SourceCanvas 1.5
SourceCanvas Privacy Policy
SourceCanvas is local by default. The app requires no account, includes no advertising tracking or developer analytics, and does not send documents or AI Host conversations to IonCreate.
Last updated: August 14, 2026
Documents and rendering
Core SVG, Mermaid, and Graphviz rendering runs on the device. Source, exports, and security-scoped folder authorizations stay in locations you choose or in the app container.
External SVG resources are blocked by default. If you explicitly enable secure remote resources, the app connects directly only to HTTPS or local resource hosts named by the document.
macOS MCP Agent
An MCP Host invokes the signed sourcecanvas-mcp helper over local stdio, which connects to Agent Service over local XPC. SourceCanvas provides no internet MCP endpoint and does not record Host conversations.
Agent configuration updates only the sourcecanvas entry and keeps local backups for file-based clients. SourceCanvas does not change Host trust or automatic approval. Information sent to ChatGPT, Claude, Cursor, VS Code, Gemini, or another Host remains subject to that Host's terms.
Local preferences and metadata
SourceCanvas uses UserDefaults for interface and Agent preferences and file timestamps to manage user-selected files and App Group preview sessions. These values are not used for tracking or sent to the developer.
The app privacy manifest declares these Required Reason APIs. It declares no tracking domains or collected data types.
Your controls
You can disable Agent Service, remove authorized folders, undo a client configuration, or delete local documents at any time. Unpinned preview history is cleaned according to the app's local retention policy.
Contact
Email privacy questions to [email protected]. This policy will be updated when features or data handling change.