Capsule.Video, Inc. (“Capsule,” “we,” “us,” or “our”) provides an AI-enabled video creation, editing, collaboration, rendering, management, and delivery platform. This Privacy Policy explains how we collect, use, disclose, store, and retain personal information when you visit a Capsule website, use Capsule Studio or another Capsule service, communicate with us, or connect Capsule to an AI assistant or other integration (collectively, the “Services”).
This Privacy Policy does not replace a customer’s agreement or Data Processing Agreement (“DPA”) with Capsule. If those terms conflict with this Privacy Policy regarding personal information that Capsule processes for a customer, the agreement and DPA control.
1Capsule’s role
Capsule processes personal information in two different roles:
- As a processor or service provider. A customer controls the purposes for which Capsule processes personal information contained in the customer’s workspace, projects, media, transcripts, prompts, design systems, and other customer-provided content (“Customer Content”). Capsule processes that information to provide the Services and on the customer’s documented instructions, except where law requires otherwise.
- As a controller or business. Capsule determines how it processes limited information used to operate its websites and business, administer accounts, manage customer and prospect relationships, provide support, secure and improve the Services, process billing, and comply with law.
If your information was submitted to Capsule by one of our customers, please contact that customer first about a privacy request. We will assist the customer as required by our DPA and applicable law. You may also contact us at legal@capsule.video if you need help identifying the relevant customer.
2Personal information we collect
The information we process depends on how you use the Services, which features and integrations are enabled, and what information a customer or user chooses to submit.
| Category | Examples | Why we process it |
|---|---|---|
| Account and workspace information | Name, business email, organization and workspace identifiers, profile details, roles, permissions, and authentication or SSO identifiers | Create and administer accounts; authenticate and authorize users; manage organizations, roles, and permissions; provide support; send service notices; and protect the Services |
| Customer Content | Uploaded video, audio, images, text, scripts, prompts, testimonials, media URLs, and other content, including faces, voices, names, contact details, or other personal information a customer includes | Ingest, store, organize, edit, transcribe, transform, render, export, deliver, and share content as directed by the customer |
| Project and configuration information | Project names and state, timelines, edits and instructions, captions, comments, templates, design systems, brand assets and selections, sharing settings, API or webhook configuration, and integration identifiers | Preserve project state; support collaboration and brand consistency; apply instructions; manage sharing, automation, and integrations |
| Derived content and outputs | Transcripts, captions, word timings, thumbnails, previews, processed audio, edited or generated media, rendered videos, copy suggestions, and soundtrack recommendations | Provide editing, transcription, accessibility, generation, preview, rendering, export, and delivery functions requested by the user |
| Technical, security, and usage information | IP address, browser, device and operating-system details, general location derived from IP address, session and authentication events, request data, error and performance logs, and feature-use analytics | Operate and secure the Services; prevent and investigate misuse; troubleshoot errors; maintain availability and performance; understand adoption; and improve the Services |
| Support and business communications | Support requests, messages, attachments, feedback, meeting information, and related correspondence | Respond to requests; troubleshoot issues; manage customer relationships; and improve the Services |
| Contract, subscription, and billing information | Business contact details, plan and account status, billing address, invoices, and transaction metadata | Administer contracts and subscriptions; process billing; maintain business records; and satisfy tax, audit, legal, and compliance requirements. Payment-card details are processed by our payment provider rather than stored in Capsule Studio. |
| Website and marketing information | Pages viewed, referring pages, links clicked, form submissions, cookie or similar identifiers, and marketing preferences | Operate and analyze our public websites; respond to inquiries; measure campaigns; and communicate about Capsule, subject to your choices and applicable law |
We may receive this information directly from you, from the customer or organization that provides your access, automatically from your browser or device, from service providers, or from integrations that you or your organization enable.
3AI assistant connectors
This section applies when a user connects Capsule to an AI assistant, such as Claude, through Capsule’s Model Context Protocol (MCP) server or another connector.
Authorization and Capsule account access
The connector uses OAuth to access the user’s Capsule account on the user’s behalf and within the permissions granted. Depending on the requested tool and the user’s Capsule permissions, the connector may access or modify:
- projects and project state;
- uploaded, linked, generated, or rendered media;
- scripts, transcripts, captions, and word timings;
- organization, workspace, role, permission, and collaboration information;
- design systems, templates, and brand assets; and
- other data needed to carry out the user’s requested Capsule action.
The connector cannot grant a user broader access than the user has in Capsule.
Information sent in both directions
- From the assistant to Capsule. Instructions that a user gives the assistant may become tool inputs sent to Capsule. These inputs can include project identifiers, scripts, prompts, media URLs, edit instructions, and other parameters needed to perform the requested action.
- From Capsule to the assistant. Capsule returns requested tool results to the assistant provider. Results may include project information, transcripts, captions, media links, status information, generated or edited content, and other requested outputs. The assistant provider processes that information under its own agreement and privacy policy.
Capsule does not collect an assistant conversation beyond the information the assistant sends to a Capsule tool as inputs needed for that tool. The connector does not independently query or extract the assistant’s memory, chat history, conversation summaries, or user-uploaded files. If a user expressly includes content or a file reference in a tool input, Capsule processes only the input needed to perform the tool’s function. Capsule does not build a separate copy of the user’s assistant conversation history.
