Smart Capy Privacy Policy
Effective date: August 24, 2026
Last updated: August 24, 2026
Secero Inc. (“Secero,” “we,” “us,” or “our”) provides the Smart Capy mobile application, also displayed as “Capy,” and related websites, AI features, subscription services, and encrypted session-sharing services (collectively, the “Service”).
This Privacy Policy explains what information we process, why we process it, when it leaves your device, how long we keep it, and the choices available to you.
Our core privacy commitments
- We do not sell personal information or User Content.
- We do not share personal information for cross-context behavioral advertising or targeted advertising.
- We do not use recordings, transcripts, notes, prompts, chats, shared sessions, or other User Content to train Secero or third-party AI models.
- Audio recording and live transcription are designed to occur on your device. Audio is not included in a Capy sharing link and is not sent to our AI provider by Capy’s current AI features.
- Ordinary local sessions are not automatically uploaded to Supabase Storage. A session snapshot is uploaded only when you affirmatively create an encrypted Capy sharing link.
- Shared session snapshots are encrypted on your device. Supabase stores ciphertext for up to 30 days. Secero, Supabase, and Cloudflare do not receive the decryption key during normal link resolution.
- We do not routinely read or review your recordings, transcripts, notes, prompts, chats, or shared-session content. Our systems and contracted providers process limited content when you request an AI or sharing feature, as explained below.
These commitments do not mean that Capy collects no personal information. Account creation, AI features, analytics, subscriptions, and encrypted sharing require the limited processing described in this Policy.
1. Scope
This Policy applies to information processed through the Service. It does not govern a third-party website, app, sign-in provider, messaging service, or other service that has its own privacy policy.
Secero is the controller or business responsible for the practices described in this Policy. In some circumstances, a school, employer, or other organization may separately control information it instructs you to process. Contact that organization about its practices.
2. Information that stays on your device
Capy stores most session information locally on your iPhone or iPad, including, as applicable:
- audio recordings;
- live and finalized transcripts, word timing, speaker labels, and language information;
- session and class titles, organization, dates, class cover images you select, markers, highlights, notes, drawings, and selected time ranges;
- AI-generated summaries, key points, due dates, and action items returned to the app;
- session-specific and app-wide chat histories;
- imported Capy files and independently imported copies of shared sessions;
- app settings, appearance preferences, and selected audio-input settings; and
- local technical state needed to recover or open the app’s database.
This local information remains on your device unless you choose a feature that transmits some of it, such as AI processing, encrypted link sharing, file export, or the system share sheet. Local information may also be included in device backups according to your Apple and device-backup settings, which Secero does not control.
When you export a Capy file, PDF, highlight file, or similar document, Capy creates a local export copy and gives it to the destination you choose. Capy sharing-link export files in the app cache are eligible for automatic cleanup after approximately 24 hours; operating-system temporary files and copies held by the selected destination are controlled by those systems.
Removing the app may remove local information, subject to your device and backup settings. Signing out does not necessarily delete local sessions from the device. Delete sessions within Capy before giving another person access to the device.
3. Information we collect or receive
A. Account and authentication information
When you create or use an account, we and our authentication providers process:
- a Supabase account UUID;
- email address;
- account creation and last-sign-in dates;
- authentication provider;
- encrypted or hashed authentication credentials and authentication-session data; and
- if you use Google Sign-In, the name and profile-image URL made available by Google.
The app stores an authentication session on your device so you can remain signed in. Google and Supabase may also process device, network, and security information to authenticate you and prevent abuse.
B. AI feature content
Capy transmits content only when you request an AI-powered feature. Depending on the feature, this may include:
- Session insights: session ID, session title, session start date, time zone, finalized transcript text, segment IDs, timestamps, and speaker labels.
- Session chat: the same session context, your question, a selected transcript excerpt, recent or relevant chat history, and prior AI responses included in the conversation.
