CDCapraDesk

Privacy Policy

Last updated: 27 June 2026

1. Data We Collect

Account data: email, name, organization info (via Supabase Auth).

Ticket data: titles, descriptions, comments, customer emails — stored in your org’s scope.

Knowledge base: articles you create for AI triage context.

Payment data: handled by Stripe. We store customer ID and subscription status only.

Analytics: page views via CapraLens (first-party). No third-party tracking.

2. AI Processing

When AI triage runs, ticket content and knowledge base articles are sent to Anthropic’s Claude API. Anthropic does not use API inputs for training. Data is processed in-memory and not stored by the provider.

3. Data Sharing

We do not sell data. We share data only with: Supabase (database, EU), Stripe (payments), Anthropic (AI triage), Resend (email), and Vercel (hosting).

4. Security

All connections use TLS. API keys are hashed with SHA-256. Row-level security policies enforce org isolation. Webhook secrets use HMAC verification.

5. Your Rights

You can export or delete your organization data by contacting support. Under GDPR, you have the right to access, rectification, erasure, and data portability.

6. Cookies

We use essential cookies only: Supabase authentication session. No advertising or tracking cookies.

7. Contact

For privacy questions: support@capradesk.com.