Data controller
Kaptor (the "Service"), available at app.gokaptor.com, is published by the operator of gokaptor.com. For any question regarding your data: contact@gokaptor.com.
Data we process
- Account: email, login credentials (via Supabase Auth, possibly Google or Apple).
- Company profile: the information you enter (company name, contact details, description, visuals, legal information).
- Prospects: publicly collected business contact details obtained at your request (name, website, professional email and phone number) for your B2B outreach.
- Billing: managed by Stripe; we do not store any payment card data.
- Technical usage: server logs necessary for the operation and security of the Service.
Purposes and legal bases
- Providing the Service (performance of the contract): account, profile, showcase website, prospecting, email sequences.
- Billing and accounting obligations (legal obligation / performance of the contract).
- B2B outreach on your behalf (legitimate interest): each email includes a one-click unsubscribe link and complies with opt-out requests.
- Improvement and security of the Service (legitimate interest).
Processors and recipients
We rely on providers who process data on our behalf: Supabase (database and authentication), Hetzner (hosting, Germany), Cloudflare (domain/DNS), Brevo (email sending), Stripe (payments), Anthropic (AI content generation), Google (login, sending via your Gmail mailbox if you enable it, and Google Business Profile if you enable it).
Content submitted to the AI is not used to train third-party models.
We do not sell your data.
Connecting your Gmail / Google Workspace mailbox
If you connect your own Gmail or Google Workspace mailbox (Settings page), Kaptor requests the Google "gmail.send" permission (sending only). It is used solely to send, from your own address, your replies to prospects who have written to you and your messages to contacts who have consented to be recontacted, which you trigger yourself within the application. Cold outreach (unsolicited first contact) never uses your Gmail mailbox: it is sent from a dedicated sending domain.
Kaptor never accesses the content of your mailbox: we do not read, list, modify, label, or delete any messages. Sending goes through the Gmail API (messages.send).
The access token (refresh token) is encrypted at rest (AES-256-GCM), stored only server-side, and never exposed to the browser. You can disconnect your mailbox at any time from Settings, which deletes the token.
Kaptor's use and transfer of information received from Google APIs comply with the Google API Services User Data Policy, including its Limited Use requirements.
Kaptor's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. (https://developers.google.com/terms/api-services-user-data-policy)
Retention periods
Account and profile data are retained for as long as your account is active, then deleted or anonymized within a reasonable period after closure, unless a legal retention obligation applies (e.g., billing).
Prospects and sending logs are retained for as long as necessary for your outreach and are then purged on request.
Your rights
You have the right to access, rectify, erase, restrict, object to, and port your data. Exercise these rights at contact@gokaptor.com. You may also file a complaint with your data protection authority (in France, the CNIL).
Prospected individuals may unsubscribe at any time via the link included in each email; their address is then added to a suppression list.
Cookies
The Service uses only strictly necessary cookies (authentication session). No advertising cookies or third-party trackers are currently placed.
Security
Data is isolated per customer (multi-tenant segregation), access to sensitive data is restricted server-side, and exchanges are encrypted (HTTPS).
Changes
We may update this policy. The date of the last update appears above.