Privacy Policy
Last updated 2026-10-04
Who is responsible
Caprail is operated by MAXIMILIAN LEODOLTER, Franz-Maier-Gasse 39/2/12, 2544 Leobersdorf, Österreich. Contact support@tallyman.io for privacy requests. We are responsible for account administration, support, and the operation of our own website. When a customer sends analytics from their website, that customer determines the purpose of collecting its visitors’ data and the applicable legal basis; Caprail processes that analytics to provide the service. Visitors may also contact the operator of the website they visited.
Data we process
Account data includes your name, email address, profile image where provided, sign-in provider identifiers, authentication credentials or tokens needed for sign-in and connected-agent access, sessions, and terms acceptance. You sign in through GitHub, Google, or supported account authentication using Better Auth, hosted with our application and database. Authentication information must be entered through the sign-in flow, never sent in chat or support emails.
Site data includes the names and domains of connected sites, their ownership, and their ingest keys. Analytics events can include timestamps, request method, pathname, IP address, user agent, approximate country, referrer host, campaign labels and advertising click identifiers, response information, and derived traffic classifications. We remove query strings and fragments from stored pathnames and store referrers as hosts. Paths and campaign values can still contain personal information; site operators must avoid sending it.
Visitor estimates use identifiers derived from IP addresses and user agents. These identifiers are pseudonymous, not anonymous. Caprail’s event collection does not require an analytics cookie, but account sign-in uses session cookies. Server-side collection does not remove a site operator’s privacy or consent obligations.
Support messages contain the information you send us. Hosting and authentication may also generate technical and security logs, including IP addresses, user agents, and error information.
Why we use data
We use account and site information to provide and administer the service, authenticate access, answer your requests, and support your account. For account holders, this processing is necessary to provide the service under our agreement with you. We use proportionate technical data for security, abuse prevention, and troubleshooting based on our legitimate interest in operating a reliable service. Where processing is required by law, we rely on that legal obligation.
Customer analytics is used to produce the reports requested by the site owner. The site owner is responsible for selecting a lawful basis and giving visitors the necessary information. Providing a site integration does not itself establish consent from that site’s visitors.
We plan to use only anonymous aggregate statistics for product improvement, marketing research, and internal AI training. Raw visitor data and account data will not be used for those purposes or sent to external AI providers for training. Hashing an identifier alone does not make it anonymous. These planned uses do not authorize additional personal-data collection.
Providers and connected agents
Vercel hosts the application and handles application requests and operational logs. Neon stores account, authentication, site, and analytics data. Better Auth is the authentication software running within this infrastructure; GitHub or Google processes sign-in when you choose that provider.
Plunk and Proton provide email delivery and correspondence services. Telegram receives operational signup and onboarding notifications containing the account holder’s name, email address, onboarding status, and account-count information. These notifications go to the operator’s configured Telegram chat.
When you authorize a connection to ChatGPT or another agent, Caprail receives the tool requests needed to answer you and returns the requested analytics and site information to that provider. If you create a site through an agent, its setup result can include that site’s ingest key. Do not publish or share that result. The agent provider handles the conversation under its own terms and privacy settings.
Data may also be disclosed where required by law or necessary to handle a legal claim.
International processing
Our current Neon database project is located in the United States. Other providers may also process data outside Austria or the European Economic Area. Provider data-processing terms describe the safeguards available for international transfers, including standard contractual clauses where applicable. Contact support@tallyman.io for information about the arrangements applicable to your data.
Retention and deletion
Analytics events are retained for 90 days, unless you delete the site sooner. Expired events are removed by daily cleanup, normally within 24 hours after expiry. The cleanup also removes expired historical analytics events and stored visitor traits.
Deleting a site from the dashboard removes the site and its associated analytics from the active database. Account information is retained while your account is active; contact support@tallyman.io to request account deletion. We may verify your identity before handling the request. Records that must be retained for a legal obligation or claim are limited to that purpose and retained for as long as necessary.
The current Neon point-in-time recovery history is configured for six hours. Deleted database records may remain recoverable during that window. Restored data must have deletion requests and event expiry reapplied before it is used in the service. This recovery window is separate from the retention of provider security logs or email correspondence.
Support correspondence is retained while handling the request and as needed for related follow-up or a legal claim. Operational logs and notifications are retained only as needed for security, troubleshooting, and administration, subject to the providers’ retention settings. Anonymous aggregate statistics that no longer identify a person may be retained separately.
Your choices and rights
You can stop sending analytics, delete a site from the dashboard, and disconnect Caprail in your agent provider’s settings. Disconnecting a plugin does not delete your Caprail account or previously recorded events. Site operators control the collector installed on their own sites.
Where applicable, you may request access, correction, deletion, restriction, or portability of your personal data and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting processing that occurred before withdrawal. Contact support@tallyman.io. You may complain to your local data-protection authority, including the Austrian Datenschutzbehörde at dsb.gv.at.
Changes
We will update this page when our data practices change. New personal-data uses will require an appropriate legal basis and any required notice or consent before they begin.