Privacy Policy

Last updated: 2 September 2026

1. Who We Are

CapraBrand is a product of CapraWorks. This policy explains how we collect, use, and protect your personal information when you use caprabrand.com (“Service”). Full publisher and contact details are set out in our legal notice. This policy is available in English and French; for consumers residing in France, the French version prevails.

2. Data We Collect

Account data: email address (used for authentication via magic link).

Brand data: brand names, taglines, descriptions, colours, fonts, social handles, and uploaded assets that you provide.

Platform credentials: API keys and tokens you enter to connect third-party platforms. They are stored in our database, protected by row-level security so only you can read them, and used solely to publish content on your behalf. Our database provider encrypts stored data at rest; we do not additionally encrypt these values at the column level. You can remove any connection at any time from Settings, which deletes the stored credentials.

Usage data: page views and feature usage collected via CapraLens (our first-party analytics). We do not use third-party tracking pixels or advertising cookies.

Payment data: handled entirely by Stripe. We store your Stripe customer ID and subscription ID but never your card details.

Instant preview data: if you use the free brand preview (/try), we store the business details you type, the generated preview, and — if you enter it to unlock a logo — your email address. We use that email to generate your logo and may follow up once about your preview; it is not added to any newsletter. A salted hash of your IP address (never the raw address) is kept for daily rate limiting.

3. How We Use Your Data, and Our Lawful Basis

Under the GDPR we must tell you the lawful basis for each purpose. They are:

  • Providing the Service (your account, your brands, publishing content you choose to publish) — performance of a contract (Art. 6(1)(b)).
  • Processing payments and keeping billing recordsperformance of a contract and legal obligation (Art. 6(1)(b) and (c)).
  • Transactional email (magic links, support replies) — performance of a contract (Art. 6(1)(b)).
  • Security, abuse prevention and rate limitinglegitimate interests (Art. 6(1)(f)) in keeping the Service available and secure.
  • One follow-up about a brand preview you generated (if you left your email on /try) — legitimate interests (Art. 6(1)(f)). You can object or ask us to delete the preview at any time.
  • Audience measurement (understanding which channels bring people to CapraBrand, see section 8) — legitimate interests (Art. 6(1)(f)). This is first-party only, is never used to profile you or track you across other sites, and you can object at any time.

4. AI Processing

When you use text AI features (social package generator, blog drafting, SEO schema, taglines, audience recommendations), your brand data is sent to Anthropic’s Claude API for processing. When you generate images (logos, banners, social images), the image prompt — which includes your business name and brand descriptors — is sent to OpenAI’s image API. Neither Anthropic nor OpenAI uses API inputs to train their models. Generated content is returned to you and is not retained by either provider to build their models.

5. Data Sharing

We do not sell your data. We share data only with:

  • Supabase — database hosting and authentication (EU region)
  • Stripe — payment processing
  • Anthropic — AI text generation (when you use AI features)
  • OpenAI — AI image generation (when you generate images)
  • Vercel — application hosting
  • Third-party platforms — only the content you explicitly choose to publish

5b. International Transfers

Your data is stored in the EU (Supabase, EU region). Some of the processors listed above are established in the United States — Stripe, Anthropic, OpenAI and Vercel. Where personal data is transferred to them outside the EEA, those transfers rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You may request further information about these safeguards using the contact details below.

6. Data Storage & Security

Your data is stored in Supabase (PostgreSQL, EU West region) with row-level security policies, and is encrypted at rest by our database provider. All connections use TLS. API tokens you generate for our own API are hashed with SHA-256 and never stored in plaintext — we cannot read them back, only verify them. Credentials for third-party platforms are stored so we can publish on your behalf, and are not additionally encrypted at the column level.

7. Your Rights

You can: access and export your data at any time via the dashboard; update or correct your information; delete your account and all associated data by contacting support. Under the GDPR you also have the rights to data portability, to restrict or object to processing carried out on the basis of our legitimate interests, and to withdraw consent where processing relies on it.

You have the right to lodge a complaint with a supervisory authority. Our lead authority is the Commission Nationale de l'Informatique et des Libertés (CNIL) https://www.cnil.fr. You may also complain to the authority in your own country of residence.

8. Cookies

We use first-party cookies only. We do not use advertising cookies, and we do not track you across other websites.

  • Authentication — Supabase session cookies that keep you signed in. Strictly necessary.
  • cb_brand — remembers which brand you last had selected. Strictly necessary.
  • caprabrand-language — remembers your language choice.
  • caprabrand-theme — remembers light or dark mode.
  • cb_attraudience measurement. On your first visit only, this records how you arrived: any campaign tag in the link (utm_*) and the website that referred you. It stores the referring site’s domain name and the page you landed on. It does not store your IP address, does not build a profile, is never combined with data from other sites, and is never shared with or sold to anyone. We use it solely to understand which channels bring people to CapraBrand. It expires after 180 days.

9. Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal data and brand content is permanently deleted within 30 days. Anonymised usage statistics may be retained indefinitely.

10. Changes

We may update this policy from time to time. Material changes will be communicated via email. The “Last updated” date at the top reflects the most recent revision.

11. Contact

For privacy questions or data requests, contact support@capraworks.com.

Privacy Policy — CapraBrand