- Cross-session chat: your question and recent chat history; session IDs, titles, dates, and bounded summaries for candidate sessions; and, for a focused request, summaries and bounded transcript excerpts from up to four selected sessions. Broad questions may use summaries without full transcript excerpts.
- AI service metadata: account authentication token, completion type, request ID, selected model, usage amounts, and technical status or error category.
This information travels from the app to a Secero service hosted on Cloudflare and then to OpenAI for generation. It is returned to your device, where the result and chat history may be stored locally.
Secero does not maintain a product database of readable AI prompts, transcripts, or responses and does not routinely inspect them. Network, security, and provider logs may temporarily process request metadata. OpenAI may retain API inputs and outputs in abuse-monitoring logs for up to 30 days by default, unless a different approved retention control applies or longer retention is legally or safety-required. OpenAI states that API data is not used to train or improve its models unless the API customer explicitly opts in. Secero does not opt in to training with your User Content.
C. Encrypted session-sharing information
When you choose Share Capy Link, the app creates an immutable session snapshot that may include:
- finalized transcript text and word timings;
- speaker labels;
- session title, recording date, duration, detected language, and technical format metadata;
- markers, marker notes, colors, and selected time ranges; and
- supported AI analysis, such as summaries, key points, due dates, and action items.
The shared snapshot excludes audio recordings, AI chat histories, account identity, class membership and cover image, and live or partial transcript content.
Before upload, the app generates a random 256-bit key and encrypts the snapshot on your device using AES-256-GCM. The private Supabase Storage bucket receives only ciphertext. We also process the following sharing metadata:
- share ID and owner account UUID;
- server-generated storage path;
- document and encryption versions;
- encrypted file size;
- pending or ready state; and
- creation, ready, and expiration timestamps.
The decryption key is placed after the `#` in the complete sharing URL. URL fragments are not sent in ordinary HTTP requests, so Secero, Cloudflare, and Supabase do not receive the key during normal creation or resolution. A recipient who has the complete link and signs in to Capy can obtain a short-lived download URL, download the ciphertext, and decrypt the snapshot on the recipient’s device.
We do not routinely access or review shared-session content and cannot decrypt stored ciphertext without the complete link. The messaging, email, collaboration, or other service used to transmit the complete link may receive and retain the link, including its decryption key, under that service’s own privacy practices.
D. Product analytics
We use Mixpanel to understand how Capy is used and improve reliability, navigation, and features. Analytics may include:
- account UUID as a distinct analytics identifier;
- email address, authentication provider, and account creation date;
- optional Google display name and HTTPS profile-image URL;
- app environment, app version, build number, platform, and screen name;
- device and app metadata automatically collected by the Mixpanel iOS SDK; and
- feature interactions and coarse outcomes, such as screens viewed; sign-in and sign-out results; classes or sessions created, opened, renamed, or deleted; recording and playback actions; insights requests and outcomes; highlights and notes actions; chat actions and response outcomes; subscription-related screens; and encrypted-sharing lifecycle outcomes.
Some analytics events include an internal session UUID, whether a session is active or completed, whether it is assigned to a class, counts, durations, plan or feature state, coarse destination category, or a standardized error category.
Analytics are linked to your account. They are not anonymous.
Capy’s analytics code is designed to reject transcript content, questions, answers, selected excerpts, note content, message content, session or class names, filenames, credentials, complete sharing URLs, decryption keys, share IDs, recipient identities, and raw error messages. Mixpanel automatic event collection and IP-based geolocation are disabled in the app’s current configuration. Like any internet provider, Mixpanel may still receive network information needed to deliver a request and operate securely.
We use analytics for product improvement and service operation, not advertising.
E. Subscription, entitlement, and usage information
If you view, purchase, restore, or use a paid plan or metered feature, we may process:
- Apple product ID, subscription plan, subscription status, billing-cycle dates, and signed transaction information;
- an app-account token tied to your Secero account;
- included allowances and remaining balances;
- transcription minutes used; and
- AI allowance, cycle spend, total spend, credit grants, and credit usage counters.
