- Home
- Privacy Policy
Legal
Privacy Policy
What personal data Capibud collects on www.capibud.com and in the Capibud app, why we collect it, who helps us process it, where it is stored and how you can exercise your rights. We do not sell personal data and we do not run advertising.
Draft for review by counsel. Last updated 8 October 2026.
1 · Who we are
The controller
Capibud Inc. ("Capibud", "we", "us") decides how and why personal data is processed on www.capibud.com (the "site") and for accounts on app.capibud.com (the "app"). Under the EU and UK GDPR we are the controller; under India's Digital Personal Data Protection Act, 2023 we are the Data Fiduciary.
For anything in this policy, write to hi@capibud.com. That address also reaches the person who handles privacy requests and grievances.
When a customer puts its own business data into a workspace under a written agreement, the customer is usually the controller of that data and Capibud processes it on the customer's instructions. That agreement governs, and this policy covers the rest.
2 · What we collect
The personal data involved
On the site
- What you send us. The contact and Decision Sprint form asks only for your work e-mail. It either sends that address with a note of where you sent it from, or opens an e-mail to hi@capibud.com in your own mail program. Anything you write in an e-mail to us is kept with it.
- Usage analytics, only if you accept. Pages viewed, clicks on contact links, how far down a page you scrolled, which version of the home-page headline you saw, your browser and device type and an approximate location derived by the provider. PostHog is set to discard IP addresses. If Microsoft Clarity is turned on, it also records how the home page is used (clicks, scrolls and mouse movement), again only after you accept.
- Country. Our edge server reads the country that Cloudflare derives from your connection and writes it into the page so the site can decide whether to ask for consent before anything is stored. We do not set a cookie for it or store your IP address.
- Choices stored on your device. Your theme, your analytics choice and the headline version you were shown (see cookies and local storage).
- Security logs. Like any website, our hosting and network provider processes IP addresses and request details briefly to deliver pages and block abuse.
In the app
- Account data. Name, work e-mail, organisation, role and workspace membership. If you sign in with Google or Microsoft, we receive your name, e-mail address and an account identifier from them. We never see your Google or Microsoft password.
- Session and security data. A session cookie, the time of sign-in, the IP address and browser string recorded with the session, and an audit trail of actions such as approvals and changes.
- Content you or your organisation provide. Files, workspace data, comments, votes and decisions. Business content can contain personal data, such as the names of approvers or project staff in a document.
- Diagnostics. Error reports and performance traces. These are scrubbed before they leave our servers: they keep opaque user and workspace identifiers and URL paths, and drop names, e-mail addresses, phone numbers, cookies, tokens, request bodies and document contents.
- Product analytics, only if you allow it. Usage events tied to an opaque user ID, never to your name or e-mail. No session recording, and no IP address.
We do not ask for, and ask you not to upload, special categories of data (health, religion, biometrics and similar) or government identifiers.
3 · Why, and on what basis
Purposes and legal bases
For people in the EU, the UK and other places with similar laws, these are the purposes and the legal basis for each.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Reply to your enquiry or Decision Sprint request | Work e-mail, your message | Steps you ask for before a contract (Art. 6(1)(b)), or our legitimate interest in answering business enquiries (Art. 6(1)(f)) |
| Measure and improve the site and the app | Analytics events | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
| Remember your theme and consent choices | Values on your device | Strictly necessary for a service you asked for |
| Provide the app: sign-in, workspaces, decisions | Account, session and content data | Performance of our contract with you or your organisation (Art. 6(1)(b)) |
| Keep the site and app secure, find and fix faults | Security logs, session records, scrubbed diagnostics | Our legitimate interest in running a secure, reliable service (Art. 6(1)(f)) |
| Optional AI features in the app | The text and data you send to the feature | Performance of our contract (Art. 6(1)(b)) |
| Meet legal duties and defend claims | Records we are required to keep | Legal obligation (Art. 6(1)(c)) or legitimate interest (Art. 6(1)(f)) |
We do not use personal data for advertising, we do not sell or rent it, and we do not make decisions about people based solely on automated processing that have legal or similarly significant effects on them. AI features in the app draft proposals; a person approves every change.
4 · Notice for India
Digital Personal Data Protection Act, 2023
If you are in India, this section is our notice to you as a Data Principal.
- What and why. The personal data and purposes are listed in section 2 and section 3. We process personal data for analytics only with your consent, and for the app to provide the service you or your organisation signed up for.
- Withdrawing consent. You can withdraw consent as easily as you gave it: use cookie settings on the site, the consent control in the app, or write to us. Withdrawal does not affect processing that happened before it.
- Your rights. You can ask for a summary of the personal data we hold about you and how we process it, the identities of those we have shared it with, and correction, completion, updating or erasure of your data. You can also nominate another person to exercise your rights if you die or become incapacitated.
- Grievances. Write to hi@capibud.com with "Grievance" in the subject. We will acknowledge it and respond within the period the law sets. If you are not satisfied, you can complain to the Data Protection Board of India.
5 · Cookies and local storage
What is stored on your device
The site itself sets no cookies. It keeps a few small values in your browser's local storage, and analytics tools add their own only after you accept. In the EEA, the UK and Switzerland, nothing that needs consent is stored until you accept. You can change your choice at any time with cookie settings, or clear site data in your browser.
