PLACEHOLDER is a detail we cannot confirm yet and must be completed before this policy is relied on.
Privacy Policy
Last updated 4 August 2026
1. Who we are
Capybari is a managed AI engineering platform. This policy explains what personal data we collect when you visit this website, create an account, or use the platform, and what we do with it.
For the purposes of the UK GDPR and the EU GDPR:
- We are the controller of personal data about our website visitors, account holders and billing contacts.
- We are a processor acting on your instructions for personal data that happens to be contained in the code, repositories, logs and systems you connect to the platform. Your contract with us, and any data processing agreement attached to it, governs that processing. PLACEHOLDER — the controller and processor split must be confirmed against the signed contract before launch.
Capybari Ltd (PLACEHOLDER — confirm the exact registered legal entity name) Registered office: PLACEHOLDER — registered office address Company number: PLACEHOLDER — company number Country of registration: United Kingdom
PLACEHOLDER — we have not appointed a Data Protection Officer. If one is appointed, or if the appointment is legally required, their name and contact details go here. We have also not appointed a UK or EU representative under Article 27; confirm whether one is required.
2. How to contact us
Write to privacy@capybari.com for anything in this policy, including requests to exercise your rights.
For security matters, including reporting a vulnerability, write to security@capybari.com.
For anything else, hello@capybari.com.
Postal correspondence goes to the registered office above.
3. What we collect
3.1 Account data
Your name, work email address, password hash, organisation name, the role you hold in that organisation, your account settings, and the timestamps of your sign-ins. If you sign up through a git host, we receive the account identifier and email address that host gives us.
3.2 Project and repository metadata
The names, URLs and default branches of the git repositories you connect, the credentials or tokens you supply to reach them, the projects and teams you configure, and the requests and tasks on your board. Commit metadata such as author names and email addresses is present in the repositories you connect and is processed as part of running the service.
3.3 Agent run logs and reports
The prompts, commands, command output, diffs, structured completion reports, investigation summaries and streamed run events produced when work runs on your projects. These may contain personal data if your repositories, logs or diagnostics contain personal data. They are stored so you can read the record of what happened, and so we can debug failures you report.
3.4 Deployment target configuration
The SSH hostnames, usernames, deploy paths, deploy commands, health checks, diagnostics commands and rollback commands you define, along with the credentials needed to reach those hosts, and the phase-by-phase output of each deployment run.
3.5 Billing data
Your billing name, billing email, billing address, VAT or tax identifier, plan, agent-run counts used for metering, invoices and payment status. Card numbers are handled by our payment processor and are never stored on our systems.
3.6 Support and correspondence
Messages you send us by email or through a form on this site, and our replies.
3.7 Website analytics
We keep server-side request logs for this marketing website — the requested URL, timestamp, response status, referrer, user agent and a truncated IP address — for security and capacity purposes.
We run no third-party trackers on this marketing website. There is no advertising network, no analytics tag, no session recorder, no social pixel and no third-party font or script. See the Cookie Policy for the complete list of what the site stores in your browser.
3.8 What we do not ask for
We do not ask for special category data — health, biometrics, race, religion, political opinions, trade union membership, sex life or sexual orientation — and the platform is not designed to process it. Do not connect systems containing special category data without a written agreement with us first.
4. Lawful bases
| What we process | Lawful basis |
|---|---|
| Account data, project metadata, run logs, deployment configuration | Performance of a contract (Article 6(1)(b)) — we cannot run the service without them |
| Billing data | Performance of a contract, and legal obligation (Article 6(1)(c)) for tax and accounting records |
| Security logging, fraud prevention, abuse investigation | Legitimate interests (Article 6(1)(f)) — keeping the platform and our customers safe |
| Service email about outages, security and material changes | Legitimate interests, and performance of a contract |
| Marketing email to people who asked for it | Consent (Article 6(1)(a)), withdrawable at any time |
| Personal data inside your repositories, logs and connected systems | We process it on your documented instructions as a processor; you determine the lawful basis |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to that processing at any time — see section 10.
5. How we use it
- To run the platform: plan requests, execute tasks in isolated worktrees, run review gates, deploy to the targets you configure, and open investigations when something fails.
- To authenticate you and keep your account secure.
- To meter agent runs, apply your plan limits, calculate overage and issue invoices.
- To answer support requests and debug faults you report to us.
- To detect, investigate and stop abuse, fraud and attacks on the platform.
- To send service messages about incidents, security and material changes to this policy or our terms.
- To meet our legal, tax and accounting obligations.
- To improve the platform's reliability, using aggregate operational metrics such as error rates, run durations and queue depth.
