Gateway.
- Neon: hosts our PostgreSQL database, in Amazon Web Services’ US East (N. Virginia) region. It holds accounts, workspaces, members, invitations, API keys, usage records, brand kits, the records and designs of saved thumbnails, and cached niche analyses.
- OpenAI: generates and edits images, including every image made from a reference photo, and reads thumbnail images and text for niche analyses, headline suggestions, thumbnail concepts and reviews. It receives your description, your headline, the instructions we build from them, and any reference photos or thumbnail image in the request.
- Black Forest Labs and ByteDance, reached through Vercel’s AI Gateway: generate some images that do not involve a reference photo. They receive the text instructions for the image.
- Google: YouTube API Services, as described above, and Google sign-in if you connect a channel. We send Google the niche you search for; we do not send it your HitCanvas account details.
- Twilio SendGrid: delivers our account emails. It receives your email address and the content of those emails.
Image and language model providers may keep request data for a limited period for safety and abuse monitoring, under their own policies. We use OpenAI’s business API, and OpenAI states that it does not use content sent through that API to train its models unless the customer opts in.
How long we keep things
- Your account and workspace: until you ask us to delete them.
- Thumbnails, designs, brand kits and logos: until you delete them, or your workspace is deleted.
- Reference photos: not kept at all, unless you save a persona. A persona’s photos: until you delete that persona, or your workspace is deleted.
- A connected YouTube channel’s token: until you disconnect, or your workspace is deleted. What we read with it: not kept.
- Niche analyses: reused for up to three days, and deleted within 30 days. Public YouTube data: no longer than 30 days.
- Usage counters and cost estimates: kept while your workspace exists, as the record of what your plan allowed and used.
- Server logs: for the limited period our hosting provider keeps them.
Deleting your data
You can delete any thumbnail from your library and any brand kit from the studio at any time; the files go with them. To delete your account, or a whole workspace you own, email support@hitcanvas.com from the address on the account. We will delete the account, its workspaces where you are the only owner, and their thumbnails, designs, kits, keys and usage records within 30 days, and confirm when it is done. You can also ask us for a copy of your data, or to correct it, at the same address.
Security
Passwords and API keys are stored hashed. Traffic is encrypted in transit. Images and logos are in private storage and are served only after we have checked that the request comes from the workspace that owns them. No system is perfectly secure; if we learn of a breach affecting your data we will tell you.
Children
HitCanvas is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, email support@hitcanvas.com and we will delete it.
Where data is processed
Our database is in the United States, and our providers may process data in the United States and other countries.
Changes to this policy
When we change this policy we will update the date at the top. If a change affects how we handle your personal data in a significant way, we will also email the address on your account before it takes effect.
Contact
Core Access Technologies · support@hitcanvas.com