Privacy Policy

Last updated: 30 August 2026

CAPS (Collaborative AI-assisted Preparation System) is an AMC study copilot operated by an independent developer based in Pakistan. This policy explains what we collect via the web app and Chrome Extension, how we use it, and who we share it with. It is governed primarily by the laws of Pakistan; mandatory privacy or consumer laws of your country or state may also apply (for example GDPR or CCPA/CPRA where relevant). Related rules of use are in our Terms of Service.

Who we are and who the Service is for

Contact: tmk@capsapp.xyz. You must be 18 or older. We do not knowingly collect data from children under 18. CAPS is available internationally; the operator is based in Pakistan; core databases are in Australia.

What we collect

Account: email, full name, Auth credentials (handled by Supabase Auth).

Profile / onboarding: exam stage, study focus, time until exam, study hours, MCQ platforms, referral source, streak fields.

Subscription: plan (free, beta, standard, premium), status, trial/subscription dates, Creem customer and subscription ids. Card details are processed by Creem (Merchant of Record), not stored by CAPS.

Extension context: selected text; truncated page text (up to 16,000 characters on queries; chips use up to 2,000 selection / 4,000 page text); page URL; local capture time. No screenshots, raw HTML dumps, or third-party site cookies/passwords.

Opening Ask CAPS after a highlight, or enabling Context / chips, is treated as consent to send that excerpt to our servers and AI processors.

AI sessions: queries, page context, responses (headline in database; full JSON in object storage), summaries, ratings, in-app feedback.

Notes / canvas: titles, taxonomy, markdown, text / image / drawing blocks and connections. Images up to 5 MB.

Usage: analytics events (no prompt/page content in PostHog by design). Web app may identify with email and plan fields; Extension identifies by user id only (no session replay). Sentry for errors. Transactional email via Resend (welcome, daily limit, feedback status).

How we use it (including automated AI)

We use data to run CAPS (auth, AI, notes, billing sync), send transactional email, secure the Service, and analyse product usage. We do not sell personal information.

Automated systems generate explanations, chips, and summaries from your query and any page context, route models, queue rate-limited requests, and apply plan-based daily caps. Outputs are study aids—not medical advice, not AMC results, and not decisions about your legal rights. Verify important clinical facts yourself.

Where we store it and how long

Supabase Auth/database: Australia (ap-southeast-2). Notes, response files, and canvas assets: Cloudflare R2 in Asia-Pacific (APAC). PostHog: EU. Hosting: Vercel. Groq may retain limited data in the US when retention applies under their terms.

Account and study data: kept while the account is active. In-app deletion ends access immediately and retains data for 30 days so you can restore by signing in with the same email (reminder around day 3); then we permanently delete it, except legal/payment records. Data export is by email to tmk@capsapp.xyz within 30 days. Query queue: results cleared after 24 hours; finished rows after 7 days.

Third-party services

  • Supabase — authentication and database
  • Google Gemini — primary AI explanations (server-side only)
  • Groq — chips, prep, and summaries (server-side only)
  • PostHog (EU) — product analytics; Extension uses user id only
  • Sentry — error monitoring
  • Creem — subscription payments (Merchant of Record)
  • Resend — transactional email
  • Cloudflare R2 — file storage (APAC)
  • Vercel — application hosting

AI and payment keys never ship in the browser or Extension. Sensitive calls go through capsapp.xyz API routes (or Edge Functions for email).

Gemini and Groq data use

Free, beta, and trial traffic uses our unpaid Gemini API tier. Under Google’s current unpaid Gemini API terms, Google may use submitted prompts, page context, and responses to improve Google products and machine learning technologies.

Paid standard / premium traffic uses our paid Gemini API tier. Under Google’s current Paid Services terms, Google does not use your prompts or responses to improve its products (limited abuse/safety logging may still apply).

CAPS does not train its own models on your content. Groq’s current terms do not allow training on inputs/outputs without explicit permission; we do not grant that permission.

Chrome Extension

Permissions: storage; side panel; alarms; HTTPS site access to read selection/page excerpts you initiate and to talk to capsapp.xyz.

Limited Use: CAPS’s use of Extension user data adheres to the Chrome Web Store User Data Policy, including Limited Use. Page content and selections are used only for prominent user-facing study features you start; not sold; not used for unrelated advertising; transferred to Gemini/Groq only via our servers to generate those features.

Your rights

All users may request access, correction, and deletion, and may stop sending page context by not using Ask CAPS / Context or by uninstalling the Extension. Email tmk@capsapp.xyz. Delete your account in Profile (30-day restore window, then permanent delete). For a copy of your data, email us; we fulfil exports within 30 days.

Where GDPR (or UK GDPR) applies, you may also have portability, restriction, and objection rights, and the right to complain to a supervisory authority. Where CCPA/CPRA applies, you may request to know, delete, and correct personal information. We do not sell personal information.

Do not enter real patient-identifiable information. If you are unsatisfied with our privacy response, you may contact a competent authority in Pakistan or in your country or state of residence where one has jurisdiction. This Policy is governed primarily by the laws of Pakistan; mandatory local privacy laws may also apply.

Security and changes

We use HTTPS, Supabase Auth, row-level security, and server-side-only AI/payment integrations. No system is perfectly secure.

We may update this policy and will change the “Last updated” date. For material changes we will take reasonable steps to notify you.

Contact

Privacy requests: tmk@capsapp.xyz