Privacy Policy
Last updated: July 22, 2026
Kapsy ("we", "us", or "our") operates the kapsy.ai website and application (the "Service"). This Privacy Policy explains how we collect, use, store, disclose, and safeguard your information when you use our Service. By using the Service, you agree to the practices described in this policy.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and profile picture as provided by your authentication provider (e.g., Google Sign-In).
Usage Data
We automatically collect information about how you interact with the Service, including pages visited, features used, timestamps, and device information (browser type, operating system, screen resolution).
Content You Create
We store the content you create within the Service, including conversations, documents, presentations, workflows, and app configurations.
Third-Party Account Data
When you connect third-party services (such as Google Calendar, Zoom, or Slack) via OAuth 2.0, we collect and store the OAuth tokens and the specific data required to provide the connected features. Details for each integration are described in the sections below.
2. How We Use Your Information
- Provide, operate, and maintain the Service
- Process your requests and deliver AI-generated content
- Improve and personalise your experience
- Facilitate integrations with third-party services you connect (e.g., creating calendar events, scheduling meetings)
- Send service-related notifications
- Detect, prevent, and address technical issues or abuse
- Comply with legal obligations
We do not use your data — including data from third-party integrations — for advertising, selling to third parties, or training AI/ML models.
3. Google User Data
Kapsy integrates with Google services via OAuth 2.0. This section describes how we handle data obtained through Google APIs, in compliance with the Google API Services User Data Policy.
Data Accessed
When you connect your Google account, Kapsy requests access to the following scopes:
- Google Calendar Events (
calendar.events) — Read and write access to your calendar events, including event titles, times, descriptions, attendees, and locations. - Google Drive Files (
drive.readonly) — Read-only access to view and download files only within the specific folders you choose to connect ("watched folders"). Kapsy never accesses your entire Drive or any files outside the folders you explicitly select. - Basic Profile Information — Your name and email address, as provided by your Google account during authentication.
How We Use Google Data
Google user data is used exclusively to:
- Display your calendar events within the Kapsy scheduling interface
- Create, update, and delete calendar events on your behalf when you use Kapsy's scheduling and booking features
- Check calendar availability to prevent scheduling conflicts
- Sync documents from the Google Drive folders you connect into your workspace knowledge base, so you can search and reference them within Kapsy
We do not use Google user data for advertising, market research, or to train AI/ML models.
Limited Use
Kapsy's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use data obtained through Google Workspace APIs (including Drive) to develop, improve, or train generalized AI and/or ML models, and we do not transfer or sell this data.
Data Sharing
Google user data is not shared with any third parties. Your Google data (calendar and Drive documents) is only processed on our servers to provide the features described above and is never sold, transferred, or disclosed to external parties for any purpose.
Data Storage & Protection
Google OAuth tokens are securely stored on Microsoft Azure infrastructure with encryption at rest and in transit (TLS 1.2+). Google data (calendar events and Drive documents) is cached temporarily on our servers only as needed to provide the features within the application. Access to stored tokens is restricted to authenticated, authorized requests from your account only.
Data Retention & Deletion
Google OAuth tokens are retained only while your Google account remains connected to Kapsy. You can disconnect your Google account at any time from your Kapsy account settings, which will immediately revoke access and delete all stored Google tokens and cached Google data. You may also revoke access directly from your Google Account permissions page. To request complete deletion of all your data, contact us at admin@mail.kapsy.ai.
4. Zoom User Data
Kapsy integrates with Zoom via OAuth 2.0 to provide video conferencing capabilities within our scheduling features.
Data Accessed
When you connect your Zoom account, Kapsy requests access to the following scopes:
- Create Meetings (
meeting:write:meeting) — Permission to create Zoom meetings on your behalf.
We access only the minimum data returned by the Zoom API when creating a meeting: meeting ID, join URL, and meeting status. We do not access meeting recordings, chat messages, participant lists, or any other Zoom account data.
How We Use Zoom Data
Zoom data is used exclusively to:
- Create Zoom meetings automatically when bookings are scheduled through Kapsy's scheduling features
- Provide meeting join links to you and your invitees in booking confirmations
We do not use Zoom data for advertising, analytics, market research, or to train AI/ML models.
Data Sharing
Zoom meeting join links are shared only with the booking participants (the host and the invitee) as part of the scheduling workflow. No other Zoom data is shared with any third parties.
Data Storage & Protection
Zoom OAuth tokens are securely stored on Microsoft Azure infrastructure with encryption at rest and in transit (TLS 1.2+). Meeting metadata (join URL and meeting ID) is stored alongside booking records only for as long as the booking exists. Access to stored tokens is restricted to authenticated, authorized requests from your account only.
Data Retention & Deletion
Zoom OAuth tokens are retained only while your Zoom account remains connected to Kapsy. You can disconnect your Zoom account at any time from your Kapsy account settings, which will immediately revoke access and delete all stored Zoom tokens. You may also revoke access directly from your Zoom installed apps page. To request complete deletion of all your data, contact us at admin@mail.kapsy.ai.
5. Slack User Data
Kapsy integrates with Slack via OAuth 2.0 to bring your team conversations into Kapsy's knowledge graph for AI-powered search and assistance.
