Privacy Policy
Effective June 10, 2026 · Early-access draft
Who we are
CapyHR ("we," "us") is operated independently, based in Omaha, Nebraska. CapyHR is a hosted personal command center: we set up and run a private instance of the software for you on infrastructure we manage. Unlike self-hosted software, your data lives on servers we operate — this policy explains what that means.
The data we handle for you
CapyHR's entire purpose is processing your personal information on your behalf, at your direction. When you connect accounts, your instance reads and stores:
- Email — message content and metadata from accounts you connect (iCloud, Gmail, Outlook), classification results, and a lifecycle log of what the system did with each message.
- Calendars — from the accounts you choose to sync, read-only. We never create, change or delete an event.
- Contacts — from the accounts you choose to sync. Reading is the default. Writing back is off unless you turn it on, and even then it is never automatic: your instance proposes a change and nothing leaves the box until you confirm it. A confirmed write can touch exactly four fields on a contact card — name, email address, phone number, organisation — and it edits those lines in place rather than replacing the card, so notes, addresses, birthdays and photos are left as they are. We can also create a new contact from one you add here. We never delete a contact from your address book. Every write keeps a copy of the card as it stood beforehand, so a change can be put back.
- Tasks, notes, and your bills ledger — what you create in the dashboard or provide for bill verification.
- Account data — your name, email, username, passkey public keys (never anything that lets us impersonate your devices), session records, and the OAuth tokens / app passwords needed to read your connected accounts. Tokens are stored with restricted file permissions, are never logged, and are used only to operate your instance. We never store passwords — there are none; sign-in is passkeys.
How we use it
For exactly four purposes: to operate your instance (triage your mail, verify your bills, build your rundown), to deliver the notifications you enable, to keep the service secure, and to troubleshoot when you ask for help. We improve CapyHR using operational signals — error logs, service health — never by mining the content of your mail.
Where it lives
Each customer gets an isolated instance: your own database and files, never shared or commingled with any other customer's. Instances run on a server we lease from Hetzner in Nuremberg, Germany, behind Cloudflare for network security and encryption in transit. We are based in Omaha, Nebraska, so your data is stored in Germany and administered from the United States. If we move the server we will say so here before the move.
Who else touches it (subprocessors)
- Hetzner Online GmbH — server hosting, Nuremberg, Germany.
- Cloudflare — DNS, TLS, network protection.
- Apple, Google, Microsoft — only the providers you connect, accessed with the credentials you authorize, revocable by you at any time.
- OpenRouter (AI processing) — only if you enable AI features. Before any content is sent for AI formatting or review, personal identifiers are substituted with anonymous codes; the AI provider sees the codes, not your details. AI features are optional and the service works without them.
- Telegram — in two places, both optional to you and neither one a place your mail goes in bulk. (1) If you turn on Telegram notifications, the alerts your instance sends you travel through Telegram's servers, so whatever an alert says — a sender, a subject line, an amount — passes through them. The default notification channel is in-app, and the service works without Telegram entirely. (2) If you write to us through the interest form on our home page, your name, email address and note are delivered to the operator as a Telegram message. That form is the only place on this site that collects anything.
What we never do
- No selling or sharing your data. No advertising. Ever.
- No training AI models on your data.
- No browsing your content. Operators access an instance's data only to provide support you've asked for, or as required to keep the service running, and we'll tell you when that happens.
Retention and deletion
- Email lifecycle records are pruned on a rolling ~90-day window.
- Live audience sessions (questions, word clouds, poll votes, reactions, game answers) are anonymous — no name, no email, nothing but a random per-browser marker — and the text and the votes are deleted 45 days after the session closes. What survives is counts: how many questions, how long they waited, the poll tallies. Nothing that could be traced back to a person.
- Continuing-education attendance records are the exception, because they are the point: if you claim CE credit at an event, your name, email and any credential number you give go on the host's attendance list, are never joined to anything you asked or voted for, and are kept for 400 days — a year plus the slack a late audit needs — then deleted. A host with a longer legal obligation can set a longer window on their own instance; there is always a window.
- You can disconnect any account at any time; new reads stop immediately.
- If you leave CapyHR, we delete your entire instance — database, files, credentials — within 30 days, and offer an export first.
Security
Per-instance isolation, passkey (Face ID / WebAuthn) sign-in with hashed session tokens, TLS everywhere, secrets kept out of code and logs. No system is perfect: if a breach affects your data we will notify you without undue delay and within 72 hours of confirming it.
Your choices and rights
Most controls are self-service in your dashboard: connect or disconnect accounts, tune notifications and quiet hours, turn AI features on or off, and manage everything you've created. Beyond that, ask us anytime to access, export, correct, or delete your data — it's yours. Contact hello@capyhr.com. We respond to every request personally; there's no form maze.
Children
CapyHR is not directed to children under 16 and we don't knowingly host their data.
Changes
If this policy changes materially, we'll notify you in your dashboard and by email before the change takes effect.