Privacy Policy

Last updated: 2026-08-05 | Version 2.2

1. Who is responsible

The data controller is the individual entrepreneur (ФОП) Dmytro Yefremenko, Ukraine, tax ID (РНОКПП) 3572210852, correspondence address: Oleksandra Polia Ave., Dnipro, 49031, Ukraine. Privacy contact: privacy@captivo.app.

2. What we process, and why

  • Account data (e-mail, name, hashed password, language) — to provide the Service. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
  • Your media and its derivatives (extracted audio during processing; transcripts, translations, subtitles) — to deliver exactly what you asked for. Basis: contract. Your video itself stays in your browser and never reaches our servers.
  • Usage and quota records (minutes/words processed, plan) — billing and quota enforcement. Basis: contract.
  • Security logs (IP address, user agent, actions) — abuse prevention and account security. Basis: legitimate interest (Art. 6(1)(f)).
  • Product analytics (page views and product events, only if you allow them) — to see which features are used. Basis: your consent (Art. 6(1)(a)); see section 4.
  • How you found us (campaign parameters, referrer, landing page) — to know which channels bring people here. Basis: legitimate interest; see section 6.
  • Country, derived from your IP address — security and aggregate statistics. Basis: legitimate interest; see section 7.
  • Error diagnostics — see section 5. Basis: legitimate interest.
  • Payment data — processed by Paddle as Merchant of Record and independent controller; we receive subscription status, never card numbers.

We do not sell personal data, do not use it for advertising, and do not use your content to train AI models.

3. Storage on your device

We store on your device only what the Service needs to work: authentication tokens and your preferences (including your interface language) in your browser's local storage, your videos in your browser's own database (IndexedDB) so they never have to leave your device, and the record of your cookie choice itself. All of this is strictly necessary and none of it is used for advertising or cross-site tracking.

4. Cookies and analytics

Analytics are opt-in. Until you choose to allow them in the consent banner, no analytics code is loaded, initialised or sent anything. The only thing stored before your decision is the decision itself, which is strictly necessary under ePrivacy Art. 5(3): it is the record of your choice, not a tracker.

If you opt in, we use PostHog to count usage: page views, product events (for example, that a transcription was started) and coarse technical data such as browser and device type. All text on the page is masked before anything leaves your browser, so the content of your media, transcripts, subtitles and translations is never part of an analytics event. Session recording is disabled — we do not record your screen. Events reference your account by an internal identifier only, never your e-mail or name. Legal basis: your consent (Art. 6(1)(a)).

Analytics data is processed on PostHog Cloud EU (Frankfurt), so it stays within the EU.

You can change your mind at any time through Cookie settings in the footer. Withdrawal takes effect immediately: capturing stops, the analytics SDK is opted out, and the identifiers it had stored in your browser are reset.

5. Error monitoring and session replay

We use Sentry to learn about crashes and errors. When an error occurs, Sentry stores the technical report and a masked replay of that session: what was clicked and how the page behaved, with all text and media content masked before it leaves your browser. We do not record sessions in which no error occurred. Reports reference your account by an internal identifier only, never your e-mail.

6. How you found us

If you arrive through a campaign or referral link, your browser passes along the campaign parameters in the address (utm_source, utm_medium, utm_campaign and similar), the referring site and the page you landed on. We keep those in memory for the duration of your visit and, if you register, store them once together with your account, so we know which channels bring people to Captivo. No cookies or other tracking storage are used for this, and if you never register, nothing about that visit is stored at all.

7. Country from your IP address

When you register and when you perform actions we log, we derive a country code from your IP address using MaxMind's GeoLite2 web service. This is the country only — not a city, not coordinates, not a precise location. We use it to refuse service in regions we are not allowed to serve and for aggregate statistics. Basis: legitimate interest (Art. 6(1)(f)).

8. Who processes data for us

We use providers for speech recognition, translation, hosting, databases, e-mail, error monitoring and payments. The current list — each provider's role, the data it receives, its region and its privacy terms — is maintained at Subprocessors, so it stays accurate between revisions of this policy.

Where providers are outside the EU/EEA, transfers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses in the provider's data processing agreement.

9. Retention and deletion

  • Extracted audio is deleted from storage right after transcription.
  • Transcripts and translations stay until you delete them or your account.
  • Activity-log entries (the action, its time, the IP address and the user agent) are deleted automatically 90 days after they are recorded. We keep them that long to answer support requests and to investigate abuse.
  • Deleting your account removes your data from our database immediately; residual copies in encrypted backups of our providers expire within 30 days.
  • Error reports in Sentry expire automatically (90 days).

10. Your rights

You can access, correct, export (Settings → export your data) and delete (Settings → delete account) your data yourself, or write to privacy@captivo.app to exercise any GDPR right — access, rectification, erasure, portability, restriction, objection, and withdrawal of consent. You also have the right to lodge a complaint with your local data protection authority.

11. Children

The Service is not directed at children and requires users to be at least 16 (see the Terms). We do not knowingly process children's data.

12. Changes

We will announce material changes to this policy by e-mail or in the app and bump the version above. The current version always lives at this address.

Questions: privacy@captivo.app. See also the Terms of Service and Refund Policy.