CapacityLab
How it worksDemo reportsOpen sourcePricingSecurityBlog
ENRU
Console ↗

Privacy

Privacy Policy

What CapacityLab collects about customers and website visitors, why, on what legal basis, for how long, who receives it, and how you exercise your rights.

Last updated: October 6, 2026

This policy is written to meet Articles 13 and 14 of the GDPR. It covers the website at capacitylab.dev, the CapacityLab console at app.capacitylab.dev, the MCP API, and support and booking channels.

1. Who is responsible

The controller is CapacityLab (operator: _legal entity and registered address to be completed by the owner_). Reach the person responsible for data protection at security@capacitylab.dev — it is the single address for privacy requests, security reports and questions about this policy. No data protection officer is designated: the processing is neither large-scale nor systematic monitoring, and involves no special categories of data.

When you connect your own infrastructure provider and run diagnostics on your systems, CapacityLab acts as your processor for the data inside those systems; you are the controller, and our Data Processing Agreement applies.

2. What we process, why, and on what legal basis

| Processing | Data | Purpose | Legal basis (Art. 6) | Kept for | | ---------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | ---------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | | Account and sign-in | email address, linked Google/GitHub or organization SSO identifier, display name, organization membership and role, session cookie | providing the console, authorisation | contract (1b) | until the account closes; then identifying fields are erased or pseudonymized as described below | | MCP OAuth | OAuth client metadata, consent, scopes, Project and organization reference, access and refresh credential records | agent access to the API | contract (1b) | access credentials expire after 10 minutes and refresh credentials after 30 days; revocation and audit records follow the security retention below | | Connected providers | the credentials you connect (encrypted at rest), the metadata of your applications and topology | running the diagnostics you ask for | contract (1b) | until you disconnect or close the account | | Diagnostics, reports and artifacts | run configuration, results, evidence, reports | the product itself | contract (1b) | raw load-test output 30 days (365 on request); results and reports for the account's life | | Action log | who did what and when in the account, from which address | security, investigations, showing you what happened | legitimate interest (1f): protecting the service and its customers | 365 days; sign-in and refusal events 180 days | | Billing | your credit balance and its movements in US dollars, checkout and order identifiers from Polar; card details never reach us | payment and accounting | contract (1b); retention — legal obligation (1c) | 10 years (accounting), keyed by an account hash, not your email | | Console telemetry | page views by route, Web Vitals, errors, traces of the console's own API calls; session not persistent, no IP kept | reliability and performance of the console | legitimate interest (1f) with the right to object — switch in Settings | per the monitoring retention (weeks, not years) | | Website analytics | page paths without query strings, coarse device and referrer categories, section reach, Web Vitals — only after you allow it | finding broken pages and understanding which content is useful | consent (1a / ePrivacy) | not persisted across visits; consent choice 180 days | | Support chat | messages and the contact details you give, page context | answering you | contract or pre-contractual steps (1b) | for the conversation and 3 years after, as evidence of handling | | Booking a call | name, email and the answers you give when booking | scheduling and preparing the call | consent / pre-contractual steps (1b) | until the engagement ends, then 3 years | | Payment webhooks | the payment provider's event payloads, sender address and user agent | reconciling payments | contract (1b) | 30 days, unless the billing ledger still references the event | | Operational logs and traces | structured events without bodies or secrets; spans without client address or user agent | operating the service, incidents | legitimate interest (1f) | 30–90 days | | Security and privacy requests | your email and the content of your request | handling vulnerabilities and rights requests | legal obligation (1c) / legitimate interest (1f) | 3 years after closure, as proof of handling |

The retention periods and limits in force are published with their version date on the Limits and rules page, which is the source of their current values.

We do not ask for, and you should not send, passwords, private keys, production credentials or special categories of personal data. Account data is required to provide the service; without an email address there is no account.

3. Who receives data

We do not sell personal data. It is processed by the following providers, each under a written agreement, and disclosed otherwise only when the law requires it:

runtime-identical worker mirror. Neither is the diagnostic artifact store.

(global network; transfers outside the EEA are covered by the EU–US Data Privacy Framework and Standard Contractual Clauses).

never us your card (region: _to be confirmed by the owner_; transfer covered by DPF/SCC).

button.

booking button (regions: _to be confirmed by the owner_).

it to test a protected Preview.