We do not sell personal data. We do not share it with advertisers. We do not use it for automated decision-making that produces legal effects for you.
6. We do not train models on your data
We do not use your code, your prompts, your agent run logs, your completion reports or your deployment output to train, fine-tune or otherwise improve any machine learning model — ours or anyone else's.
Your content is sent to third-party model providers only to produce the output of a run you asked for. We configure those providers so that content sent through our accounts is excluded from their model training, and we require that exclusion contractually. PLACEHOLDER — confirm the exact contractual wording with each named provider before launch, and record the zero-retention or limited-retention setting that applies to each.
Where a model provider retains prompt and output data briefly for abuse monitoring, that retention is set by the provider. We name the providers and their retention behaviour in section 7 once they are confirmed.
7. Sub-processors
We use a small number of third parties to run the service. Each is bound by a written contract that limits them to processing on our instructions and requires appropriate security measures.
PLACEHOLDER — every named vendor below is unconfirmed. Before launch, replace each PLACEHOLDER with the legal entity name, the processing location, and a link to that vendor's own sub-processor and security documentation. We will publish a dated sub-processor list and give notice of changes; the notice period must be set in the contract.
| Category | Purpose | Vendor |
|---|---|---|
| Cloud hosting and infrastructure | Running the application, databases, backups and agent execution environments | PLACEHOLDER — named hosting provider and region |
| Model providers | Producing the output of agent runs | PLACEHOLDER — named model provider(s) |
| Payment processing | Taking payment, storing card details, issuing invoices | PLACEHOLDER — named payment processor |
| Email delivery | Sending account, service and support email | PLACEHOLDER — named email delivery provider |
| Error and uptime monitoring | Detecting faults and outages | PLACEHOLDER — named monitoring provider, or remove if self-hosted |
8. International transfers
Some of these sub-processors are located outside the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA, we rely on one of the following:
- An adequacy decision by the UK government or the European Commission covering the destination country.
- The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
- The EU Standard Contractual Clauses, with a transfer risk assessment on file.
PLACEHOLDER — record which mechanism applies to each sub-processor, and where the transfer risk assessments are held. You may request a copy of the relevant safeguards by writing to privacy@capybari.com.
9. Retention
We keep personal data only as long as we need it. PLACEHOLDER — these periods are proposed defaults and must be confirmed against operational reality and any statutory minimums before launch.
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted within 30 days of closure |
| Project, repository and board metadata | For the life of the account, then deleted within 30 days of closure |
| Agent run logs, streamed events and completion reports | 12 months from the run, or until you delete the project, whichever is sooner |
| Deployment target configuration and credentials | Until you delete the target; credentials are deleted immediately on deletion |
| Deployment run output and health-check output | 12 months |
| Investigation records | 12 months |
| Billing records and invoices | 7 years, to meet UK tax and accounting requirements |
| Support correspondence | 24 months from the last message |
| Website server logs | 90 days |
| Security and audit logs | 12 months |
| Backups | Rolling backups are overwritten within 35 days; deleted data persists in backups until that cycle completes |
When a retention period ends we delete the data or irreversibly anonymise it.
10. Your rights
Under the UK GDPR and the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where we no longer have a lawful reason to keep it.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Object — object to processing we carry out on the basis of legitimate interests, and to direct marketing at any time and without reason.
- Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent — where we rely on consent, withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.
How to exercise them
Write to privacy@capybari.com with the request and enough information for us to find your records. We will respond within one month. If the request is complex we may extend that by a further two months and will tell you why within the first month.
We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we will tell you the charge before doing the work. We may ask you to verify your identity before we act.
If your personal data sits inside a customer's repository, logs or connected systems, that customer is the controller. Send your request to them; we will support them in answering it, and we will pass on requests that reach us in error.
11. Cookies
This marketing website sets no advertising or third-party cookies and loads no third-party scripts. The signed-in application uses a small number of strictly necessary cookies. The Cookie Policy lists every item by name, purpose and duration.
12. Children
The platform is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@capybari.com and we will delete it.
13. Changes to this policy
We may update this policy. When we do, we change the "last updated" date at the top and keep the previous version on file.
If a change materially affects how we handle your personal data, we will email account holders at least 30 days before it takes effect.
14. Complaints
If you are unhappy with how we have handled your personal data, tell us first at privacy@capybari.com so we can try to put it right.
You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Telephone: 0303 123 1113 Website: ico.org.uk
If you are in the EEA, you may complain to the supervisory authority in your country of residence, place of work, or the place where the alleged infringement happened.