Privacy policy
Effective from October 1, 2026
This policy explains what personal data Cappa processes, why, for how long, and what your rights are. The rules for using the services are in the terms of service.
Data controller
The controller of your personal data is Patryk Adamkiewicz, Godowa 1D, 38-100 Strzyżów. For anything about your personal data, write to [email protected].
In short
- Notes in the app are encrypted on your device. We cannot read them and never learn your master password.
- The demo runs entirely in your browser. Notes you write in it never reach us.
- We use no ads and no tools that track visitors.
What we process and why
The waitlist
We process your email address, the language and place of signup, the signup and confirmation dates and, if you give it, your answer about which notes app you use. We use them to tell you when access to Cappa opens.
- Legal basis: your consent (Article 6(1)(a) GDPR), which you confirm with the emailed link.
- Retention: an unconfirmed signup is deleted after 30 days, and the confirmation link works for 7 days. A confirmed signup is kept until you remove it or we close the waitlist.
App accounts
We process your email address, name, sign-in data (never your master password), encrypted notes and settings, the list of your devices, and sessions with their IP address and browser description. We email security notifications to the account address, for example when a new device is added.
- Legal basis: performance of the contract (Article 6(1)(b) GDPR) and, for notifications and account protection, our legitimate interest (Article 6(1)(f) GDPR).
- Retention: until the account is deleted. A session expires after 7 days of inactivity or when you sign out.
- Accounts are created from an invitation that holds your email address. We delete it together with the account, and an unused invitation 30 days after it expires or is revoked.
Service security
Your IP address is seen by Cloudflare, which carries traffic to the service, and the app uses it to limit request rates. These entries are deleted automatically, at most a little over an hour later. Legal basis: our legitimate interest in protecting the service (Article 6(1)(f) GDPR).
Database backups are deleted automatically after 14 days.
Correspondence
When you write to [email protected], we process your address and the message to answer you. Legal basis: our legitimate interest (Article 6(1)(f) GDPR). We keep the message until the matter is resolved.
Who helps us
These providers process data on our behalf:
- Oracle
- Cloudflare, Inc.
- Plus Five Five, Inc. (Resend)
- Proton AG
Cloudflare and Resend are based in the United States. Transfers there rely on the EU-U.S. Data Privacy Framework and the European Commission's standard contractual clauses. Proton AG is based in Switzerland, which the European Commission recognises as providing adequate data protection.
Cookies and browser storage
We use only essential cookies: one remembers the blog language you picked with the switcher or by opening an article, the other keeps you signed in. The app also stores your account email and encrypted notes in your browser so it works offline.
Your rights
You have the right to access, correct, delete, restrict and port your data, and to object to processing based on legitimate interest. You can withdraw consent at any time; this does not affect earlier processing. Send requests to [email protected].
You can also lodge a complaint with the Polish President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland) or with the authority where you live or work.
Do you have to provide data
No, but without an email address you cannot join the waitlist or create an account. We make no decisions based solely on automated processing, including profiling.
Changes
We publish a new version of this policy on this page with a new effective date and email people on the waitlist and account owners about significant changes.