Written to be read, not to be survived. Every sub-processor is named, every retention period is a real number, and where we have not done something — an Article 27 representative, a Data Protection Officer — this page says so instead of going quiet. If a question you have is not answered here, privacy@capybari.com reaches a person.

Privacy Policy

Last updated 5 September 2026

1. Who we are

Capybari is a managed AI engineering platform. This policy explains what personal data we collect when you visit this website, create an account, or use the platform, and what we do with it.

For the purposes of the UK GDPR and the EU GDPR:

  • We are the controller of personal data about our website visitors, account holders and billing contacts.
  • We are a processor acting on your instructions for personal data that happens to be contained in the code, repositories, logs and systems you connect to the platform. Your contract with us, and any data processing agreement attached to it, governs that processing. In short: we are the controller of data about you as an account holder, and the processor of whatever personal data happens to live inside the systems you connect.

Dackapps LLC, the company behind Capybari Registered office: 16192 Coastal Highway, Lewes, Delaware 19958, United States Company number: 2505215 Country of registration: United States

We have not appointed a Data Protection Officer, and we are not required to: we are not a public authority, and our core activities are neither large-scale monitoring nor large-scale processing of special category data. Privacy questions go to privacy@capybari.com and reach a person who can act on them. If one is appointed, or if the appointment is legally required, their name and contact details go here. Our position on an Article 27 representative is in section 8.

2. How to contact us

Write to privacy@capybari.com for anything in this policy, including requests to exercise your rights.

For security matters, including reporting a vulnerability, write to security@capybari.com.

For anything else, hello@capybari.com.

Postal correspondence goes to the registered office above.

3. What we collect

3.1 Account data

Your name, work email address, password hash, organisation name, the role you hold in that organisation, your account settings, and the timestamps of your sign-ins. If you sign up through a git host, we receive the account identifier and email address that host gives us.

3.2 Project and repository metadata

The names, URLs and default branches of the git repositories you connect, the credentials or tokens you supply to reach them, the projects and teams you configure, and the requests and tasks on your board. Commit metadata such as author names and email addresses is present in the repositories you connect and is processed as part of running the service.

3.3 Agent run logs and reports

The prompts, commands, command output, diffs, structured completion reports, investigation summaries and streamed run events produced when work runs on your projects. These may contain personal data if your repositories, logs or diagnostics contain personal data. They are stored so you can read the record of what happened, and so we can debug failures you report.

3.4 Deployment target configuration

The SSH hostnames, usernames, deploy paths, deploy commands, health checks, diagnostics commands and rollback commands you define, along with the credentials needed to reach those hosts, and the phase-by-phase output of each deployment run.

3.5 Billing data

Your billing name, billing email, billing address, VAT or tax identifier, plan, agent-run counts used for metering, invoices and payment status. Card numbers are handled by our payment processor and are never stored on our systems.

3.6 Support and correspondence

Messages you send us by email or through a form on this site, and our replies.

3.7 Campaign attribution

If you reach this site through a tagged campaign link — an advertisement, a newsletter, a partner's post — we keep the campaign labels from that link and send them with any form you then submit, so we can tell which campaign produced which enquiry. We keep both the first campaign that brought you here and the most recent one before you got in touch. These are labels we wrote into our own links; they contain no identifier and no record of what you read. See the cookie policy for where they are stored in your browser.

3.8 Website analytics

We keep server-side request logs for this marketing website — the requested URL, timestamp, response status, referrer, user agent and a truncated IP address — for security and capacity purposes.

We run no advertising trackers on this marketing website. There is no advertising network, no session recorder, no social pixel and no third-party font or script.

There is one analytics tag: Google Analytics 4, which currently runs on every visit while the site is new. The Cookie Policy says so plainly, names the cookies it sets, and explains how to stop it. Google acts as our processor; we have turned off Google Signals and ad personalisation, so nothing here feeds an advertising profile.

3.9 What we do not ask for

We do not ask for special category data — health, biometrics, race, religion, political opinions, trade union membership, sex life or sexual orientation — and the platform is not designed to process it. Do not connect systems containing special category data without a written agreement with us first.

4. Lawful bases

What we process Lawful basis
Account data, project metadata, run logs, deployment configuration Performance of a contract (Article 6(1)(b)) — we cannot run the service without them
Billing and payment data Performance of a contract, and legal obligation (Article 6(1)(c)) for tax and accounting records
Campaign labels submitted with a form Legitimate interests (Article 6(1)(f)) — knowing which campaign produced an enquiry we were going to answer anyway
Security logging, fraud prevention, abuse investigation Legitimate interests (Article 6(1)(f)) — keeping the platform and our customers safe
Service email about outages, security and material changes Legitimate interests, and performance of a contract
Marketing email to people who asked for it Consent (Article 6(1)(a)), withdrawable at any time
Personal data inside your repositories, logs and connected systems We process it on your documented instructions as a processor; you determine the lawful basis

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to that processing at any time — see section 10.