Apple processes your payment method and purchase transaction. Secero does not receive your full payment-card or bank-account details.
F. Device, network, security, and operational information
When the app or website communicates with our services, Secero and its providers may process IP address, request time, endpoint, response status, app or browser information, authentication status, security signals, and limited logs needed to route traffic, rate-limit requests, detect abuse, diagnose failures, and keep the Service secure. We seek to avoid placing User Content, complete sharing links, or decryption keys in operational logs.
The app also detects microphone permission and available audio-input information on your device. Analytics records only coarse properties such as built-in versus external input, device count, and whether the selected input remains available—not the hardware name or UID.
G. Communications and website submissions
If you contact us, request support, exercise a privacy right, or join a website waitlist, we may collect your email address, the contents of your communication, and any information you choose to provide. Do not send sensitive session content in a support request unless it is necessary and you have permission to do so.
4. How we use information
We use information to:
- create and secure accounts and maintain signed-in sessions;
- provide local recording, transcription, organization, annotation, export, AI, and encrypted-sharing features;
- authenticate sharing-link senders and recipients;
- manage subscriptions, entitlements, usage allowances, and credits;
- provide support and respond to requests;
- measure feature use and improve the Service;
- maintain reliability, troubleshoot errors, prevent fraud or abuse, and enforce our Terms;
- comply with law and protect the rights, safety, and security of users, Secero, providers, and the public; and
- carry out a corporate transaction subject to the safeguards described below.
We may aggregate or de-identify information so it can no longer reasonably identify you. We may use de-identified information for analytics, security, and product improvement and will not attempt to re-identify it except to test our de-identification methods or as permitted by law.
5. No sale, advertising sharing, or training
Secero does not:
- sell or rent personal information or User Content;
- share personal information for cross-context behavioral advertising or targeted advertising;
- use advertising SDKs or data brokers in Capy;
- use User Content to train Secero models; or
- permit OpenAI or another AI provider to train models on User Content submitted through Capy.
We disclose information to service providers for the business purposes described in this Policy. That limited disclosure is not a sale and is not advertising “sharing” as those terms are defined by applicable U.S. state privacy laws.
6. When we disclose information
We may disclose information to:
- Supabase: account authentication, account and entitlement records, subscription synchronization, usage counters, sharing metadata, private encrypted-sharing storage, and short-lived signed upload or download URLs.
- Cloudflare: delivery and security of Secero’s API and sharing-link website, including transient AI requests, responses, authentication status, and operational metadata.
- OpenAI: prompts, transcript context, summaries, and other AI feature content described above, solely to generate requested AI output and operate the API safely. Secero does not opt this content into model training.
- Mixpanel: linked account profile fields and product-usage analytics described above, solely for analytics and product improvement.
- Google: sign-in requests and profile information when you choose Google Sign-In.
- Apple: app distribution, subscription purchase and management, transaction verification, device services, and any information processed by Apple under your Apple account and settings.
- Professional advisers and authorities: lawyers, auditors, insurers, regulators, law enforcement, courts, or other parties when reasonably necessary to comply with law, establish or defend legal claims, or protect rights and safety.
- Transaction counterparties: a buyer, investor, lender, successor, or adviser in a merger, financing, reorganization, bankruptcy, or sale of all or part of our business. Any successor will be required to handle personal information consistently with this Policy unless it provides legally required notice and choice.
- At your direction: recipients and services you select through sharing, export, system share sheets, or other integrations.
We require service providers to process information only for contracted services, protect it appropriately, and provide privacy protection consistent with this Policy and applicable law. Providers may process limited information for their own legal compliance, security, fraud prevention, and service-integrity obligations.
