Privacy Policy
Capacitr is a product of Capacitr, Inc., a Delaware corporation.
This Privacy Policy describes what information the Capacitr mobile application (the “App”), distributed through the Apple App Store, and the Capacitr website at https://capacitr.xyz collect about you, who processes that information on our behalf, and what you can ask us to do with it. It sits alongside the Terms & Conditions and expands on that document’s “Privacy Policy”, “Information This Privacy Policy Does Not Apply To” and “Website Usage Information” sections rather than replacing them. Where the two differ in detail, this page is the more specific and more recent statement.
Capacitr, Inc. may change this Privacy Policy at any time. Changes will be posted at https://capacitr.xyz/privacy and the LAST UPDATED date above will change with them. Your use of the Service after a change has been posted constitutes your agreement to the updated policy, so you should read this page from time to time.
The Short Version
We do not sell, rent, or trade your personal information, and we do not share it with advertising networks or data brokers. The App contains no advertising SDK and performs no cross-app or cross-site tracking for advertising.
Capacitr, Inc. never has access to your private keys or your seed phrase. They are generated and held by Privy’s key infrastructure and are never transmitted to us.
The App sends text, links, images and — when you ask about your own portfolio — your balances and positions to third-party AI providers so they can be summarised and answered. Section 4 states exactly what is sent, to whom, and for what.
You can request a copy of your data, or its deletion, by emailing support@capacitr.xyz from the address associated with your account.
1. Information You Give Us
1.1 Account and Identity
Signing in is handled by Privy (privy.io), our authentication and wallet-infrastructure provider. The App offers five ways to sign in: Google, Apple and X (Twitter) single sign-on, a one-time code sent to your email address, and a one-time code sent by SMS to your phone number. Privy performs the sign-in and returns your identity to us.
From that we store, against your account:
your Privy account identifier, and which of the methods above you used;
a display name and an avatar image — taken from the provider you signed in with, or chosen by you;
your X handle, where you signed in with X;
your email address, where the sign-in carried one;
your referral code, and the referral code of whoever referred you, where one applies;
when your account was created and last updated, and how far through onboarding you are, so you can resume it on another device.
We do not store your phone number. SMS sign-in is performed by Privy against a number Privy holds; that number is not written to our records.
1.2 What You Type, Paste and Attach
Agent conversations. The messages you send to the in-app Agent, and its replies, are stored on our servers so that a conversation is available on every device you sign in to. You can archive a conversation from within the App.
Links and searches you scan. When you scan a link or run a scan on some text, we store the raw input exactly as you submitted it, the status of that scan, and when it happened, against your account — this is what your scan history is made of.
Images you attach. An image you attach to an Agent message is uploaded from your device directly to our image store, at a random, hard-to-guess path. That path forms part of a publicly reachable URL, because the AI provider fetches the image over the public internet in order to read it; the URL contains no account identifier of yours. Images are capped at 1 MB and at three per message, and are automatically deleted 90 days after upload.
1.3 Notification Preferences
If you allow notifications, we store your device’s push token and the notification choices you have made, including any topics you have muted. We also store your device’s time zone, so that a scheduled notification arrives at a sensible local hour. Nothing else about your device’s configuration is collected.
2. Wallet and Blockchain Information
The App includes a non-custodial wallet created for you by Privy.
Private keys and seed phrases. These are generated and held inside Privy’s key infrastructure. Capacitr, Inc. does not collect, store, receive, or otherwise have access to them at any time, and they are never transmitted to us or to any AI provider. This is the same commitment made in the Terms.
Public addresses and balances. We read and store the public addresses of the wallets associated with your account, and we read balances and holdings from public blockchains and from any trading venue you choose to connect. Those are reads of public or venue-held data and do not require your keys.
Public blockchains are permanent. A transaction recorded on a public blockchain is outside Capacitr, Inc.’s control. It cannot be edited or deleted by us or by anyone else, including in response to a deletion request.
3. Information Collected Automatically
Product analytics. We use PostHog to understand how the App and the website are used — screens opened, features used, and similar events — associated with your account identifier. Analytics requests from the website are proxied through https://capacitr.xyz/ingest rather than sent to PostHog directly by your browser.
Diagnostics and errors. Errors and crashes are captured as exception events through that same PostHog pipeline, including the error message and a stack trace. We do not deliberately place the contents of your conversations into an error report, but an error message can incidentally describe what caused it.
Server logs. As the Terms state, our servers automatically record IP addresses and request information when you use the App or the website.
4. Third-Party AI Processing
Capacitr uses third-party AI services — Google (Gemini), OpenAI and TypeSafe AI — to summarize public news and market feeds, to answer your questions and to assess your open positions.
When you ask about your own portfolio, the balances, positions, profit and loss, and wallet addresses needed to answer are sent to these providers as part of your question.
To assess an open position, its venue, side, entry and current prices, profit and loss, distance to liquidation, whether a stop is set, and recent headlines are sent to TypeSafe AI — never your wallet address, balances or position size.
Your private keys and seed phrases are never transmitted.
The App asks for your agreement to this processing before it sends anything to an AI provider for the first time.
4.1 Who the Providers Are, and What Each One Does
Google — Gemini models, through the Google AI API. This is the primary provider. It summarises news and market feeds, analyses links you scan, reads images you attach, and generates the Agent’s replies.
OpenAI — speech-to-text transcription. When a link you scan is a video or audio post, its audio may be sent to OpenAI’s transcription API so that the spoken words can be read and summarised.
