KAPTRA

Privacy Policy

  • Effective date: 10 September 2026
  • Last updated: 10 September 2026
  • Operator: Kaptra LLC (“Kaptra”, “we”, “us”)
  • Scope: the website, console, API, documentation, community and other related services provided by Kaptra (together, the “Service”)

This Privacy Policy explains how Kaptra collects, uses, stores, shares and protects personal information when you visit, register for and use the Service, and the rights you have over your personal information. This Policy forms part of the Kaptra Terms of Service; where the two differ on the handling of personal information, this Policy prevails.

Please read this Policy carefully before using the Service. By registering an account, ticking a consent box or actually using the Service, you confirm that you have read and understood the processing described here. If you do not agree, please do not use the Service.


1. Information we collect

We collect information only to the extent necessary to provide the Service, keep it secure, bill for it and meet our legal obligations.

1.1 Information you provide

  • Account information: your email address and login password (stored in encrypted form).
  • Payment information: top-up amounts, transaction records and the details needed for invoices. Sensitive payment-instrument data such as full card numbers is handled by third-party payment providers, and we normally do not store it.
  • Business and verification information: the entity details, use-case descriptions, authorisation materials and similar that you provide during customer due diligence, enterprise onboarding or custom requests.
  • Communications: the content and records of your contact with us through tickets, email or the community.

1.2 Information generated when you use the Service

  • Logs and usage data: IP address, access timestamps, User-Agent, service consumption, API endpoints called, request rate and concurrency characteristics.
  • Task data: task type, success or failure, duration, credits consumed, error codes, and the target domain or site identifier you submit with a task.
  • Device and linked identifiers: device fingerprints and linked identifiers used for risk control and to prevent ban evasion.
  • Cookies and login tokens: see Section 5.

1.3 Task payloads (important)

To complete recognition you submit business payloads to us: images, interaction parameters, page fragments and the like. These payloads are used only to complete that one recognition and are not kept afterwards as training material. Samples retained temporarily for troubleshooting are kept for no more than 7 days, are not used to train general models offered to other customers, and are deleted when that period ends. If you separately commission custom model training in writing, the payloads are handled within the scope of that commission.

1.4 Information from third parties

Third-party payment providers may pass us the payment amount, transaction status and invoice details to confirm a transaction. We do not actively obtain personal information from third parties beyond what the Service needs.

We do not actively collect special categories of sensitive personal information such as race, religion, health or biometric data. Please do not submit such information, or personal information of others that you are not entitled to submit, in task payloads or tickets.


2. How we use information

We process personal information for the following purposes:

  • Providing the Service: creating and managing accounts, issuing and verifying API keys, running recognition tasks and returning results.
  • Billing and reconciliation: handling top-ups, charges, refunds, invoices and transaction disputes.
  • Security and anti-abuse: identity verification, risk control, rate limiting, circuit breaking, preventing fraud and ban evasion, and enforcing the Terms of Service.
  • Operating and improving the Service: quality statistics, troubleshooting and performance tuning based on task metadata. We do not use your task payloads to train general models offered to other customers.
  • Communication and support: answering tickets and enquiries, and sending the notices the Service requires.
  • Legal obligations: meeting cybersecurity, tax, accounting and regulatory requirements, and responding to lawful requests from law enforcement or rights holders.

Where the law of your region requires a legal basis for processing personal information (for example the EU General Data Protection Regulation), ours are: performance of our contract with you (account, Service, billing); our legitimate interests (security, anti-abuse, service improvement); compliance with legal obligations (data retention, assisting law enforcement); and, where necessary, your consent (non-essential cookies, marketing messages). You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before it.


3. How we share information

We do not sell your personal information, and we do not disclose it to third parties except in the following cases:

  • with your authorisation or consent;
  • to processors needed to provide the Service: payment processors, cloud infrastructure and content delivery providers (including Cloudflare), analytics and customer support tools, and the like. We give them information only to the extent necessary and require them to take on confidentiality and security obligations equivalent to this Policy;
  • legal and safety requirements: where required by law or regulation or by a lawful request of a competent authority, or where necessary to prevent imminent harm or to protect public safety and the legitimate rights of others;
  • business transfers: in a reorganisation, merger, acquisition or asset transfer, where the successor remains bound by this Policy.