7. Retention
We retain information only for as long as reasonably necessary for the purposes described above, subject to the following:
- Local content: remains on your device until you delete it, delete the app, erase the device, or it is removed under your device or backup settings. Secero does not control copies in your device backups or exported files.
- Ready encrypted shares: remain downloadable for up to 30 days after creation and are then scheduled for deletion. Cleanup runs periodically, so technical deletion may occur shortly after expiration rather than at the exact expiration second.
- Incomplete encrypted uploads: are scheduled for deletion after approximately one hour.
- Recipient imports: are independent local copies controlled by the recipient and are not deleted when the hosted ciphertext expires.
- AI requests: Secero processes readable AI content in transit and does not keep it in a product-content database. OpenAI’s default abuse-monitoring retention may be up to 30 days, subject to approved account controls and limited legal or safety exceptions.
- Account and entitlement records: are retained while your account is active and for a limited period afterward as needed to complete deletion, maintain security, resolve disputes, enforce agreements, and meet legal obligations.
- Subscription and transaction records: are retained as required for entitlement verification, accounting, tax, fraud prevention, disputes, and legal compliance.
- Analytics: are retained for up to 24 months, after which they are deleted or de-identified, unless a shorter period is required by law or you request deletion.
- Support and privacy requests: are retained for as long as needed to respond and maintain an appropriate record of the request.
- Security and operational logs: are retained for a limited period appropriate to their security, reliability, and legal purpose.
Deletion from active systems may not immediately remove information from encrypted backups. Backup copies are isolated from ordinary use and expire under provider backup schedules unless law requires longer retention. We may retain a minimal record of a deletion request, transaction, or legal hold where required or permitted by law.
8. Your choices and rights
Local content and permissions
You can delete local sessions and chats in the app, control microphone permission in iOS or iPadOS Settings, choose whether to use AI features, and choose whether to create or open a sharing link. You can export content before deletion.
Because a completed sharing link is not currently revocable, do not create a link unless you are comfortable with the encrypted snapshot remaining available to anyone with the complete link and an authenticated Capy account for up to 30 days.
Account information and deletion
You may request access to, correction of, or deletion of account information by contacting [email protected]. We may need to verify your identity. Account deletion does not cancel an App Store subscription, delete copies already exported or imported by another person, or remove information we must retain by law.
Analytics
You may object to or request deletion of linked analytics by contacting [email protected]. Uninstalling Capy stops future app analytics from that installation but does not by itself delete information already received.
Privacy-law rights
Depending on where you live, you may have rights to:
- know whether and how we process your personal information;
- access or receive a portable copy;
- correct inaccurate information;
- delete information;
- restrict or object to certain processing;
- withdraw consent, where processing is based on consent;
- opt out of sale, targeted advertising, or certain profiling;
- appeal a denied request; and
- complain to a privacy or data-protection authority.
We do not sell personal information, use it for targeted advertising, or make decisions producing legal or similarly significant effects based solely on automated processing. We will not discriminate against you for exercising a privacy right.
To submit a request or appeal, contact [email protected] with the subject “Privacy Request.” Authorized agents may submit requests where permitted by law, but we may require proof of authority and identity verification. We will respond within the period required by applicable law.
9. California privacy notice
This section applies to California residents to the extent the California Consumer Privacy Act, as amended (“CCPA”), applies to Secero.
