Draft for legal review. This is a thorough outline written by the Capybari team. It has not been reviewed by a qualified solicitor and it is not legal advice. It must be reviewed and approved by a solicitor before launch. Every item marked PLACEHOLDER is a detail we cannot confirm yet and must be completed before this policy is relied on.

Privacy Policy

Last updated 4 August 2026

1. Who we are

Capybari is a managed AI engineering platform. This policy explains what personal data we collect when you visit this website, create an account, or use the platform, and what we do with it.

For the purposes of the UK GDPR and the EU GDPR:

  • We are the controller of personal data about our website visitors, account holders and billing contacts.
  • We are a processor acting on your instructions for personal data that happens to be contained in the code, repositories, logs and systems you connect to the platform. Your contract with us, and any data processing agreement attached to it, governs that processing. PLACEHOLDER — the controller and processor split must be confirmed against the signed contract before launch.

Capybari Ltd (PLACEHOLDER — confirm the exact registered legal entity name) Registered office: PLACEHOLDER — registered office address Company number: PLACEHOLDER — company number Country of registration: United Kingdom

PLACEHOLDER — we have not appointed a Data Protection Officer. If one is appointed, or if the appointment is legally required, their name and contact details go here. We have also not appointed a UK or EU representative under Article 27; confirm whether one is required.

2. How to contact us

Write to privacy@capybari.com for anything in this policy, including requests to exercise your rights.

For security matters, including reporting a vulnerability, write to security@capybari.com.

For anything else, hello@capybari.com.

Postal correspondence goes to the registered office above.

3. What we collect

3.1 Account data

Your name, work email address, password hash, organisation name, the role you hold in that organisation, your account settings, and the timestamps of your sign-ins. If you sign up through a git host, we receive the account identifier and email address that host gives us.

3.2 Project and repository metadata

The names, URLs and default branches of the git repositories you connect, the credentials or tokens you supply to reach them, the projects and teams you configure, and the requests and tasks on your board. Commit metadata such as author names and email addresses is present in the repositories you connect and is processed as part of running the service.

3.3 Agent run logs and reports

The prompts, commands, command output, diffs, structured completion reports, investigation summaries and streamed run events produced when work runs on your projects. These may contain personal data if your repositories, logs or diagnostics contain personal data. They are stored so you can read the record of what happened, and so we can debug failures you report.

3.4 Deployment target configuration

The SSH hostnames, usernames, deploy paths, deploy commands, health checks, diagnostics commands and rollback commands you define, along with the credentials needed to reach those hosts, and the phase-by-phase output of each deployment run.

3.5 Billing data

Your billing name, billing email, billing address, VAT or tax identifier, plan, agent-run counts used for metering, invoices and payment status. Card numbers are handled by our payment processor and are never stored on our systems.

3.6 Support and correspondence

Messages you send us by email or through a form on this site, and our replies.

3.7 Website analytics

We keep server-side request logs for this marketing website — the requested URL, timestamp, response status, referrer, user agent and a truncated IP address — for security and capacity purposes.

We run no third-party trackers on this marketing website. There is no advertising network, no analytics tag, no session recorder, no social pixel and no third-party font or script. See the Cookie Policy for the complete list of what the site stores in your browser.

3.8 What we do not ask for

We do not ask for special category data — health, biometrics, race, religion, political opinions, trade union membership, sex life or sexual orientation — and the platform is not designed to process it. Do not connect systems containing special category data without a written agreement with us first.

4. Lawful bases

What we process Lawful basis
Account data, project metadata, run logs, deployment configuration Performance of a contract (Article 6(1)(b)) — we cannot run the service without them
Billing data Performance of a contract, and legal obligation (Article 6(1)(c)) for tax and accounting records
Security logging, fraud prevention, abuse investigation Legitimate interests (Article 6(1)(f)) — keeping the platform and our customers safe
Service email about outages, security and material changes Legitimate interests, and performance of a contract
Marketing email to people who asked for it Consent (Article 6(1)(a)), withdrawable at any time
Personal data inside your repositories, logs and connected systems We process it on your documented instructions as a processor; you determine the lawful basis

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to that processing at any time — see section 10.

5. How we use it

  • To run the platform: plan requests, execute tasks in isolated worktrees, run review gates, deploy to the targets you configure, and open investigations when something fails.
  • To authenticate you and keep your account secure.
  • To meter agent runs, apply your plan limits, calculate overage and issue invoices.
  • To answer support requests and debug faults you report to us.
  • To detect, investigate and stop abuse, fraud and attacks on the platform.
  • To send service messages about incidents, security and material changes to this policy or our terms.
  • To meet our legal, tax and accounting obligations.
  • To improve the platform's reliability, using aggregate operational metrics such as error rates, run durations and queue depth.

