Privacy policy

Last updated: March 2026

Data controller

The data controller is Clément Guérin, sole proprietor (micro-enterprise), SIRET: 10028571700011, located at 43 Quai Malakoff, 44000 Nantes, France. For any data-related inquiries: hello@autokap.app

Data collected

When using AutoKap, we collect the following data:

  • Account data : email address, user ID (via Supabase Auth)
  • Usage data : pages visited, actions performed in the application (via PostHog, only with your consent)
  • Screenshots and videos : screenshots and videos generated via the service are stored in Supabase Storage and linked to your account
  • Authentication data : if you use the automatic login feature for your captures, the credentials you provide (URL, email, password) are encrypted (AES-256-GCM) and stored in our database
  • AI data : content submitted to AI features (page analysis, conversational assistant) is sent to our AI model provider (OpenRouter) for processing, without permanent storage on our end
  • Billing data : managed by Stripe — we do not store your banking details

Purposes of processing

  • Providing and operating the AutoKap service
  • Managing your account and subscription
  • Product improvement (anonymized analytics with consent)
  • Service-related communications (updates, incidents)

Legal basis

  • Contract performance : processing of data necessary to provide the service
  • Legitimate interest : product improvement via anonymized analytics
  • Consent : analytics cookies (PostHog), collected via the consent banner

Data retention

  • Account data : retained until account deletion
  • Screenshots and videos : retained according to your plan's retention period, or until deleted by the user or account closure
  • Analytics data : 12 months maximum
  • Billing data : as required by law (10 years for accounting records)

Data transfers

Your data is hosted within the European Union or Switzerland (Infomaniak, Supabase EU region). No transfers to third countries are made without appropriate safeguards. Data processing agreements (DPAs) are in place with our sub-processors.

Sub-processors involved: Supabase (database and storage), Infomaniak (VPS hosting), Stripe (payment), PostHog (analytics, with consent), OpenRouter (AI processing).

Your rights (GDPR)

Under the GDPR, you have the following rights regarding your data:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to data portability
  • Right to object
  • Right to restriction of processing

To exercise these rights, contact us at hello@autokap.app. In case of unresolved disputes, you may file a complaint with the CNIL.