Last updated: September 2, 2026
This Privacy Policy explains how Capigo ("Capigo", "we", "us", or "our") processes personal data when you use the Capigo mobile application (the "App"), Capigo websites, and related services.
This Privacy Policy should be read together with the Capigo Terms of Service.
Capigo is currently operated by:
Aleksander Karnat
operating under the name karnat.studio
ul. Sopocka 28 B
37-400 Nisko
Poland
At the time this Privacy Policy was last updated, Capigo is operated as an unregistered business activity under applicable Polish law. If the operator's legal form or registration details change, this Privacy Policy will be updated accordingly.
For purposes of applicable data protection law, including the General Data Protection Regulation ("GDPR") where applicable, Aleksander Karnat is the controller of personal data processed for Capigo, except where another provider independently determines the purposes and means of its own processing.
Privacy: privacy@karnatstudio.com
General support: capigo@karnatstudio.com
This Privacy Policy applies to personal data processed in connection with:
External websites opened through links in Capigo are governed by their own privacy policies and terms.
The data processed depends on how you use Capigo.
Capigo supports authentication using:
Depending on the authentication method and authentication service involved, information may include:
Capigo uses Firebase Authentication as part of its authentication infrastructure.
The information maintained by Firebase Authentication is not necessarily the same as the information stored in Capigo's own application database.
Capigo's own application database does not automatically receive your email address, display name, or profile picture merely because you sign in. An application record may be created when needed for Capigo functionality, including when a purchase-related record is created.
Different sign-in methods associated with the same email address may be linked to the same Capigo account rather than creating separate accounts.
We do not use your profile picture for note processing.
Your ordinary Capigo notes, categories, reminders, and files attached to notes are stored locally on your device.
Capigo does not provide a general cloud backup or synchronization service for this content.
We do not intentionally upload or store ordinary note content or note attachments on Capigo's servers merely because you create or store them in the App.
This does not apply when you voluntarily use a feature that requires specific content to leave the device, such as AI-powered voice processing or a feedback submission with an attachment.
When you use an AI-powered voice feature, the App records the audio that you choose to submit.
The recording is transmitted:
from your device → through Capigo's backend infrastructure → to the relevant third-party transcription service.
Capigo does not intentionally retain submitted AI voice recordings as permanent files on its ordinary backend infrastructure.
Our application logs do not contain the audio itself or audio fragments. Technical logs may contain limited metadata such as the number of bytes received and the recording duration.
Where server-side transcription is used, the audio is transmitted through Capigo's backend and then sent to ElevenLabs for speech-to-text processing.
Where speech recognition occurs on the device, the resulting text may instead be transmitted to our backend for subsequent AI processing.
Our application logs do not contain the textual content of voice transcriptions. Logs may contain limited metadata such as the length of a transcription measured in characters.
Depending on the processing path, text derived from your voice input may be transmitted from Capigo's backend to Anthropic for AI processing.
AI-generated output may include:
The resulting note is returned to the App and stored locally on your device.
Our application logs do not intentionally contain the generated note content, title, or other substantive AI output.
Capigo also provides a separate manual dictation feature that may use speech recognition provided by your Android device or operating system.
Where this feature operates through on-device speech recognition, the spoken content is processed locally rather than being sent to Capigo's AI backend.
The device or operating-system provider may apply its own privacy practices to its speech-recognition functionality.
Certain Capigo functionality may inspect the system clipboard.
Where supported by the device and operating system, Capigo first uses the clipboard's available system classification or metadata without necessarily reading the underlying clipboard contents.
Where a fallback mechanism requires it, Capigo may read the clipboard contents for the limited purpose of providing the relevant functionality.
Clipboard information is not retained as part of your Capigo account merely because it is accessed for this functionality.
Capigo allows you to attach one or more phone numbers to a note, together with an optional label.
A number can be selected using the operating system's contact picker, typed in manually, or accepted from a suggestion when the system clipboard appears to contain a phone number.
Capigo does not request permission to read your contacts. When you use the system contact picker, the operating system returns only the single entry that you select.
An attached number is stored as a copy within the note on your device. It is not a live link to your address book, and later changes in your contacts are not reflected in the note.
Attached phone numbers and their labels are stored locally as part of the note. They are not transmitted to Capigo's servers and are not included in the data sent for AI processing.