We do not sell personal data. We do not share it with advertisers. We do not use it for automated decision-making that produces legal effects for you.

6. We do not train models on your data

We do not use your code, your prompts, your agent run logs, your completion reports or your deployment output to train, fine-tune or otherwise improve any machine learning model — ours or anyone else's.

Your content is sent to third-party model providers only to produce the output of a run you asked for. We configure those providers so that content sent through our accounts is excluded from their model training, and we require that exclusion contractually. PLACEHOLDER — confirm the exact contractual wording with each named provider before launch, and record the zero-retention or limited-retention setting that applies to each.

Where a model provider retains prompt and output data briefly for abuse monitoring, that retention is set by the provider. We name the providers and their retention behaviour in section 7 once they are confirmed.

7. Sub-processors

We use a small number of third parties to run the service. Each is bound by a written contract that limits them to processing on our instructions and requires appropriate security measures.

PLACEHOLDER — every named vendor below is unconfirmed. Before launch, replace each PLACEHOLDER with the legal entity name, the processing location, and a link to that vendor's own sub-processor and security documentation. We will publish a dated sub-processor list and give notice of changes; the notice period must be set in the contract.

Category Purpose Vendor
Cloud hosting and infrastructure Running the application, databases, backups and agent execution environments PLACEHOLDER — named hosting provider and region
Model providers Producing the output of agent runs PLACEHOLDER — named model provider(s)
Payment processing Taking payment, storing card details, issuing invoices PLACEHOLDER — named payment processor
Email delivery Sending account, service and support email PLACEHOLDER — named email delivery provider
Error and uptime monitoring Detecting faults and outages PLACEHOLDER — named monitoring provider, or remove if self-hosted

8. International transfers

Some of these sub-processors are located outside the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or the EEA, we rely on one of the following:

  • An adequacy decision by the UK government or the European Commission covering the destination country.
  • The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
  • The EU Standard Contractual Clauses, with a transfer risk assessment on file.

PLACEHOLDER — record which mechanism applies to each sub-processor, and where the transfer risk assessments are held. You may request a copy of the relevant safeguards by writing to privacy@capybari.com.

9. Retention

We keep personal data only as long as we need it. PLACEHOLDER — these periods are proposed defaults and must be confirmed against operational reality and any statutory minimums before launch.

Data Retention
Account data For the life of the account, then deleted within 30 days of closure
Project, repository and board metadata For the life of the account, then deleted within 30 days of closure
Agent run logs, streamed events and completion reports 12 months from the run, or until you delete the project, whichever is sooner
Deployment target configuration and credentials Until you delete the target; credentials are deleted immediately on deletion
Deployment run output and health-check output 12 months
Investigation records 12 months
Billing records and invoices 7 years, to meet UK tax and accounting requirements
Support correspondence 24 months from the last message
Website server logs 90 days
Security and audit logs 12 months
Backups Rolling backups are overwritten within 35 days; deleted data persists in backups until that cycle completes

When a retention period ends we delete the data or irreversibly anonymise it.

10. Your rights

Under the UK GDPR and the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have your data deleted where we no longer have a lawful reason to keep it.
  • Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Object — object to processing we carry out on the basis of legitimate interests, and to direct marketing at any time and without reason.
  • Restriction — ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  • Withdraw consent — where we rely on consent, withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.

How to exercise them

Write to privacy@capybari.com with the request and enough information for us to find your records. We will respond within one month. If the request is complex we may extend that by a further two months and will tell you why within the first month.

We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we will tell you the charge before doing the work. We may ask you to verify your identity before we act.

If your personal data sits inside a customer's repository, logs or connected systems, that customer is the controller. Send your request to them; we will support them in answering it, and we will pass on requests that reach us in error.

11. Cookies

This marketing website sets no advertising or third-party cookies and loads no third-party scripts. The signed-in application uses a small number of strictly necessary cookies. The Cookie Policy lists every item by name, purpose and duration.

12. Children

The platform is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to privacy@capybari.com and we will delete it.

13. Changes to this policy

We may update this policy. When we do, we change the "last updated" date at the top and keep the previous version on file.

If a change materially affects how we handle your personal data, we will email account holders at least 30 days before it takes effect.

14. Complaints

If you are unhappy with how we have handled your personal data, tell us first at privacy@capybari.com so we can try to put it right.

You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office:

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Telephone: 0303 123 1113 Website: ico.org.uk

If you are in the EEA, you may complain to the supervisory authority in your country of residence, place of work, or the place where the alleged infringement happened.