Privacy and remote resources
Canon verifies public blockchain data. To do that, its server queries Radiant ElectrumX servers for the transactions involved in a verification. The references you verify are part of those queries.
Remote media is never fetched by our servers. When a Glyph points at an off-chain URL, Canon displays the URL as text. If you choose to check its digest, your own browser fetches it directly — the media host will see your request, not ours.
QR scanning happens on your device. Camera frames are processed locally and never uploaded.
Receipts are validated in your browser. Importing a receipt sends only the references it names to our server for on-chain verification; the receipt file itself is not uploaded or stored, and receipts are not logged.
Canon keeps short-lived caches of blockchain data as a performance optimization and standard operational logs for abuse prevention (rate limiting). No accounts, no wallets, no tracking pixels.