A phone number may relate to a person other than you. You are responsible for the information you choose to attach to a note.
Capigo requests permission to place calls only when you first use the call button next to an attached number. If you decline, Capigo opens the system dialer with the number pre-filled instead, and calling remains available.
Capigo can appear in your device's sharing menu. When you share content into Capigo, it opens as a new note and is saved to that note.
Depending on what you share, this may include text, a link, or a file such as an image, a video, or a document.
Files shared in this way are copied into Capigo's private storage on your device, so that the note continues to work after the sharing application's temporary access has expired.
Capigo does not request storage permission for this. The application you share from grants Capigo temporary access to that specific item.
Content shared into Capigo is stored locally as part of the note, in the same way as any other note content. It is not transmitted to Capigo's servers merely because you shared it into the App.
When you attach a file to a note, Capigo also stores the file's original name, so that several attachments can be told apart within the note.
A file name may itself contain personal data, depending on how the file was named.
Stored file names are kept locally as part of the note and are not transmitted to Capigo's servers.
Photographs taken directly with the camera from within the App do not have a file name supplied by you and are stored under a name generated by the App.
Section 7.1 describes separately the limited circumstances in which a file name or path may appear in automatically collected crash diagnostics.
Capigo can create a backup file containing your notes. The file is generated on your device and is handed to your operating system's sharing menu, so that you can choose where to send or save it.
The backup file contains note content, titles, categories, reminders, checklist items, links, phone numbers attached to notes, and the stored file names of attachments.
The backup file does not contain the attachment files themselves. Photographs and documents attached to a note are not included and are not restored by an import.
The backup file does not contain your account identifier or the email address associated with your account.
Capigo does not upload the backup file. Once you share or save it, the file is outside the App, and any further handling is subject to the terms of the service or application you send it to.
When an AI processing path requires server-side speech-to-text transcription, the audio recording is transmitted:
from your device → through Capigo's backend → to ElevenLabs.
ElevenLabs processes the recording to generate a transcription.
Capigo's own backend does not maintain a permanent archive of the recording.
However, ElevenLabs may independently retain and process submitted voice data under its applicable privacy policy, service terms, and service configuration.
ElevenLabs states that it may use voice data for research, development, training, and improvement of its AI models and services. Its published privacy information also describes retention of certain voice-related data for up to three years after the last interaction, subject to applicable exceptions.
For the service currently used by Capigo, Zero Retention Mode is not available under the applicable service plan. We therefore do not describe the processing of audio by ElevenLabs as ephemeral processing.
After transcription, or after on-device speech recognition where applicable, text necessary for the requested AI functionality is transmitted:
from Capigo's backend → to Anthropic.
The original voice recording is not intentionally transmitted to Anthropic where the applicable processing path requires only text.
Anthropic's commercial API documentation states that inputs and outputs are not used to train its models by default.
Anthropic also states that commercial API inputs and outputs are generally deleted within 30 days, subject to documented exceptions and service-specific arrangements.
We process information necessary to maintain your available AI Use balance and operate usage-based features.
This may include:
We do not maintain a complete content history of every AI request.
Purchases of AI Usage packages made through the Android version of Capigo are processed through Google Play Billing.
We may process information necessary to:
Purchase verification may require temporary access to a Google Play purchase token or other transaction identifier.
Where a purchase identifier is retained by Capigo after verification, it is pseudonymised using a cryptographic hash rather than retained as a raw purchase token.
We do not receive or store your payment card number or full payment card details.
Capigo periodically checks Google Play information concerning purchases that have been refunded, revoked, cancelled, charged back, or otherwise invalidated.
Where necessary, we process information required to identify the affected transaction, determine whether it has already been processed, associate it with the relevant Capigo account, and adjust available AI Uses where applicable.
Certain payment-related application logs may contain your Capigo account identifier for these purposes.
These logs are retained for up to 30 days.
Your email address is not included in these payment-related application logs.
We use Firebase Crashlytics to diagnose crashes and technical problems.
Crashlytics may automatically process:
Capigo does not intentionally send the following to Crashlytics:
Automatically collected exception information may nevertheless contain technical details such as a file name or file path. For example, an operating-system file error may expose the name of a file selected by the user.
Firebase currently documents a 90-day retention period for Crashlytics crash stack traces and associated identifiers before deletion begins.
