PRIVACY
Privacy Policy
Effective and last updated: September 9, 2026
This policy explains how the hosted Capsulet service at capsulet.org processes information. The operator of capsulet.org is responsible for that processing. Privacy questions and requests can be sent to accounts@capsulet.org.
Information Capsulet processes
Account and profile information
Capsulet processes your email address, account and verification status, sign-in methods, and account timestamps. Passwords are stored as password hashes, not as plaintext. If you use Google or GitHub to sign in, Capsulet records the provider, its immutable account identifier, and profile attributes the provider supplies, such as email, email-verification status, display name, or GitHub login.
Google and GitHub are used only for authentication and explicit account linking in the current product. Provider access tokens are used temporarily to complete authentication and are not retained by Capsulet.
Google Sign-In and Google user data
Google Sign-In is optional. Capsulet requests only the OpenID Connect scopes openid, email, and profile. Data received from Google may include the immutable Google account subject (sub), email address, email-verification status, and name or other basic profile information available through those scopes.
Capsulet uses this Google user data only for authentication, Capsulet account creation or identification, explicit sign-in-method linking, and basic profile display. Capsulet does not access Gmail, Google Drive, Google Calendar, Google Contacts, or other Google Workspace content. OAuth provider access tokens are temporary during the callback and are not persisted after the callback.
Google user data is not sold, used for advertising, shared with data brokers, used for credit or lending decisions, or used to train generalized artificial-intelligence or machine-learning models.
Processors and sharing
Google provides the identity data during the sign-in flow. Capsulet stores the linked identity data in its PostgreSQL control-plane database on infrastructure provided by OVH, so OVH processes that stored data as the hosting provider. If Capsulet sends an account-related email, the configured transactional email provider may receive the destination email address and message-delivery data. Capsulet does not send the Google OIDC subject, email-verification status, or profile name to Firebase Cloud Messaging. Capsulet does not otherwise share Google user data except when required by law or necessary to protect users and the service.
Storage, protection, retention, and deletion
The immutable Google subject and available email, verification, and display-name attributes are stored with the account or linked sign-in method in PostgreSQL. Public traffic uses TLS; OAuth callbacks validate issuer, audience, signature, expiry, nonce, state, and PKCE; browser sessions are short-lived; and account-scoped authorization limits access. OAuth state is stored as a verifier rather than as its raw value.
Linked Google identity data is retained while the Google sign-in method remains connected and while needed to provide and secure the account. A signed-in user can disconnect Google after adding or retaining another usable sign-in method; this deletes the linked Google identity record from the active database, although account-level information such as the Capsulet account email may remain. Capsulet does not currently provide a self-service full-account deletion workflow. To request deletion of the account and associated Google user data, contact accounts@capsulet.org. Data may remain temporarily in production backups, which are retained for 14 days, or longer where required by law or necessary for legitimate security and integrity records.
Machines, Capsules, Runtimes, and operational information
Capsulet stores the identifiers, names, ownership relationships, placement and lifecycle state needed to connect and operate your Machines, Capsules, and Runtimes. Machine records can include operating system and architecture, software and protocol versions, declared capabilities, public encryption keys, presence and last-seen times, health, power state, and available resource metrics.
For Codex threads, the control plane keeps only a limited operational projection such as an upstream thread identifier, Runtime relationship, attention state, observation source, and timestamps.
Devices, notifications, and Firebase Cloud Messaging
For paired devices, Capsulet processes a device name, platform, status, last-seen time, notification preferences and Capsule subscriptions, and the Firebase Cloud Messaging (FCM) registration token needed to route notifications. It also keeps notification, delivery, and supported interaction metadata, including safe titles, summaries, available choices, state, timestamps, and failure classes. An FCM token routes delivery; it does not authenticate Capsulet API requests.
Notification delivery sends the minimum required message data and FCM registration token to Google Firebase Cloud Messaging. Revoking a Device invalidates its Capsulet access credential; delivery and action authorization are checked separately.
Artifacts
When you explicitly publish an artifact, the control plane stores metadata including its opaque identifier, filename, type, size, SHA-256 digest, source Machine/Capsule/Runtime relationships, status, creation time, and expiry. The immutable file snapshot remains on the source agent and is transferred only for an authenticated download. Capsulet does not provide general workspace upload, browsing, backup, or migration.
Workspace and Codex content boundary
Using Capsulet remote or resume does not upload your Codex workspace contents or transcript to the Capsulet control plane. Prompts, responses, turns, previews, titles, filesystem paths, repository data, diffs, tool calls, command output, approval bodies, and file contents are excluded from the hosted thread projection. Remote Codex traffic is end-to-end encrypted between trusted endpoints; the relay forwards ciphertext.
Data is processed only when required by a supported feature. For example, explicitly publishing an artifact transfers that selected file, and responding to a supported notification processes the safe interaction metadata and selected opaque choice needed for that action.
Credentials and security
Capsulet uses short-lived browser sessions, CSRF protection, scoped account and Machine ownership checks, TLS for public services, and end-to-end Noise encryption for Codex traffic. The server persists verifiers rather than raw values for browser sessions, PAT credentials, Machine credentials, Device credentials, Farm Manager credentials, email verification and password-reset tokens, pairing grants, CLI login grants, and OAuth state. Raw endpoint credentials are returned only when required for initial use and are stored by the relevant client using its protected credential storage; Android uses Keystore-backed encrypted preferences.
No system can be guaranteed completely secure. Keep your connected Machines, devices, email account, and local credential stores protected, and contact us if you believe access has been compromised.
How information is used and shared
Information is used to provide authentication, account recovery, Machine and Device connectivity, routing, notification delivery, artifacts, security enforcement, auditing, troubleshooting, and service operation. Capsulet does not sell personal information and does not use it for advertising.
Information is shared only as needed with infrastructure and delivery providers, including Google or GitHub when you choose their authentication method, Google Firebase Cloud Messaging for push delivery, and the configured transactional email provider for verification and password-reset messages. Those providers process information under their own terms and privacy policies. Information may also be disclosed when required by law or necessary to protect users and the service.
Cookies and tracking
The portal uses only the Secure session and CSRF cookies required for sign-in and request protection. It does not currently use advertising cookies, analytics, or other tracking technology. Because only necessary security cookies are used, the current portal does not display a tracking-consent banner.
Retention and your choices
Short-lived grants and sessions expire according to their purpose. Browser sessions currently expire after 15 minutes; verification and reset links after 30 minutes; CLI authorization and Device pairing grants after 10 minutes; and production route grants no later than one hour. Agent artifact snapshots normally expire after 24 hours. Expired or revoked operational metadata and audit records may remain to preserve security, integrity, and troubleshooting history. The current production backup process retains local database backups for 14 days.
Account and control-plane records are otherwise retained while needed to provide and secure the service. You can revoke Devices and connected sign-in methods through supported controls. To request access, correction, or deletion of account information, contact accounts@capsulet.org. Some records may need to be retained where required by law or for legitimate security and integrity purposes.
Changes and contact
This policy may be updated when the service or its data handling changes. The date above will be revised when that happens. Questions or privacy requests should be sent to accounts@capsulet.org.