← back to canvas

Privacy Policy

Datenschutzerklärung — Collaborative AI Canvas

Please read: This is a plain-language document for a non-commercial art experiment; it is not legal advice. A review by a German lawyer is planned before any commercial use.
Note on language: This privacy policy is provided in English only. The site is operated from Germany and the EU General Data Protection Regulation (GDPR / DSGVO) applies. Diese Datenschutzerklärung wird ausschließlich in englischer Sprache bereitgestellt.

1. Controller

The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is the operator of this site — an individual in Germany running the project privately and non-commercially. The operator participates anonymously; postal contact and legal service are handled through a contact channel listed in the site footer.

There is no designated data protection officer; the project does not meet the thresholds of Art. 37 GDPR / § 38 BDSG.

2. Summary

This site has no user accounts, no analytics, no advertising, no tracking pixels, no third-party embeds and no profiling. It collects the minimum needed to run a shared canvas fairly and keep bots out. Concretely: an anonymous session cookie, your IP address held only in memory for rate-limiting, a Cloudflare bot check, and your text prompt.

Important: your prompt text is public. Every submission that passes automated content moderation is stored and displayed to all visitors in a live feed on this site, attributed to a short anonymous session handle such as anon-x4f2. Prompts rejected by moderation are not stored and never shown. Whatever you type into the prompt box is published as written, so never enter personal information about yourself or anyone else. The handle is a random identifier — it carries no name, account or contact detail — but any personal data you put into the prompt yourself will be visible to everyone.

Because no analytics or marketing cookies are used, there is no cookie consent banner.

3. What is processed, why, and on what legal basis

3.1 Anonymous session cookie

When you first interact with the canvas, a cookie is set containing a randomly generated, signed session identifier. It contains no name, no email address, no account and no profile — it exists solely to enforce “one submission per session per round” and to show you the result of your own submission.

3.2 IP address (transient, never stored)

Your IP address is visible to the server when your browser makes a request, as with any website. It is used only in volatile memory, for the duration of a round, to count submissions per network and block flooding. It is never written to a database, never written to a log file, and never persisted in any form; the in-memory counters are discarded each round.

Note that the hosting provider (see section 4) processes connection data, including IP addresses, independently at the network level for delivery and security purposes.

3.3 Cloudflare Turnstile (bot check)

Before a submission is accepted, a Cloudflare Turnstile challenge runs in your browser. Turnstile is a privacy-oriented alternative to a CAPTCHA: it evaluates signals from the browser environment (such as browser characteristics and interaction behaviour) to decide whether the request comes from a human, and issues a single-use token that the server verifies. It usually requires no interaction from you. According to Cloudflare, Turnstile does not use the data for advertising or cross-site tracking. Loading the widget transmits your IP address and browser data to Cloudflare.

3.4 Your prompt text — stored and published

The text prompt you submit (maximum 500 characters) is first checked by automated content moderation. If it is rejected, it is discarded immediately and is neither stored nor shown to anyone. If it passes, it is stored and published: displayed to all visitors in the live submission feed on this site, next to a short anonymous session handle such as anon-x4f2. This applies to every accepted submission, not only to those that win a round. If your submission wins the round lottery, the prompt is additionally sent to the AI provider to generate the image (see section 4).

Only the anonymous session handle is shown with a prompt. It is derived from the random session identifier in your cookie and contains no name, email address or account. It does, however, group together the prompts submitted from the same browser session during the event, so avoid writing anything across several prompts that could identify you in combination.

3.5 Shapes and generated images

The shape you draw and the image the AI generates inside it are — like the prompts — public by design. They are painted onto a shared canvas that anyone can view, screenshot and share, they form part of a collective artwork, and they are recorded in an event log so that a timelapse film and other derivative works can be produced after the event. They are not linked to any name and cannot be traced back to you by visitors; the anonymous session handle described in section 3.4 may be shown alongside them, for example in the result notification.

3.6 What is not done

This list is about tracking and marketing, not about secrecy of your submission: the prompts, shapes and images you contribute are published, as described in sections 3.4 and 3.5.