Capigo uses Firebase App Check with the Play Integrity provider to help verify that backend requests originate from a legitimate version of the App.
This may involve processing:
We use these mechanisms to protect backend resources, reduce automated abuse, prevent unauthorised access, and maintain the security of Capigo.
Capigo does not currently use App Check replay protection.
When you submit a feedback or support request, we may process:
Capigo does not automatically capture screenshots from your device.
You choose whether to attach a screenshot or other file.
A submitted attachment may contain personal, confidential, or sensitive information, including information visible within your notes.
Feedback screenshots and other attachments are stored in private Firebase Cloud Storage.
The storage used for this purpose is located in Belgium, within the European region.
Public access to submitted files is blocked. Files are written through the Capigo backend and are accessible only through authorised administration.
Feedback attachments are automatically deleted 30 days after submission.
When you interact with Capigo websites, public forms, backend endpoints, or other internet-facing infrastructure, technical request information may be processed.
This may include:
We use this information for purposes including:
Certain transaction-related application logs may contain your Capigo account identifier for up to 30 days and may therefore remain temporarily after account deletion.
Your email address is not included in these transaction-related logs.
Firebase Hosting and Google Cloud infrastructure may separately process request and audit logs according to their own applicable service rules. Standard Cloud Logging retention for applicable Hosting logs is 30 days unless a different configuration applies. Certain Google Cloud audit logs may have separate mandatory retention periods imposed by Google.
We do not use these technical logs to build advertising profiles.
Capigo includes a News feature that retrieves a news or announcements file from our infrastructure when the App is opened or refreshed.
The News request does not intentionally include:
The same news content may be provided to multiple users and is not personalised based on your account or notes.
As with ordinary internet requests, the infrastructure handling the request may process technical information such as:
The News content is stored locally in the App's private storage and replaced when newer content is retrieved.
We process personal data for defined purposes, including:
Where the GDPR applies, the legal basis for processing depends on the specific purpose.
We rely on this basis where processing is necessary to provide Capigo or a service requested by you, including:
We may rely on legitimate interests where processing is necessary for purposes such as:
Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and freedoms override those interests.
We process or retain information where necessary to comply with applicable legal obligations, including accounting, tax, regulatory, and lawful record-keeping requirements.
Where consent is required by applicable law, we will rely on consent and provide the relevant information when consent is requested.
Where processing is based on consent, you may withdraw consent at any time, without affecting processing carried out before withdrawal.
We do not sell your personal data.
We use third-party service providers where necessary to operate, secure, maintain, and provide Capigo.
Depending on the service involved, we use:
The information processed depends on the relevant service.
Firebase uses global infrastructure unless a particular service or configuration provides a specific data-location choice. Firebase Authentication is currently operated from data centres in the United States.
When required for server-side speech-to-text processing, Capigo sends the submitted voice recording to ElevenLabs through Capigo's backend.
ElevenLabs may independently retain and process the submitted data according to its applicable privacy policy, service terms, and service configuration.
ElevenLabs states that voice data may be used for research, development, training, and improvement of its AI models and services.
Where required for AI processing, Capigo sends text derived from the submitted voice input to Anthropic's commercial API services.
The original voice recording is not intentionally sent to Anthropic where the applicable processing path requires only text.
Anthropic states that commercial API inputs and outputs are not used to train its models by default.
We may disclose information where required or permitted by law, including to authorities or professional advisers where reasonably necessary for legal, security, accounting, or other lawful purposes.
Some third-party providers used by Capigo may process personal data outside the European Economic Area, including in the United States.
Where the GDPR applies, international transfers are carried out using a legally recognised transfer mechanism where required.
Depending on the provider and processing activity, this may include:
The applicable mechanism may differ depending on the provider and processing activity.
The location of data depends on the type of data and the service involved.
For example:
We do not represent that all third-party services used by Capigo process data exclusively within Europe.
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Different categories of data have different retention periods.
Notes, categories, reminders, and attachments stored locally remain on your device until you delete them, remove the relevant App data, uninstall the App, or otherwise remove them.
Capigo does not generally maintain a server-side backup of this content.
Capigo does not intentionally retain submitted AI audio as permanent files on its ordinary backend infrastructure.
