AI Vendor Directory · Image, video & audio generation
Does Canva train on your data?
No — does not train on your data by default. Vendor-stated default: no for Teams/Business/Enterprise and Education (control disabled — cannot even opt in); consumer Free/Pro governed by per-user Privacy Settings toggles. Canva's Trust Center states for Business/Enterprise accounts the AI-training control "is disabled... This means that we don't use your business, team or enterprise content to improve AI-powered features, and we don't allow third parties to do so either" (admin opt-in "coming soon"). Education user content is never used. For individual accounts, two Privacy Settings toggles govern use: "general usage and activity" (metadata, never content) and "your content" — Canva only uses content consistent with those settings; users can change them anytime. Canva Creators are paid for training use of their content and can opt out.
By the Shieldra Compliance Team · Last updated 2026-07-29
What is Canva (Magic Studio)?
Canva's suite of generative design tools (Magic Write, Magic Media, Magic Design, etc.) inside the Canva design platform. SMBs typically use it for marketing graphics, social content and presentations.
Key facts
- Vendor: Canva — https://www.canva.com/magic/
- Trains on customer data by default: no for Teams/Business/Enterprise and Education (control disabled — cannot even opt in); consumer Free/Pro governed by per-user Privacy Settings toggles
- Source for the training answer: https://www.canva.com/trust/privacy/
- Data residency: US
- Last verified: 2026-07-29
What certifications does Canva hold?
- ISO 27001
- SOC 2
- SOC 3
- PCI DSS
- Data Privacy Framework
Security, DPA, and subprocessor links
- Security / trust page: https://www.canva.com/security/
- Data processing agreement (DPA): https://www.canva.com/policies/data-processing-addendum/
- Subprocessor list: https://www.canva.com/policies/subprocessors/
What is your EU AI Act role when you build on Canva?
Your organization is a deployer under the EU AI Act; Canva is the provider responsible for machine-readable marking of synthetic media. Article 50 deepfake/synthetic-content disclosure duties can fall on you when publishing AI-generated images or video of real people or as apparent fact.
What to record in your AI registry
- Provider: Canva
- Model type: third party api
- Data typically flowing to the vendor: designs and uploaded media, brand assets, prompt text
Sources
- https://www.canva.com/trust/privacy/
- https://www.canva.com/security/
Disclaimer
Curated from vendor-published pages on the date above. Vendor terms change - verify against the cited sources before relying on a profile for a procurement decision. Last verified 2026-07-29.
Frequently asked questions
Does Canva train AI models on your data?
No — does not train on your data by default. Vendor-stated default: no for Teams/Business/Enterprise and Education (control disabled — cannot even opt in); consumer Free/Pro governed by per-user Privacy Settings toggles. Canva's Trust Center states for Business/Enterprise accounts the AI-training control "is disabled... This means that we don't use your business, team or enterprise content to improve AI-powered features, and we don't allow third parties to do so either" (admin opt-in "coming soon"). Education user content is never used. For individual accounts, two Privacy Settings toggles govern use: "general usage and activity" (metadata, never content) and "your content" — Canva only uses content consistent with those settings; users can change them anytime. Canva Creators are paid for training use of their content and can opt out.
What certifications does Canva hold?
Per the vendor's published pages as of 2026-07-29: ISO 27001; SOC 2; SOC 3; PCI DSS; Data Privacy Framework.
Where does Canva store your data?
Vendor-listed data residency options as of 2026-07-29: US.
What is your EU AI Act role when you build on Canva?
Your organization is a deployer under the EU AI Act; Canva is the provider responsible for machine-readable marking of synthetic media. Article 50 deepfake/synthetic-content disclosure duties can fall on you when publishing AI-generated images or video of real people or as apparent fact.