4. Recipients and processors

RecipientRole & data
Cloudflare
(Workers, R2, D1, Turnstile)
Hosting, edge delivery, object and database storage, and the bot check. Processes connection data (including IP address), the session cookie, stored images, stored prompt texts and event-log entries. Acts as processor under Art. 28 GDPR on the basis of Cloudflare's data processing addendum.
OpenAI
(image generation & moderation)
Receives the prompt text together with a fixed system prompt and the shape mask, in order to run moderation and generate the image. Receives no cookie, no session identifier and no direct identifier of you. Established in the USA (OpenAI, L.P. / OpenAI Ireland Ltd. for EEA users).
Google
(Gemini image models — testing only)
May be used as an alternative image-generation provider during testing or as a fallback. Same data as above: prompt text and shape mask only.

No other recipients in the sense of contracted processing. Data is disclosed to public authorities only where legally required. Beyond this, note that the prompt feed and the canvas are public: everyone on the internet can read the prompts you submit — that is the point of the project, not a transfer to a processor.

5. Transfers to third countries

Processing may involve transfers to the United States, in particular to Cloudflare, Inc. and to the AI provider used for generation. These transfers are safeguarded by the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures (transport encryption, data minimisation), and — where the recipient is certified — by the EU–US Data Privacy Framework adequacy decision under Art. 45 GDPR.

Despite these safeguards, a residual risk remains that US authorities may access data. Because the only content transferred to the AI provider is your prompt text and the shape you drew — the same prompt text that is in any case published openly on this site — you can eliminate this risk for yourself simply by not including personal information in your prompt.

6. Retention

DataRetained
Session cookie / session identifier4 days
IP addressNot retained — in memory only, cleared each round
Prompt text — rejected by moderationNot retained — discarded immediately, never stored or shown
Prompt text — accepted, published in the feedDuration of the project and thereafter for archival and timelapse purposes, as part of the artwork
Anonymous session handle shown with a promptSame as the published prompt it belongs to
Generated images, shapes, event logDuration of the project and thereafter for archival and timelapse purposes, as part of the artwork
Turnstile token hashesDuration of the current round only

Because the prompts, images, shapes and event log constitute the artwork itself and the source material for the timelapse film, they are kept indefinitely for archival and artistic purposes. They contain no identifiers assigned by the operator beyond the random session handle — but a published prompt contains whatever text its author typed, which is why you are asked not to put personal data there.

7. Your rights

Under the GDPR you have the right to:

Requests can be sent via the contact channel listed in the site footer.

An important practical limitation: the project deliberately stores almost nothing that could identify you. There is no account, and IP addresses are never persisted. What is stored — the prompt text, the shape, the image and the random session handle — normally cannot be linked to you as an individual, so under Art. 11 GDPR the operator is not obliged to obtain additional information solely in order to identify you. If you want to exercise a right in relation to a specific submission, please identify it precisely: the session handle shown with it and the approximate time, or the exact wording of the prompt. You can delete the session cookie yourself at any time through your browser settings; it expires on its own after 4 days.

Removing a published prompt. If a prompt in the feed contains personal data — yours or someone else's — or should not be there for any other reason, report it via the contact channel listed in the site footer and it will be reviewed and, where appropriate, deleted. The same applies to a generated area on the canvas: describe where and when it was drawn. Note two limits: the Terms of Use reserve the right to remove or overpaint any content in any case, and content that was publicly visible may already have been copied, quoted or archived by third parties, which the operator cannot reverse.

8. Security

All traffic is served exclusively over HTTPS. The session identifier is cryptographically signed to prevent tampering, and only a short derived handle — never the full identifier — is shown publicly. Prompts pass automated content moderation before they are stored or displayed. The service runs on Cloudflare's edge platform with its standard technical and organisational protections. Please keep in mind that the prompt feed is intentionally public: security measures protect the system, they do not make your submission private.

9. Changes

This policy may be updated if the technical setup changes — for example if the image provider changes. The version published on this page is the current one.

10. Contact

For privacy questions, rights requests and data protection matters, please use the contact channel listed in the site footer.