Application logs contain only limited metadata such as byte count and recording duration.
Capigo does not retain transcription text in its ordinary application logs.
Logs may contain limited metadata such as transcription length.
Third-party transcription providers may retain submitted audio or derived data according to their own policies and service arrangements.
Capigo does not intentionally retain generated note content in its ordinary application logs.
Third-party AI providers may retain inputs and outputs according to their applicable retention policies.
Certain payment-related logs containing a Capigo account identifier are retained for up to 30 days and may therefore remain temporarily after account deletion.
Technical purchase records are retained only for as long as reasonably necessary for purposes such as:
Where purchase-related information is required to be retained by law, it may be stored for the applicable statutory period.
Feedback information may be retained for as long as reasonably necessary to investigate the matter, respond to the user, improve the service, or address related security or legal issues.
Feedback screenshots and other uploaded attachments are automatically deleted 30 days after submission.
Firebase currently documents a 90-day retention period for Crashlytics crash stack traces and associated identifiers before deletion begins.
Firebase currently documents that logged IP addresses for Authentication are retained for a few weeks.
Other authentication information remains until deletion is initiated by the Firebase customer, after which it is removed from live and backup systems within 180 days.
Firebase Hosting may process and retain IP-related request data for its service operation and abuse prevention.
Standard Cloud Logging retention for applicable Hosting logs is 30 days unless a different retention configuration applies.
Certain Google Cloud audit logs stored in the _Required bucket have a 400-day retention period that cannot be changed by the customer. These are separate from ordinary application logs and include certain administrative and system-event audit records.
Third-party providers may apply retention periods different from those used by Capigo.
For example:
You can request deletion of your Capigo account:
When an account deletion request is completed, we delete the server-side account data that is intended to be deleted as part of the account deletion process.
Certain information may remain where necessary or permitted for:
Deletion of a Capigo account initiates deletion of the relevant Firebase Authentication account.
Firebase may retain certain authentication information temporarily in backup systems or logs according to its documented deletion processes. Firebase currently states that authentication information is removed from live and backup systems within 180 days after deletion is initiated.
Certain transaction-related application logs may contain the deleted account's identifier for up to 30 days after account deletion.
The identifier remains solely as part of the temporary technical log and is not retained to preserve or reactivate the deleted account.
Deleting your Capigo account does not automatically delete local Capigo data from every device.
Deleting your account through the website cannot directly delete data stored in the private storage of your phone or another device.
When account deletion is performed through the App, applicable local Capigo data on that device is deleted as part of the account-deletion process.
Local data stored on other devices may remain until separately removed.
Deleting your Capigo account permanently removes the associated AI Use balance.
Unused AI Uses cannot be recovered or transferred after the account has been deleted, except where applicable law requires otherwise.
Where the GDPR or comparable data-protection law applies, you may have the right to:
To exercise your rights, contact:
privacy@karnatstudio.com
We may need to verify your identity before responding.
Your rights may be subject to legal limitations or exceptions.
If you are located in Poland, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).
Capigo is intended for users aged 13 and older.
This age requirement does not remove any additional protections that may apply to minors under the laws of the country where the user lives.
Where applicable law requires parental involvement, consent, or other safeguards concerning the processing of children's personal data, those requirements continue to apply.
If we become aware that personal data has been processed in circumstances where applicable law requires corrective action because of the user's age, we will take appropriate steps.
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction.
Depending on the system, these measures include:
Feedback attachments are stored in private Cloud Storage located in Belgium, within the European region.
AI audio submitted for processing is not intentionally stored as a permanent file on Capigo's ordinary backend infrastructure.
No method of electronic transmission or storage can be guaranteed to be completely secure.
Capigo may display news, announcements, or other informational content containing links to external websites.
Opening an external link may take you outside the Capigo App and into your device's browser.
External websites and services are operated independently from Capigo and may have their own privacy policies, terms, security practices, and data-processing practices.
We do not control the privacy practices of external websites that we do not operate.
We may update this Privacy Policy where reasonably necessary, including when:
We will update the "Last updated" date whenever this Privacy Policy is revised.
Where required by applicable law, we will provide additional notice or obtain consent before applying a material change.
For privacy questions, requests concerning personal data, or GDPR-related matters:
privacy@karnatstudio.com
For general support:
capigo@karnatstudio.com