Data Accessed
When you connect your Slack workspace, Kapsy requests access to the following scopes:
- channels:history, groups:history — Read messages from public and private channels the Kapsy bot has been explicitly invited to.
- channels:read, groups:read, mpim:read — List channels and group conversations so users can manage which are connected.
- files:read — Ingest files (PDFs, documents, images) shared in those channels for searchable knowledge.
- users:read — Display user names alongside messages for attribution.
- chat:write — Post AI-generated answers and search results back to channels when invoked.
How We Use Slack Data
Slack data is used exclusively to:
- Index messages and files into Kapsy's knowledge graph for natural-language search
- Generate AI-powered answers grounded in your team's Slack history
- Surface decisions, action items, and relevant context from past conversations
We do not use Slack data for advertising, market research, selling to third parties, or training AI/ML models.
Data Sharing
Slack data is not shared with any third parties. AI-generated responses based on Slack content are visible only to authenticated members of your Kapsy workspace.
Data Storage & Protection
Slack OAuth tokens and ingested message content are securely stored on Microsoft Azure infrastructure with encryption at rest (AES-256) and in transit (TLS 1.2+). Access is scoped to authenticated users in the workspace that authorised the connection. The Kapsy bot only sees content from channels it has been explicitly invited to.
Data Retention & Deletion
Slack OAuth tokens are retained only while your Slack workspace remains connected to Kapsy. You can disconnect Slack at any time from your Kapsy account settings, which will immediately revoke access and delete stored Slack tokens. Ingested message content is deleted within 30 days of disconnection. You may also uninstall the Kapsy app directly from your Slack workspace's app management page. To request complete deletion of all your data, contact us at admin@mail.kapsy.ai.
6. Third-Party Services
We use the following third-party services that may process your data:
- Firebase (Google) — Authentication and analytics
- Microsoft Azure — Cloud hosting, storage, and AI services
- OpenAI / Anthropic — AI model providers for generating content
- Sentry — Error tracking and performance monitoring
- Google Calendar — Calendar integration (user-initiated, OAuth 2.0)
- Zoom — Video meeting creation (user-initiated, OAuth 2.0)
- Slack — Workspace messaging integration (user-initiated, OAuth 2.0)
Each third-party provider is governed by their own privacy policy. We only share the minimum data necessary for the service to function. We do not sell, rent, or trade your personal data to any third party.
7. Data Storage & Security
Your data is stored on Microsoft Azure infrastructure in secure data centres. We implement industry-standard security measures including:
- Encryption in transit — All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
- Encryption at rest — Data stored on Azure is encrypted at rest using AES-256 encryption
- Access controls — Role-based access controls and the principle of least privilege are enforced for all system access
- Authentication — User authentication is handled via Firebase (Google) with secure JWT token verification
- OAuth token security — Third-party OAuth tokens are stored securely and are only accessible by the authenticated user who authorised the connection
- Monitoring — We use Sentry for real-time error tracking and Azure Application Insights for infrastructure monitoring
However, no method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Data Retention & Deletion
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention practices include:
- Account data — Retained until you delete your account or request deletion
- Content you create — Retained until you delete the content or your account
- OAuth tokens — Retained only while the third-party service remains connected; deleted immediately upon disconnection
- Usage analytics — Retained in aggregated, anonymised form for service improvement
You may request deletion of your account and all associated data at any time by contacting us at admin@mail.kapsy.ai. We will process deletion requests within 30 days and confirm completion via email.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal data
- Rectify inaccurate or incomplete data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Data portability — receive your data in a structured format
- Withdraw consent for any optional data processing at any time
To exercise any of these rights, contact us at admin@mail.kapsy.ai. We will respond to your request within 30 days.
10. Cookies & Tracking
We use essential cookies for authentication (session tokens). We use Firebase Analytics and Sentry for usage analytics and error tracking. You can control cookie preferences through your browser settings.
11. Children's Privacy
Our Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
13. AI Assistants & API Connectors
Kapsy offers an official Model Context Protocol (MCP) connector that lets you drive your workspace from AI assistants such as Claude and ChatGPT, or any other MCP-compatible client, at https://api.kapsy.ai/mcp. When you connect an AI assistant:
- You authenticate via OAuth 2.1 or a Personal Access Token. The assistant acts on your behalf and can only access data your account and the granted scopes permit — it never sees another workspace's data.
- The tools you invoke read and write the same workspace data described elsewhere in this policy (issues, docs, CRM records, forms, decks, and the like). No new categories of personal data are collected by the connector itself.
- Your prompts and the tool inputs/outputs are processed by the third-party AI provider you chose (e.g. Anthropic or OpenAI) under that provider's privacy terms. Kapsy does not control, and is not responsible for, how that provider handles the conversation. Review your assistant provider's privacy policy before connecting.
- Every connector tool call is logged with the acting token, tool name, and outcome for security and audit purposes. You can revoke a connector or Personal Access Token at any time in Settings → API tokens (or by disconnecting the connector in your AI assistant), which immediately ends its access.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at admin@mail.kapsy.ai.