Gavana

Privacy

Effective July 30, 2026

What Gavana handles

Gavana processes the account details you use to sign in, the canvases and assets you create or share, and operational records needed to keep those items synchronized, secure, and recoverable.

AI providers and connected tools

When you explicitly generate content, Gavana sends the prompt, selected references, and generation settings to the provider you configured. When you connect ChatGPT or another MCP client, it can access only the Gavana permissions shown on the consent screen. OAuth and Agent Access credentials are stored encrypted and can be revoked.

How data is used

Data is used to provide the canvas service, execute actions you request, prevent abuse, diagnose failures, and protect accounts. Gavana does not sell your canvas content or use it for advertising. We also maintain aggregate, first-party service counts for completed sign-ins, Canvas creation, and feature-request submissions; these counts contain no Canvas content, prompts, asset data, account identifiers, provider settings, or access credentials.

Storage and retention

Canvas projects and uploaded assets remain until you delete them or your account is removed. Short-lived authorization codes and job artifacts expire automatically; security and operational records may be retained as needed to protect the service.

Your controls

You can remove canvas content, revoke connected Agent Access and OAuth credentials, and disconnect Gavana from ChatGPT. For account or privacy requests, use the contact path in the Gavana Help Center.