The main categories of processors we currently use are cloud computing and content delivery, payment processing, analytics and customer communication tools. The list may change with the business, and we will update this Policy when it does.


4. Cross-border data transfers

Kaptra serves developers in many countries and regions, and we and our processors may store or process personal information outside the country or region you are in. We apply the safeguards required by applicable law (such as standard contractual clauses or other lawful mechanisms) so that personal information transferred across borders receives protection equivalent to this Policy. Where your region has specific requirements for cross-border transfers, we will obtain your separate consent or make the corresponding compliance arrangements as needed.


5. Cookies and login tokens

  • Cookies: we use cookies to sign you in and keep your session. You can refuse some or all cookies in your browser, but some features may not work properly once they are disabled.
  • Login tokens: used to authenticate your signed-in state and stored in our systems for no more than 7 days; the token is deleted when you sign out.
  • Do Not Track: when we detect a DNT (Do Not Track) signal from your browser, we do not carry out the corresponding tracking or set non-essential cookies.

6. Data retention

We keep personal information only for as long as necessary for the purposes described in this Policy, or longer where the law requires. In general:

  • account information: for as long as you hold the account; after closure it is deleted or anonymised, except for what must be kept by law or to prevent fraud;
  • network operation and access logs: no less than 6 months, or longer where applicable law requires;
  • transaction, charge and invoice records: for the period required by applicable accounting and tax rules;
  • ticket, communication and abuse-report records: generally 3 years;
  • task payloads: see Section 1.3; deleted as soon as recognition completes, with troubleshooting samples kept no more than 7 days.

When there is no longer a business or legal need to keep information, we delete or anonymise it. Where deletion is temporarily impossible for technical reasons (such as backup archives), we store the information in secure isolation until it can be deleted.


7. Your rights

To the extent permitted by applicable law, you have the following rights over your personal information:

  • to be informed and to access: to learn how we process your information and to obtain a copy;
  • to rectify and complete: to correct inaccurate or incomplete information;
  • to erase: to have your information deleted where the conditions are met;
  • to restrict and object: to restrict or object to our processing in particular circumstances;
  • to portability: to obtain or transfer the information you provided, where technically feasible;
  • to withdraw consent: at any time, for processing based on consent;
  • not to be subject to solely automated decisions: to request human intervention in any solely automated decision that significantly affects you.

You can change some information yourself in your account settings, or exercise the rights above by emailing [email protected]. To protect your account we may ask you to verify your identity first. We will reply within the period set by applicable law. If you believe our processing infringes your rights, you have the right to lodge a complaint with a competent supervisory authority.

The law of your country or region may give you additional or different rights. You can make the corresponding request through the same channel, and we will not treat you differently for exercising your rights.


8. Minors

The Service is for users aged 18 or over with full legal capacity. We do not knowingly collect personal information from anyone under 18. If we find that we have collected a minor’s information, we will disable the account concerned and delete the information promptly.


9. Security

We take reasonable and appropriate technical and organisational measures to protect personal information, including encryption in transit (such as TLS), least-privilege access control in production, and restricted access to keys and logs. Even so, no transmission or storage over the internet can be guaranteed absolutely secure. Sending information to the Service carries inherent risk, and you must take reasonable care yourself (for example by keeping your keys safe).

If a personal-information security incident occurs that may affect your rights, we will take remedial measures promptly as applicable law requires and, where necessary, notify you and the relevant supervisory authorities.


10. Changes to this Policy

We may revise this Policy from time to time. The revised version will be published on the website with an updated “Last updated” date. For changes that materially and adversely affect your rights or obligations, we will give reasonable advance notice before they take effect, normally no less than 30 days, by website announcement, console notice or email from our official address; where applicable law requires, we will obtain your consent again. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.


11. Contact us

If you have any questions, complaints or rights requests about this Policy or the handling of personal information, contact us through:

Official technical support & tickets

Powered by the Discord Ticket system

  1. Click the button below to join the official Discord server
  2. Go to #open-ticket and click "Open ticket"
  3. The system creates a private 1:1 channel where engineers respond online
Open Discord to submit a ticket ↗