Copy the HTML out of a ChatGPT Canvas, upload it to a host, and the page can contact a CSS CDN and Google Fonts before a visitor has clicked anything. That is where the General Data Protection Regulation (GDPR) work for a Canvas app starts: with what the page loads, what it keeps on the device and what happens to anything people type in. This GDPR checklist runs through 9 checks in the order a visitor meets them, for the three places an app you built in canvas can be in October 2026: a shared canvas link, your own hosting, or a rebuild as a ChatGPT Site.

Before you read on

  • OpenAI removed canvas from GPT-5.5 Instant and GPT-5.5 Thinking on 28 May 2026 and moved writing and code into blocks inside the chat, which cannot be published as a page.
  • A shared canvas link opens on chatgpt.com, where OpenAI sets the cookies and your code cannot add a consent banner around the page.
  • On a ChatGPT Site or your own host, you decide what visitor data is collected and why, which makes you the controller for it.
  • A page that loads nothing from other companies and stores nothing optional leaves very little to fix.

Canvas apps now live in one of three places

Canvas was the side-by-side editor for writing and code in ChatGPT, introduced on 3 October 2024. It rendered HTML and React in a sandboxed preview, shared a canvas through a link and downloaded code with the right file extension.

That changed this year. OpenAI's model release notes for 28 May 2026 say canvas is no longer available in GPT-5.5 Instant or GPT-5.5 Thinking, and that writing and coding now happen in writing blocks and code blocks inside the chat. Paid users could keep canvas on legacy models for a limited time, until those models were retired, and the same notes set the retirement of OpenAI o3 from ChatGPT for 26 August 2026.

The blocks have grown since. According to the ChatGPT release notes, writing blocks gained a full-screen editor, saving to the Library and downloads on 8 June 2026, and since 7 October 2026 GPT-6 answers in ChatGPT can include interactive elements such as calculators and small tools, which OpenAI calls Intelligent UI. All of them live inside a conversation: none is a page with your own address. On 9 October 2026, OpenAI's help article on canvas answered with a page that says it does not exist, in English and in Latvian, and the help centre search for canvas returned no article about it.

The app you built is still somewhere, and where it lives decides who sets the cookies and who answers for the data:

Where the app livesWho runs the pageWhat you control
A shared canvas link on chatgpt.comOpenAIThe code inside the preview, nothing around it
A ChatGPT SiteOpenAI hosts it, you publish itContent, forms, storage and who can open it
Your own host, from exported codeYou and your hosting providerEverything the page loads and stores

ChatGPT Sites is not canvas's successor. OpenAI launched it in public beta on 9 July 2026 as a separate product: you start a Site from ChatGPT Work or Codex and describe what to build, so a canvas app moves there as a rebuild, not an import. OpenAI's help article on creating Sites lists it for Plus, Pro and workspace plans, not for Free or Go. At launch, public publishing was not available in the EEA, Switzerland or the United Kingdom. Its current version, updated in early October 2026, no longer names a regional limit, so check that your account can publish publicly before you plan a European launch on it.

The same split runs through most AI app builders: the builder's preview belongs to the builder, the published app to whoever publishes it. The checks below are yes or no questions, and a no is a task before launch: the last section says which fix each one usually needs.

A shared canvas link runs on OpenAI's page

A shared canvas link is a page on chatgpt.com that shows a copy of your canvas to whoever opens it. OpenAI runs that page and sets its cookies, and nothing in your code changes them. The link suits a prototype you want a colleague to try, and it is a poor home for an app that asks visitors for anything.

A plain HTTP request on 9 October 2026 to a made-up shared canvas address on chatgpt.com showed what happens before anything renders. The server redirected it to the home page with canvas_not_found in the address. It also set five cookies, among them oai-did with a lifetime of 31,104,000 seconds, which is 360 days. So the shared canvas route itself is still there, months after the May change.

Those cookies are OpenAI's to explain and to ask consent for, and your part is the code inside the preview. If it sends what people type to a server you chose, that request is yours wherever the page sits, and the last archived copy of OpenAI's canvas article (20 July 2026) said previews ask the user to confirm before they talk to third parties OpenAI does not know about. The same question comes up with Claude Artifacts published from claude.ai.

Check 1: can you add your own notice and consent choices where the app lives?