  • Railway — hosts the application and its database.
  • Fly.io — runs the managed, per-Run diagnostic worker.
  • Tigris — stores diagnostic artifacts, reports and runtime manifests.
  • Google OAuth — an optional sign-in provider configured through Clerk.
  • Google Artifact Registry — canonical software images; Fly Registry holds the
  • Cloudflare — DNS, TLS, this website, email routing for security@
  • Polar — payments and invoices; sees your email and what you bought,
  • Chatwoot — support chat (EU), loaded only when you press the support
  • Tymeslot and Cal.com — call booking, loaded only when you press the
  • Vercel API — your own Vercel team, only after you explicitly connect

Source hosting, CI and container registries hold no customer data. The current list, with regions and the date each provider was last reviewed, is kept on the Security page.

4. Transfers outside the EEA

Processing locations depend on the configured service and the applicable provider arrangement; the current Fly/Tigris/Railway architecture does not by itself establish EU-only or Frankfurt-only residency. Before relying on a regional processing or international-transfer commitment, contact security@capacitylab.dev for the applicable locations, provider agreements and safeguards. A provider's general certification is not proof that a particular transfer is covered.

5. Cookies and similar technologies

Website analytics. We use PostHog to understand whether the website works and which content is useful. PostHog is disabled by default and its code is loaded only after a visitor explicitly allows the analytics category in our privacy controls. It is served from our own proxy on `capacitylab.dev`, so the browser never sends telemetry to PostHog directly; the project discards client IP addresses, keeps no cross-visit identifier and has session replay switched off. PostHog (PostHog Cloud, United States) receives this website telemetry after that consent. It may then collect page paths with query strings removed, sanitized UTM campaign labels, coarse referrer, language, device, viewport and connection categories, section reach, scroll milestones, bounded visible time and the last visible section, named link and calculator interactions without form values, browser errors, navigation timing and Web Vitals. Website telemetry does not include session replay, mouse coordinates, keystrokes, form text, email addresses, full referrer URLs, exact screen dimensions or persistent cross-visit analytics identifiers, and analytics sessions are not persisted between visits.

whether analytics was allowed, together with CookieConsent's consent record metadata. It is not sent to PostHog. Change or withdraw your choice any time under Cookie settings in the footer; withdrawing stops collection and reloads the page without PostHog.

Chatwoot widget from `app.chatwoot.com`, which then receives the page and browser context needed to run the conversation and sets a `cw_conversation` cookie to keep the conversation across pages. Support chat is a functional service you request and is independent of the analytics category. See Chatwoot's cookie documentation.

booking button.

signed in; there are no passwords.

notice on your first visit, and a switch under Settings → Privacy that turns it off for that browser (`capacitylab-console-analytics`, one year). It never sends your email or name, request bodies, headers, query strings or cookies.

  • `capacitylab_consent` (strictly necessary, up to 180 days) — remembers
  • Support chat. The Report a problem launcher does not contact Chatwoot until a visitor explicitly presses it. Opening it loads the
  • Booking. The Tymeslot scheduler is contacted only after you press the
  • Console session (`__Secure-capacitylab.session_token`, HttpOnly) — keeps you
  • Console telemetry — first-party and self-hosted, on by default with a

6. Your rights

You have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to take it with you in a machine-readable form, and to withdraw consent at any time without affecting what was done before. In the console, Settings → Your data → Download gives you everything we hold about you as JSON, and Delete account closes the account and replaces your email with a pseudonym wherever it was kept, while retaining only what the table above lists.

For anything else, write to security@capacitylab.dev. To protect your data we verify requests: sign in to the console, or write from the email address on the account. We answer within 30 days; if a request is complex we tell you within that time and take up to two further months.

You also have the right to lodge a complaint with a supervisory authority — the one in the EU member state where you live or work, or the authority of the controller's establishment (_to be named by the owner_).

7. Security

How we protect data — encryption, access control, logging, vulnerability handling and what we do within 72 hours of a breach — is described on the Security page.

8. Changes

We change this policy when the processing changes, and we note the date at the top. Material changes are announced in the console before they take effect.

CapacityLab

Evidence-led capacity testing for applications your team already owns.

support@capacitylab.dev
ProductHow it worksEvidenceWe ❤️ open sourcePricingConsole
LegalTermsPrivacyLimits and rulesRefunds & cancellationSecurityDPA
ElsewhereLinkedInXTelegramYouTube