Parallel (parallel.ai) — live web research. When answering your question well requires current facts, the question is sent to Parallel, which searches the public web and returns a short, cited brief.
TypeSafe AI (typesafe.ai) — position assessment. When the position advisor is on, each of your open positions is described to TypeSafe’s System One model, which answers whether recent news cuts against it and how urgent that is. The App turns that answer into the note you see on the position. It does not place, change or close any order.
Each provider processes what it receives under its own terms and privacy policy, which govern what that provider may do with it.
4.2 What Is Sent
the text of your messages and the questions you ask the Agent;
the links, posts and articles you scan, and their contents;
images you attach to an Agent message;
and, only where your question requires it, the balances, positions, profit-and-loss figures and public wallet addresses that the Agent reads from your wallet and from the venues you have connected. The Agent has read-only tools for this. They run when answering you needs them — for example when you ask what you hold or how you are doing — and their results are placed into the model’s context so that it can answer. These reads remain available even where trading is switched off for your account.
and, when the position advisor is on, for each of your open positions: the venue, the side, the entry and current prices, the profit and loss, the distance to liquidation, whether a stop is set, and the recent headlines about it. Positions are described without your wallet address, your balances or the size of the position, and without any account identifier.
4.3 What Is Never Sent
your private keys or your seed phrase — we do not hold them at all;
your email address, your phone number, or your sign-in credentials.
No AI provider is used to make an automated decision that has a legal effect on you. The Agent produces information and suggestions; it does not decide anything about your account. See the Terms’ “AI-Generated Suggestions” section, which governs how those outputs must be treated.
5. Who Else Receives Information
Privy — authentication, and the key infrastructure behind your wallet.
Google, OpenAI, Parallel and TypeSafe AI — AI processing, as described in section 4.
PostHog — product analytics and error tracking.
Google Firebase Cloud Messaging — push-notification delivery. Your device registers a push token with Firebase; we store that token against your account, and Firebase is what actually delivers a notification to your device.
Content and market-data providers — when you scan a link, the link is sent to whichever service can fetch it (for example a social-media data provider, or a page-reading service) so that its contents can be read. Those services receive the link, not your identity.
Trading venues you connect — where you connect a venue, we read your balances and holdings from it using your public address.
Hosting, database and storage providers — the application, its database, and the image store run on infrastructure we rent. Those providers process data on our behalf and under contract.
We do not sell, rent, or trade your personal information to any third party. We do not share it with advertising networks or data brokers, and the App links no advertising or attribution SDK.
5.1 Legal and Business Disclosures
As stated in the Terms, we may share or disclose personal information about you when: we have your consent; we use a third-party service provider to provide a product, service or function on our behalf, and require that provider to keep your information confidential and to use it only for the purpose for which we engaged them; we need to protect our legal rights; we must comply with applicable laws, regulations, or legal or regulatory process; or in connection with a sale, merger, transfer, exchange or other disposition of all or a portion of the Capacitr, Inc. business.
6. What This Policy Does Not Cover
This Privacy Policy does not apply to information collected about you by anyone other than Capacitr, Inc. Any information you provide when you visit websites or applications other than the App or https://capacitr.xyz, or when you purchase products or services offered or advertised by companies other than Capacitr, Inc. (including Apple Inc.), is subject to the privacy policies of the organisations that run and own those websites and applications. Where the App opens a third party’s own interface — a venue, an exchange, a payment or funding provider, or a link you follow out of the App — what you do there is governed by that party’s privacy policy, not by this one. Capacitr, Inc. cannot be held responsible for the content or the privacy policies of external websites to which we may link.
7. Your Rights, and How to Exercise Them
You may at any time request a copy of the personal data Capacitr, Inc. holds about you, or request that your account and personal data be deleted, by emailing support@capacitr.xyz from the email address associated with your account. We will verify your identity and respond to your request within a reasonable timeframe and in accordance with applicable law. Please note that:
we may retain certain information where required by law or for legitimate business purposes such as fraud prevention, security, and compliance with legal obligations;
deletion of your account does not affect your digital assets, which remain accessible to you through your private keys and standard third-party tools; and
records of transactions on public blockchains are permanent and outside Capacitr, Inc.’s control, and cannot be deleted by us or by anyone else.
You can also do the following at any time, without contacting us: turn notifications off in your device settings, which stops push delivery; archive an Agent conversation from within the App; and sign out.
8. Retention
We keep your account record, your Agent conversations, and your scan history for as long as your account exists, and after that only where a legal obligation or a legitimate business reason requires it. Images you attach to an Agent message are deleted automatically 90 days after upload. Analytics and diagnostic events are retained by PostHog under its own retention settings.
9. Age Requirement
The Service is not directed to, and may not be used by, anyone under 18 years of age; the Terms require that you be at least 18 and have the legal capacity to enter into them. We do not knowingly collect personal information from children. If we learn that we hold personal information about a person under 18, we will delete it.
10. Where Your Information Is Processed
Capacitr, Inc. is a Delaware corporation based in the United States, and the providers named in this policy process data in the United States and in other countries. By using the Service you understand that your information will be transferred to and processed in the United States and in those countries, which may have data-protection rules that differ from those where you live.
11. Contact
Capacitr, Inc.
support@capacitr.xyz
Use that address for any question about this Privacy Policy, and to exercise any of the rights described in section 7. For the terms governing your use of the Service, including the general risk disclosure, see https://capacitr.xyz/terms.