On a shared canvas link the answer is no, because the page is not yours to change. Move any app that collects data or loads trackers to your own host first, or rebuild it as a ChatGPT Site where your plan and region allow public publishing. How to verify: open the public address in a private window. Look for a privacy notice and a way to refuse that belong to you, not to the platform.

What the page loads before anyone clicks

An exported app can be a single HTML file, and one file can still reach several companies. Each request to another server carries the visitor's IP address, which the GDPR can treat as personal data, whether or not a cookie comes back with it.

Check 2: does every file the page loads come from your own host?

A single-file app can pull its CSS framework, fonts and JavaScript libraries from public CDNs. On 9 October 2026, requests to cdn.tailwindcss.com, fonts.googleapis.com, unpkg.com, esm.sh and cdn.jsdelivr.net set no cookies at all. The IP address travels anyway, which makes this a GDPR question rather than a cookie question.

A German court has already put a price on it. In judgment 3 O 17493/20 of the Munich Regional Court, dated 20 January 2022, a website had loaded Google Fonts from Google's servers and passed a visitor's IP address to Google without consent. The court ordered the operator to pay €100 in damages. It found nothing that justified the transfer, because the fonts can be used without contacting Google when the page loads.

Where an exported Canvas app sends data, in order

An example single-file app exported from ChatGPT Canvas, in the order of a first visit. Step 1: your host sends the page and logs the visitor's IP address, which stays with your host. Step 2: Tailwind CSS loads from cdn.tailwindcss.com, another company, which receives the IP address. Step 3: a font loads from fonts.googleapis.com, another company, which receives the IP address. Step 4: the app saves its state in local storage on the visitor's device, where it stays. Step 5: a form sends what the visitor typed to an API, a spreadsheet or an inbox run by another company. A check mark means your host or the visitor's device, and a warning triangle means another company receives it.1Your host sends the pageYour host logs the IP address2Tailwind loads from a CDNcdn.tailwindcss.com3A font loads from Googlefonts.googleapis.com4The app saves its stateLocal storage, on the device5A form sends data outTo an API, sheet or inboxYour host or the visitor's deviceAnother company receives it
Steps 2 and 3 happen before anyone clicks. On 9 October 2026 neither host set a cookie, but both received the visitor's IP address, and serving the files from your own host removes both requests.

How to verify: open the deployed page with the browser's developer tools on the Network tab, reload, and list every domain that is not yours. The Tailwind Play CDN script prints its own warning in the console, cdn.tailwindcss.com should not be used in production. Download the font and the libraries, serve them from your host, and the list shrinks to one domain.

Check 3: do embeds and analytics wait for consent?

Analytics tags, a map, a chat widget or a YouTube embed set or read their own cookies, and those need consent before they run. The rule sits in the ePrivacy Directive, in Article 5(3) of the consolidated Directive:

Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing.

In plain English: anything optional that touches the visitor's device waits for a yes. Kukie.io's script blocking holds tags like these until the visitor accepts the category they belong to. How to verify: open the page in a private window, refuse everything, then check the cookies and storage panel of the developer tools. Nothing optional should be there.

Local storage is fine until it leaves the device

An app that saves its own state in local storage, such as a to-do list or a half-finished form, uses the visitor's device for the feature that visitor asked for. Article 5(3) exempts storage that is strictly necessary for a service the visitor explicitly requested, and an app's own working state is the kind of use that exemption describes, unlike a tracking identifier kept in the same place.

The European Data Protection Board (EDPB) draws a second line. In Guidelines 2/2023 on the technical scope of Article 5(3), adopted on 7 October 2024, it says a browser app using information stored on the device does not gain access to it as long as the information does not leave the device. Once the app sends that information, or anything derived from it, to a server, Article 5(3) applies.

Check 4: does anything the app stores leave the device?

Look for values that start in storage and end in a request: a visitor ID sent with every form, a saved score posted to a leaderboard, a list synced to a spreadsheet. How to verify: in the developer tools, open the storage panel and note every key, then search the code for each key name near a fetch call.

A form makes you responsible for what people type in

The moment a Canvas app collects a name, an email address or a free-text answer and sends it somewhere, someone decides why that data is collected and what happens to it. For an app you publish, that someone is you, the data controller. OpenAI says the same about ChatGPT Sites, its hosting feature for apps built in ChatGPT. Its help article on ChatGPT Sites and data protection laws states that under the ChatGPT Sites Terms the Site owner is the data controller of End User Data, and that OpenAI processes it under its Data Processing Addendum.

