Legal
Privacy Policy
Version 2026-08-20 · Capprly
Effective 2026-08-20. This policy explains what Capprly collects, why, and the control you have over it.
1. What we collect
- Account data: email address, display name, and authentication identifiers (including Google sign-in id if you use it).
- Creator data: your public creator page, application details and everything you publish.
- Activity data: follows, tails, picks viewed and product events used to measure the signup, creator and subscription funnels.
- Billing data: subscription status, renewal dates and a payment processor customer id. Card numbers are never sent to or stored by Capprly.
- Technical data: IP-derived request metadata and error logs used for security, rate limiting and debugging.
2. Why we use it
- To run your account, keep the verified record accurate and deliver premium access you paid for.
- To prevent fraud, abuse, scraping and unauthorised access.
- To measure product funnels in aggregate so we can improve the service.
- To send transactional email: confirmations, password resets, receipts and important account notices.
We do not sell personal data, and we do not use your data to build advertising profiles.
3. Who processes it
We use a managed cloud database and authentication provider to store account data, and a payment processor for subscriptions and creator payouts. These providers act on our instructions under contract and may process data in the United States.
4. How long we keep it
- Account and profile data: while the account is open, then removed or anonymised after closure.
- Published picks and grading records: retained permanently in de-identified form, because the integrity of a public record depends on it.
- Billing records: retained as long as tax and accounting law requires.
- Product analytics: retained in aggregate; identifiers removed on account deletion.
5. Your controls
From account settings you can update your profile, download a machine-readable export of everything tied to your account, and request deletion. Deletion requests are actioned by a human and confirmed by email. You can also email privacy@capprly.com.
6. Security
- Row-level database authorisation: every table is access-controlled per account, not by client-side checks.
- Premium content is masked server-side; the browser never receives picks you have not paid for.
- Sensitive operations are rate limited and audit logged.
- Payment credentials and service keys are held server-side only.
7. Children
Capprly is not directed to anyone under 21. We do not knowingly collect data from minors, and we delete such accounts when identified.
8. Changes
Material changes are announced in-product with a new policy version recorded against your acceptance. Questions: privacy@capprly.com.