Last updated: April 2, 2026 · Taciturn Studios LLC
The table below is a plain-English summary of the data boundary between your sites and DashCanopy. This applies to all features including the Dash AI agent, the monitoring dashboard, and all integrations.
| Data Type | ✓ DashCanopy CAN see | ✗ DashCanopy CANNOT see |
|---|---|---|
| Traffic & Visitors | Aggregate visitor counts, page view totals, sparkline trends pushed by your site | Individual visitor identities, IP addresses, browsing history, session recordings |
| Revenue | Total revenue figures you choose to push via your /api/stats endpoint | Individual transaction details, customer payment information, order contents, customer names |
| Uptime & Performance | HTTP status codes, response times, uptime percentage from public-facing URLs you register | Server logs, database query times, internal infrastructure details, error stack traces |
| Site Content | Article titles and slugs (only when Dash is explicitly instructed to audit or rewrite an article, and only transiently — not stored) | Article body content at rest, draft content, private pages, password-protected content, media files |
| Customer Data | Nothing — customer data from your sites is never transmitted to DashCanopy | Customer names, emails, addresses, purchase history, account details, any PII from your site's users |
| Email Lists | Nothing — subscriber lists are never shared with DashCanopy | Subscriber emails, names, segments, engagement history, MailerLite/Resend data |
| Database Contents | Nothing — your site's database is never accessible to DashCanopy | Any table, row, or column from your site's database |
| API Keys & Credentials | The DashCanopy API key you generate for push integrations (stored encrypted) | Your Stripe keys, MailerLite keys, hosting credentials, or any other third-party API keys from your sites |
| Webhook Events | Event type, timestamp, and summary payload you configure your site to push (e.g., "new sale: $49") | Full order objects, customer details, or any data beyond what you explicitly configure to push |
Dash is designed with a zero-retention content policy. Here is exactly what happens when Dash performs an action on one of your connected sites:
Dash receives your instruction (e.g., "audit the SEO on ArborSage"). No data has been accessed yet.
Using the API key you provided, Dash calls your site's tRPC or REST endpoint to fetch only the data needed for the task (e.g., article titles and meta descriptions). This call is authenticated with your own key — Taciturn Studios LLC does not have standing access to your site.
The fetched content is passed directly to the AI model (via Taciturn Studios LLC's LLM API) and processed in a single request. It is held in server memory only for the duration of that request — typically 5–20 seconds.
After the AI response is generated, the original content is discarded from memory.Taciturn Studios LLC's database stores only the run metadata: site name, action type, timestamp, and success/failure status. The actual article text, recommendations, or any other content is never written to Taciturn Studios LLC's database.
If the action produces an output (e.g., a rewritten article), it is pushed directly back to your site via the same authenticated endpoint and displayed to you in the Dash run log. Taciturn Studios LLC retains no copy.
The following data is stored in Taciturn Studios LLC's database as part of your DashCanopy account:
| Data | Why it is stored | How to delete it |
|---|---|---|
| Your name, email, and account ID | Account authentication and communication | Contact legal@dashcanopy.com to delete your account |
| Site names, URLs, and descriptions you add | Dashboard display and monitoring configuration | Delete sites from your dashboard at any time |
| Historical performance stats (visitor counts, revenue totals, uptime) | Trend charts and anomaly detection | Retained for 90 days; contact us to purge earlier |
| Webhook event summaries | Event log display in dashboard | Auto-purged after 30 days; delete manually from dashboard |
| Dash agent run metadata (site name, action type, timestamp, status) | Audit trail and run history display | Delete from Agent Settings → Run History at any time |
| Subscription and billing records | Payment processing and subscription management (via Stripe) | Retained per legal and tax requirements; contact us for details |
DashCanopy uses the following third-party services that may process data on our behalf:
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing and subscription management | Name, email, payment method (handled directly by Stripe — we never see card numbers) |
| Resend | Transactional email delivery | Your email address and the content of emails sent to you |
| OpenAI (LLM) | AI feature processing (Dash agent, diagnostics, content tools) | Only the content of your specific AI request — no persistent storage by the LLM provider |
| TiDB Cloud | Database hosting | All data stored in your DashCanopy account (encrypted at rest) |
Regardless of your location, you have the right to:
To exercise any of these rights, contact us at legal@dashcanopy.com. We will respond within 30 days.