Last updated: August 22, 2026
This policy is written to meet Articles 13 and 14 of the GDPR. It covers the website at capacitylab.dev, the CapacityLab console at app.capacitylab.dev, the MCP API, and support and booking channels.
1. Who is responsible
The controller is CapacityLab (operator: _legal entity and registered address to be completed by the owner_). Reach the person responsible for data protection at security@capacitylab.dev — it is the single address for privacy requests, security reports and questions about this policy. No data protection officer is designated: the processing is neither large-scale nor systematic monitoring, and involves no special categories of data.
When you connect your own infrastructure provider and run diagnostics on your systems, CapacityLab acts as your processor for the data inside those systems; you are the controller, and our Data Processing Agreement applies.
2. What we process, why, and on what legal basis
| Processing | Data | Purpose | Legal basis (Art. 6) | Kept for | | ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------ | | Account and sign-in | email address, Google/GitHub/Telegram account identifier, display name, role in the account, session cookie | providing the console, authorisation | contract (1b) | until the account closes; then the email is replaced by a pseudonym everywhere it was kept | | MCP API tokens | token digest (never the token), owner, scopes, dates | agent access to the API | contract (1b) | 90 days of life; the record stays under a pseudonym after account closure | | Connected providers | the credentials you connect (encrypted at rest), the metadata of your applications and topology | running the diagnostics you ask for | contract (1b) | until you disconnect or close the account | | Diagnostics, reports and artifacts | run configuration, results, evidence, reports | the product itself | contract (1b) | raw load-test output 30 days (365 on request); results and reports for the account's life | | Action log | who did what and when in the account, from which address | security, investigations, showing you what happened | legitimate interest (1f): protecting the service and its customers | 365 days; sign-in and refusal events 180 days | | Billing | your plan, its renewal dates, included-budget movements in US dollars, checkout and order identifiers from Polar; card details never reach us | payment and accounting | contract (1b); retention — legal obligation (1c) | 10 years (accounting), keyed by an account hash, not your email | | Console telemetry | page views by route, Web Vitals, errors, traces of the console's own API calls; session not persistent, no IP kept | reliability and performance of the console | legitimate interest (1f) with the right to object — switch in Settings | per the monitoring retention (weeks, not years) | | Website analytics | page paths without query strings, coarse device and referrer categories, section reach, Web Vitals — only after you allow it | finding broken pages and understanding which content is useful | consent (1a / ePrivacy) | not persisted across visits; consent choice 180 days | | Support chat | messages and the contact details you give, page context | answering you | contract or pre-contractual steps (1b) | for the conversation and 3 years after, as evidence of handling | | Booking a call | name, email and the answers you give when booking | scheduling and preparing the call | consent / pre-contractual steps (1b) | until the engagement ends, then 3 years | | Payment webhooks | the payment provider's event payloads, sender address and user agent | reconciling payments | contract (1b) | 30 days, unless the billing ledger still references the event | | Operational logs and traces | structured events without bodies or secrets; spans without client address or user agent | operating the service, incidents | legitimate interest (1f) | 30–90 days | | Security and privacy requests | your email and the content of your request | handling vulnerabilities and rights requests | legal obligation (1c) / legitimate interest (1f) | 3 years after closure, as proof of handling |
We do not ask for, and you should not send, passwords, private keys, production credentials or special categories of personal data. Account data is required to provide the service; without an email address there is no account.
3. Who receives data
We do not sell personal data. It is processed by the following providers, each under a written agreement, and disclosed otherwise only when the law requires it:
(global network; transfers outside the EEA are covered by the EU–US Data Privacy Framework and Standard Contractual Clauses).
never us your card (region: _to be confirmed by the owner_; transfer covered by DPF/SCC).
button.
booking button; the booking is then mirrored into Fibery, our work tracker, as a task with your name and email (regions: _to be confirmed by the owner_).
provider you connected, only after an explicit connection.
- Railway — hosts the application and its database (EU).
- Google Cloud — runs diagnostics and stores reports (Frankfurt, EU).
- Cloudflare — DNS, TLS, this website, email routing for security@
- Polar — payments and invoices; sees your email and what you bought,
- Chatwoot — support chat (EU), loaded only when you press the support
- Tymeslot and Cal.com — call booking, loaded only when you press the
- Vercel, Render, Railway provider APIs — your own resources at the
Source hosting, CI and container registries hold no customer data. The current list, with regions and the date each provider was last reviewed, is kept on the Security page.
4. Transfers outside the EEA
Your data is stored in the EU. Where a provider above operates globally (Cloudflare) or in the United States (Polar, possibly Fibery or Tymeslot), the transfer relies on the EU–US Data Privacy Framework where the provider is certified and on the European Commission's Standard Contractual Clauses otherwise. Copies of the safeguards are available on request.
5. Cookies and similar technologies
Website analytics. We use a self-hosted Grafana Faro pipeline to understand whether the website works and which content is useful. Faro is disabled by default and its code is loaded only after a visitor explicitly allows the analytics category in our privacy controls. It may then collect page paths with query strings removed, sanitized UTM campaign labels, coarse referrer, language, device, viewport and connection categories, section reach, scroll milestones, bounded visible time and the last visible section, named link and calculator interactions without form values, browser errors, navigation timing and Web Vitals. Website telemetry does not include session replay, mouse coordinates, keystrokes, form text, email addresses, full referrer URLs, exact screen dimensions or persistent cross-visit analytics identifiers, and analytics sessions are not persisted between visits.
whether analytics was allowed, together with CookieConsent's consent record metadata. It is not sent to Grafana Faro. Change or withdraw your choice any time under Cookie settings in the footer; withdrawing stops collection and reloads the page without Faro.
Chatwoot widget from `app.chatwoot.com`, which then receives the page and browser context needed to run the conversation and sets a `cw_conversation` cookie to keep the conversation across pages. Support chat is a functional service you request and is independent of the analytics category. See Chatwoot's cookie documentation.
booking button.
signed in; there are no passwords.
notice on your first visit, and a switch under Settings → Privacy that turns it off for that browser (`capacitylab-console-analytics`, one year). It never sends your email or name, request bodies, headers, query strings or cookies.
- `capacitylab_consent` (strictly necessary, up to 180 days) — remembers
- Support chat. The Report a problem launcher does not contact Chatwoot until a visitor explicitly presses it. Opening it loads the
- Booking. The Tymeslot scheduler is contacted only after you press the
- Console session (`__Secure-authjs.session-token`, HttpOnly) — keeps you
- Console telemetry — first-party and self-hosted, on by default with a
6. Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to take it with you in a machine-readable form, and to withdraw consent at any time without affecting what was done before. In the console, Settings → Your data → Download gives you everything we hold about you as JSON, and Delete account closes the account and replaces your email with a pseudonym wherever it was kept, while retaining only what the table above lists.
For anything else, write to security@capacitylab.dev. To protect your data we verify requests: sign in to the console, or write from the email address on the account. We answer within 30 days; if a request is complex we tell you within that time and take up to two further months.
You also have the right to lodge a complaint with a supervisory authority — the one in the EU member state where you live or work, or the authority of the controller's establishment (_to be named by the owner_).
7. Security
How we protect data — encryption, access control, logging, vulnerability handling and what we do within 72 hours of a breach — is described on the Security page.
8. Changes
We change this policy when the processing changes, and we note the date at the top. Material changes are announced in the console before they take effect.