90 Days Gen AI Risk Trial -Start Now
Book a demo
Design·Free; Pro $15/mo; Teams $10/user/mo; Enterprise custom (~$2k-$30k/yr)·canva.com

Canva AI

Canva's Magic Studio bundles 25+ AI features (Magic Write, Magic Edit, Magic Design, Dream Lab) into the Canva design platform across Free, Pro, Teams and Enterprise tiers.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Canva AI, marketed as Magic Studio, layers generative and editing AI into Canva's browser-based design tool. Features include Magic Write (text), Magic Design (template generation), Magic Edit and Magic Eraser (image editing), Dream Lab (text-to-image), Magic Switch (format resizing), and an AI video suite. The tools are distributed across Canva's existing tiers with per-plan usage caps (500 premium uses on Pro/Teams, up to 4000 standard uses on Enterprise). Canva's privacy policy states that user content, media uploads and account activity may be used to train their algorithms, models and AI products. An opt-out control exists in privacy settings, and Canva Education user content is contractually excluded from training. Canva is EU-U.S. Data Privacy Framework certified; SOC 2 is documented in their Trust Center but not prominent in the consumer policy. Data is stored across US, EU, UK, AU, SG, NZ and Philippines regions.

Risk factors

3
  • Cloud-based design tool that processes user-generated content.
  • Data shared with third-party services for feature enhancement.
  • Requires user authentication but may not have strong enterprise controls.

Recommendations

8
  • Purchase Canva Enterprise for SSO, SCIM, admin controls and DPA
  • Centrally disable AI training in privacy settings for all managed accounts
  • Use Brand Kits, folder permissions and access levels to contain confidential assets
  • Restrict third-party Canva Apps that request broad data access
  • Require SSO and enforce MFA on Canva Enterprise tenant
  • Classify and block uploads of regulated data (PHI, PCI, unreleased IP) via DLP
  • Audit Magic Studio prompt history for sensitive content leakage
  • Review Canva Trust Center SOC 2 report during annual vendor review

Data handling

Storage
Data stored in US, EU, UK, Australia, Singapore, New Zealand and Philippines. EU-U.S. Data Privacy Framework certified.
Retention
Retained for commercially reasonable period after account deletion; backups and legal-hold data kept longer.
Training on inputs
User content, uploads and activity used to train Canva AI by default. Opt-out available in privacy settings. Canva Education content excluded contractually.