5. How we use it

  • To run the platform: plan requests, execute tasks in isolated worktrees, run review gates, deploy to the targets you configure, and open investigations when something fails.
  • To authenticate you and keep your account secure.
  • To count agent runs, apply your plan's limits, and settle credit balances.
  • To answer support requests and debug faults you report to us.
  • To detect, investigate and stop abuse, fraud and attacks on the platform.
  • To send service messages about incidents, security and material changes to this policy or our terms.
  • To meet our legal, tax and accounting obligations.
  • To improve the platform's reliability, using aggregate operational metrics such as error rates, run durations and queue depth.

We do not sell personal data. We do not share it with advertisers. We do not use it for automated decision-making that produces legal effects for you.

6. We do not train models on your data

We do not use your code, your prompts, your agent run logs, your completion reports or your deployment output to train, fine-tune or otherwise improve any machine learning model — ours or anyone else's.

Your content is sent to third-party model providers only to produce the output of a run you asked for. We configure those providers so that content sent through our accounts is excluded from their model training, and we require that exclusion contractually, and the agreements with Anthropic, OpenAI and OpenRouter forbid it. You can also connect your own provider account on any plan, which takes us out of that relationship entirely. See the named provider before launch, and record the zero-retention or limited-retention setting that applies to each.

Where a model provider retains prompt and output data briefly for abuse monitoring, that retention is set by the provider. We name the providers and their retention behaviour in section 7 once they are confirmed.

7. Sub-processors

We use a small number of third parties to run the service. Each is bound by a written contract that limits them to processing on our instructions and requires appropriate security measures.

This list is dated and we give notice before adding to it. Processing locations are named because "the cloud" is not an answer to where your code is executed.

Category Purpose Vendor
Cloud hosting and infrastructure Running the application, databases, backups and agent execution environments Contabo (Europe and United States) and Vultr (Europe and United States)
Model providers Producing the output of agent runs Anthropic, OpenAI and OpenRouter. Not used where you connect your own provider account
Payment processing Taking payment and issuing receipts PayPal. Card details are handled by PayPal and never reach our systems
Email delivery Sending account, service and support email None — we run our own mail server. Your address is not shared with a delivery vendor
Error and uptime monitoring Detecting faults and outages None. We have no third-party monitoring vendor; see the status page for what that means in practice

8. International transfers

Some of these sub-processors are located outside the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA, we rely on one of the following:

  • An adequacy decision by the UK government or the European Commission covering the destination country.
  • The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
  • The EU Standard Contractual Clauses, with a transfer risk assessment on file.

We are a United States company, so personal data reaching us is transferred out of the UK and the EEA by definition. That transfer relies on the Standard Contractual Clauses, together with the UK Addendum for UK data, and the same mechanism covers our US-located hosting. Hosting in Europe stays in Europe.

You may request a copy of the relevant safeguards by writing to privacy@capybari.com. We have not yet appointed an EU or UK representative under Article 27; if you are in the EU or UK and would ordinarily contact one, write to privacy@capybari.com and we will answer directly.

9. Retention

We keep personal data only as long as we need it. The periods below are the ones we operate to.

Data Retention
Account data For the life of the account, then deleted within 30 days of closure
Project, repository and board metadata For the life of the account, then deleted within 30 days of closure
Agent run logs, streamed events and completion reports 12 months from the run, or until you delete the project, whichever is sooner
Deployment target configuration and credentials Until you delete the target; credentials are deleted immediately on deletion
Deployment run output and health-check output 12 months
Investigation records 12 months
Billing records and invoices 7 years, to meet UK tax and accounting requirements
Support correspondence 24 months from the last message
Website server logs 90 days
Security and audit logs 12 months
Backups Rolling backups are overwritten within 35 days; deleted data persists in backups until that cycle completes

When a retention period ends we delete the data or irreversibly anonymise it.

10. Your rights

Under the UK GDPR and the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where we no longer have a lawful reason to keep it.
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Object — object to processing we carry out on the basis of legitimate interests, and to direct marketing at any time and without reason.
  • Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  • Withdraw consent — where we rely on consent, withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.

How to exercise them

Write to privacy@capybari.com with the request and enough information for us to find your records. We will respond within one month. If the request is complex we may extend that by a further two months and will tell you why within the first month.

We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we will tell you the charge before doing the work. We may ask you to verify your identity before we act.

If your personal data sits inside a customer's repository, logs or connected systems, that customer is the controller. Send your request to them; we will support them in answering it, and we will pass on requests that reach us in error.

11. Cookies

This marketing website sets no advertising or third-party cookies and loads no third-party scripts. The signed-in application uses a small number of strictly necessary cookies. The Cookie Policy lists every item by name, purpose and duration.

12. Children

The platform is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@capybari.com and we will delete it.

13. Changes to this policy

We may update this policy. When we do, we change the "last updated" date at the top and keep the previous version on file.

If a change materially affects how we handle your personal data, we will email account holders at least 30 days before it takes effect.

14. Complaints

If you are unhappy with how we have handled your personal data, tell us first at privacy@capybari.com so we can try to put it right.

You also have the right to complain to a supervisory authority. We are a United States company, so we do not have a lead authority of our own — you complain to the one where you are.

If you are in the United Kingdom, that is the Information Commissioner's Office:

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Telephone: 0303 123 1113 Website: ico.org.uk

If you are in the EEA, you may complain to the supervisory authority in your country of residence, place of work, or the place where the alleged infringement happened.