Check 5: does every form field have a reason to exist?

Article 5(1)(c) GDPR asks for data that is adequate, relevant and limited to what is necessary for the purpose. A generated form can ask for more than the feature uses, such as a phone number on a newsletter sign-up or a date of birth on a quiz. How to verify: for each field, name the feature that breaks without it, and delete the fields nobody can name.

Check 6: does a privacy notice say where the data goes?

Article 13 GDPR lists what people must be told when their data is collected: who you are, why you collect it, the legal basis, who receives it, how long you keep it and what rights they have. A one-page privacy notice linked from the form covers it. It has to name the real recipients, including the form backend and the host. How to verify: compare the recipients in the notice with the domains from check 2 and the endpoints from check 4.

Check 7: is there a contract with every service that receives the data?

Article 28 GDPR requires a contract with each processor: the host, the form backend, the email tool and any AI API the app calls. On a ChatGPT Site, OpenAI points to its Data Processing Addendum, or one your organisation signed with OpenAI, for that role. The same OpenAI article notes that Sites does not support data residency or inference residency at launch. Read where the data is stored before you rely on any transfer mechanism for EU visitors. How to verify: list every processor next to its signed or accepted data processing terms.

Check 8: are API keys and secrets out of the browser code?

If an exported app calls an AI API or a database straight from the browser, the key ships to every visitor in the page source. Article 32 GDPR asks for security appropriate to the risk, and a public key that opens your database fails that test the first time someone reads the source. How to verify: open the page source and search for sk-, apiKey and Bearer, then move any hit behind a server function.

Visitors need a way to change their mind

Check 9: can a visitor withdraw consent and ask for their data?

Article 7(3) GDPR is short on this point: "It shall be as easy to withdraw as to give consent." In practice, a choice made in a banner needs a link that reopens it from every page, and a request to see or delete data needs an address that someone reads. Article 12(3) gives you one month to answer, extendable by two further months for complex requests. How to verify: find the link that reopens the choices on a page other than the home page, and send a test request to the address in your notice.

What to do when a check fails

Most failures share a fix. A failed check 1 means a move: export the code to your own host, or rebuild it as a ChatGPT Site where you can publish a notice and consent choices. Checks 2 and 3 fail on third-party requests, and the answer is to serve the file yourself or hold the tag until the visitor agrees. Checks 4 to 9 are paperwork and plumbing: fewer fields, a notice that names the recipients, contracts, a server function for secrets and a link that reopens consent. None of them needs the app rebuilt.

Short answers on Canvas apps, links and cookies

Can I put a cookie banner on a shared canvas link?

No. A shared canvas link opens on chatgpt.com, and the cookies on that page are set and explained by OpenAI. If the app needs its own notice and consent choices, publish it on your own host or as a ChatGPT Site.

Is ChatGPT Canvas still available?

Not in current models. OpenAI removed canvas from GPT-5.5 Instant and GPT-5.5 Thinking on 28 May 2026 and moved writing and code into blocks in the chat. Paid users could keep it on legacy models only until those were retired, and OpenAI set the retirement of o3 for 26 August 2026.

What replaced ChatGPT Canvas?

Writing blocks and code blocks inside the chat, which open full screen and save to the Library since June 2026, and since 7 October 2026 interactive elements in GPT-6 answers. ChatGPT Sites is a separate product for publishing websites and lightweight apps, not a canvas replacement.

Does local storage need consent like a cookie?

Article 5(3) of the ePrivacy Directive covers any storage on the visitor's device, not only cookies. Storage that is strictly necessary for the feature the visitor asked for is exempt, and the EDPB says reading it is not access while the information stays on the device.

Who is the data controller for a ChatGPT Site?

OpenAI's help article on Sites and data protection says the Site owner is the data controller for visitor data under the ChatGPT Sites Terms. OpenAI processes that data under its Data Processing Addendum.

See what your exported app loads before launch

If your Canvas app now sits on your own host or a ChatGPT Site, run its address through the Script audit. It lists the third-party scripts the page loads, so checks 2 and 3 start from a list instead of an empty Network tab.