During the preceding 12 months, we may have collected the following CCPA categories:
| Category | Examples | Sources | Business or commercial purposes | Categories of recipients |
| --- | --- | --- | --- | --- |
| Identifiers | Account UUID, email, optional name and profile-image URL, IP address | You, your device, Google, Apple, Supabase | Authentication, security, support, analytics, subscriptions, sharing | Supabase, Cloudflare, Mixpanel, Google, Apple, OpenAI as applicable |
| Commercial information | Product ID, plan, subscription status, signed transaction information, credits and allowances | You, Apple, app and backend | Purchases, entitlements, accounting, fraud prevention | Apple, Supabase, Cloudflare |
| Internet or electronic activity | Screens and features used, actions, app/build/platform metadata, request and error status | App, device, service providers | Service operation, analytics, security, improvement | Mixpanel, Cloudflare, Supabase |
| User content | AI prompts, transcript context, summaries, selected excerpts, encrypted session snapshots | You and your use of features | Requested AI generation and encrypted sharing | Cloudflare, OpenAI, Supabase ciphertext storage, recipients at your direction |
| Inferences | Coarse feature preferences or likely relevant sessions selected for a chat request | App and AI processing | Personalize the requested response and improve features | Cloudflare, OpenAI, Mixpanel for coarse feature analytics |
We have not sold these categories or shared them for cross-context behavioral advertising during the preceding 12 months. We do not have actual knowledge that we sell or share personal information of anyone under 16. We do not use or disclose sensitive personal information to infer characteristics about you or for purposes that trigger a right to limit under the CCPA.
California residents may request to know, access, correct, or delete covered information and may exercise any other applicable CCPA right using the methods in Section 8. We do not offer a financial incentive in exchange for personal information.
California’s “Shine the Light” law may permit residents to request information about disclosures for third parties’ direct marketing. We do not disclose personal information to third parties for their own direct marketing.
10. European Economic Area, United Kingdom, and Switzerland
If European data-protection law applies, Secero Inc. is the controller for processing described in this Policy. We rely on the following legal bases:
- Contract: to create your account and provide requested app, AI, sharing, subscription, and support features.
- Legitimate interests: to secure, operate, analyze, and improve the Service, prevent abuse, and protect rights, balanced against your rights and expectations.
- Consent: where required for analytics, device permission, or another specific processing activity. You may withdraw consent prospectively.
- Legal obligation: to comply with tax, accounting, law-enforcement, regulatory, and other binding requirements.
Information may be processed in the United States and other countries that may not provide the same level of protection as your home country. Where required, we use recognized transfer safeguards, such as adequacy decisions or standard contractual clauses.
You may contact Secero directly at [email protected] or Secero Inc., Attn: Privacy, 1111B S Governors Ave #39431, Dover, DE 19904, United States to exercise your rights. You may also lodge a complaint with your local supervisory authority.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information. Current measures include on-device AES-256-GCM encryption for shared snapshots, private Supabase Storage, short-lived signed transfer URLs, authenticated sharing endpoints, access controls, and restrictions intended to keep content and secrets out of analytics and routine logs.
No safeguard is perfect. We cannot guarantee that information will never be lost, accessed, disclosed, altered, or destroyed. Protect your device, account credentials, exported files, and complete sharing links. Notify us at [email protected] if you believe your account or information has been compromised.
12. Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided personal information, contact [email protected] so we can investigate and delete it where required.
Users under the age of legal majority must have permission from a parent or legal guardian. Schools and other organizations using Capy with students are responsible for obtaining any consent required by education and children’s privacy laws.
13. Recording and third-party privacy
Capy may capture the voices and statements of people other than the account holder. The person using Capy controls when recording begins and is responsible for providing notices and obtaining consents required by applicable recording, wiretap, education, employment, privacy, and intellectual-property laws. Please do not record or share a person without lawful authority.
If another user records or shares information about you, contact that user first because the recording and most session data may exist only on devices Secero cannot access. You may also contact us at [email protected], and we will assist where technically and legally possible.
14. Changes to this Policy
We may update this Policy as the Service or law changes. We will post the updated version and revise the “Last updated” date. If a change materially affects how we use previously collected information, we will provide additional notice and obtain consent where required.
We will not begin selling User Content, sharing personal information for targeted advertising, or using User Content for model training through a silent policy update.
15. Contact us
For privacy questions or requests:
Secero Inc.
Attn: Privacy
1111B S Governors Ave #39431
Dover, DE 19904
United States
Email: [email protected]