On www.capibud.com
| Name | Kind | Purpose | How long | Consent |
|---|---|---|---|---|
cb-mode, cb-brand | Local storage | Your light, dark or system theme | Until you clear it | Not needed |
cb-consent | Local storage | Remembers whether you accepted or declined analytics | Until you clear it | Not needed |
cb-hero | Local storage | Keeps the same home-page headline version on each visit while we test which headline is clearer | Until you clear it | Asked for in the EEA, UK and Switzerland; elsewhere stored by default |
ph_*_posthog | Cookie and local storage (PostHog) | Counts visits and events without identifying you by name | Up to 1 year | Only after you accept |
_clck, _clsk and related | Cookies (Microsoft Clarity) | Home-page usage analysis, only if we turn Clarity on | Up to 1 year | Only after you accept |
On app.capibud.com
| Name | Kind | Purpose | How long | Consent |
|---|---|---|---|---|
phx_session | Cookie (HttpOnly, Secure, SameSite=Lax) | Keeps you signed in | Up to 12 hours | Not needed |
Keycloak cookies such as KEYCLOAK_SESSION and AUTH_SESSION_ID | Cookies on auth.capibud.com | The sign-in service, including Google and Microsoft sign-in | Session, or until the sign-in session ends | Not needed |
capibud-consent, phx-prefs | Local storage | Your analytics choice and display preferences | Until you clear it | Not needed |
| PostHog cookie and storage | Cookie and local storage | Product analytics by opaque user ID | Up to 1 year | Only after you allow it |
| Microsoft Clarity cookies | Cookies | Usage analysis on public demo workspaces only, if turned on | Up to 1 year | Only after you allow it |
6 · Who processes it
Processors and sub-processors
We use these providers to run the site and the app. Each processes personal data only to provide its service to us, under its data processing terms.
| Provider | What it does for us | Where |
|---|---|---|
| Cloudflare | DNS, content delivery and security for both domains; hosting of the site; e-mail routing for hi@capibud.com; R2 file and backup storage; text embeddings for search in the app | Global network; R2 storage in Asia-Pacific |
| Railway | Hosting for the app, its sign-in service and its job workers | Singapore |
| Neon | The app's Postgres database | Singapore (AWS ap-southeast-1) |
| Keycloak (self-hosted on Railway) | Sign-in and single sign-on with Google and Microsoft | Singapore |
| Google, Microsoft | Identity providers when you choose to sign in with them | Per their own terms |
| Anthropic (Claude) | Optional AI features in the app. Under Anthropic's commercial API terms, inputs and outputs are not used to train its models. | United States |
| Better Stack | Error tracking for the app (scrubbed reports) and uptime monitoring | United States |
| New Relic | Backend performance traces and metrics (scrubbed) | United States |
| PostHog | Consent-based analytics on the site and in the app; IP addresses discarded | United States |
| Microsoft Clarity | Consent-based usage analysis, only where turned on | United States |
| Resend | Account e-mails from the sign-in service, such as verification and password reset | United States |
We may also disclose personal data to professional advisers, to a buyer or successor if the business is sold or reorganised, or where the law requires it. We will update this list before adding a provider that processes customer data, and customers under contract can ask to be told of changes.
7 · International transfers
Where data goes
The app's main data stores are in Singapore and the Asia-Pacific region. Some providers above are in the United States, and Cloudflare serves pages from data centres near you. When personal data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the provider's data processing agreement, including the European Commission's Standard Contractual Clauses and the UK addendum where they apply. For transfers out of India, we follow any restrictions the Government of India notifies under the DPDP Act.
8 · How long we keep it
Retention
- Enquiries. For as long as the conversation is active, then up to [24 months] after the last contact unless it turns into a customer relationship.
- Site analytics. Up to [24 months], then deleted or aggregated so it no longer relates to a person.
- Values on your device. Until you clear them; we cannot reach them.
- App accounts and workspace content. For as long as the account or the customer agreement runs. After it ends we delete or return it on request, and in any case within [90] days, except as below.
- Backups. Daily database backups roll off after 35 days.
- Decision record. The app's decision record is append-only and tamper-evident by design, so entries cannot be edited in place. If you ask us to erase your personal data, we remove or replace identifying details wherever the record allows and restrict the rest, and we tell you what remains and why.
- Diagnostics. Kept for the provider's standard retention period, usually weeks, and scrubbed of names and e-mail addresses before they are sent.
9 · Security
How we protect it
All traffic is encrypted in transit with TLS, and the database and file storage are encrypted at rest by their providers. Sign-in goes through Keycloak with Google or Microsoft single sign-on; administrative access requires multi-factor authentication and is restricted at the network edge. Session cookies are HttpOnly and Secure. The app rate-limits requests, writes an append-only audit trail, scrubs personal data from diagnostics, and keeps daily backups that we test by restoring them. No system is perfectly secure; if a breach affects your personal data, we will tell you and the relevant authorities as the law requires. To report a vulnerability, see our security.txt.
10 · Your rights
What you can ask for, and how
Depending on where you live, you can ask us to:
- give you a copy of your personal data and tell you how we use it;
- correct or complete it;
- erase it;
- restrict how we use it, or object to processing based on our legitimate interests;
- send it to you or another provider in a portable format;
- withdraw consent at any time, without affecting earlier processing.
Send your request to hi@capibud.com. We may need to confirm your identity first. We reply within one month, or tell you within that month if we need longer and why. If your data sits in a workspace your employer controls, we will pass your request to them and help them answer it.
You can also complain to your data protection authority, for example the authority in your EU country, the UK Information Commissioner's Office or the Data Protection Board of India. We would appreciate the chance to resolve it first.
11 · Children
Not for children
The site and the app are business tools for adults. They are not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has sent us personal data, write to us and we will delete it.
12 · Changes
When this policy changes
We will update the date at the top of this page whenever we change it. If a change materially affects how we use personal data, we will say so on the site and, for app users, by e-mail or in the app before it takes effect.
13 · Contact
Getting in touch
Capibud Inc. · hi@capibud.com. See also our Terms of Use.
Questions about your data?
Write to hi@capibud.com. A person reads every message, and we reply to privacy requests within one month.