The connector may store limited account-linked widget or interface state, such as draft fields, workflow progress, and user selections. This allows an interactive Capsule experience to be restored when a user returns to or resumes an earlier assistant conversation. Because users may return to prior conversations, this state is not limited to the active session and may be retained for as long as it remains reasonably useful to restore or support the user’s prior interactive experience, and as otherwise needed for security, legal, or contractual purposes. This state is associated with the user’s account and may be deleted as part of deleting the associated account data. It is not intended to serve as a separate copy of Capsule project or media content.
OAuth credentials used by the connector include access tokens that expire after one hour and single-use, rotating refresh tokens that expire after 30 days. Refresh tokens are retained in Capsule’s token store until they are used or expire. Disconnecting through the assistant causes the assistant to discard its connection credentials and stops ordinary future connector use. Capsule-issued credentials may remain technically valid until they expire unless invalidated earlier.
The Capsule connector does not insert third-party advertisements, sponsored content, or paid product placements into tool results.
4How we use personal information
We use personal information to:
- provide, maintain, support, personalize, and secure the Services;
- authenticate users and manage accounts, organizations, workspaces, access, and integrations;
- receive, store, organize, transcribe, edit, generate, render, export, and deliver content as requested;
- process connector tool inputs and return results to the user’s selected assistant provider;
- communicate about accounts, service changes, support, security, and administrative matters;
- monitor performance, investigate errors, prevent fraud and abuse, and respond to security incidents;
- understand use of the Services, conduct de-identified quality assurance, evaluate features, and improve the Services;
- administer contracts, subscriptions, billing, and customer relationships;
- send marketing communications where permitted, subject to opt-out rights; and
- comply with law, enforce our agreements, resolve disputes, and protect Capsule, our customers, users, and others.
Where EEA, UK, or similar law applies to processing for which Capsule is the controller, we rely on one or more of the following legal bases: performance of a contract, our legitimate interests in operating and securing the Services and business, consent where required, and compliance with legal obligations. You may contact us for more information about the legal basis that applies to a particular activity.
5AI-enabled features
Certain optional features use machine-learning or artificial-intelligence providers to perform a customer-requested function. Depending on the feature, inputs may include selected audio, video, images, transcripts, prompts, project context, and instructions. Outputs may include transcripts and word timings, generated images or video, synthetic voice or processed audio, copy suggestions, and soundtrack recommendations.
Capsule uses Customer Content to provide and support the Services and does not use Customer Content to train foundation models. Capsule enables zero-retention or no-training settings with AI providers where those controls are available. Capsule’s AI features are not used to infer protected attributes or perform unconsented biometric identification.
Information that a user directs Capsule to return to an independent AI assistant provider is processed by that provider under the provider’s terms, privacy policy, plan, and user settings. Users and customer administrators should review those settings before enabling a connector.
6How we disclose personal information
We disclose personal information only as described below and as permitted by applicable law:
- At the customer or user’s direction. We disclose information to authorized users, collaborators, publishing or sharing destinations, integrations, AI assistant providers, and other recipients selected by the customer or user.
- To service providers and subprocessors. Providers support hosting, storage, databases, authentication, content delivery, rendering, media processing, AI features, observability, security, analytics, customer support, billing, and business administration. They receive only information reasonably necessary for their function and are subject to contractual confidentiality, security, and data-protection obligations where applicable.
- For legal, safety, and security reasons. We may disclose information if reasonably necessary to comply with law or valid legal process; protect a person’s safety; prevent or investigate fraud, abuse, or security incidents; or protect Capsule’s, our customers’, or others’ rights and property. Where permitted, Capsule seeks to direct government requests for Customer Content to the customer and does not voluntarily disclose Customer Content to law enforcement.
- For a corporate transaction. Information may be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate protections.
- With professional advisers and affiliates. We may disclose information to auditors, legal counsel, insurers, accountants, and affiliated entities that need it to provide services or support our business.
- With consent. We may disclose information for another purpose when the relevant person or customer consents or directs us to do so.
Capsule does not sell Customer Content. Capsule does not sell or share Customer Personal Information processed on behalf of a customer for purposes outside the limited purposes in the customer agreement and DPA, except as otherwise permitted by applicable law.
Our public marketing websites may use analytics or advertising cookies and pixels. Disclosure of identifiers or internet activity through those technologies may be considered “sharing” for cross-context behavioral advertising under some U.S. state privacy laws, even when no money is exchanged. Section 10 explains how to exercise applicable opt-out rights. Capsule does not use Customer Content for advertising.
7Service providers and other third parties
The providers involved depend on the features a customer uses, and a provider does not receive every category of information listed in this Policy. Capsule uses service providers and subprocessors in the following categories:
- application and cloud hosting, databases, media storage, rendering, and content delivery;
- authentication, identity management, and enterprise access;
- security, error reporting, observability, service quality, and product analytics;
- customer support, customer relationship management, billing, payment processing, and business administration;
- website analytics and advertising measurement; and
- transcription, AI-enabled features, media generation and processing, voice, audio processing, and soundtrack services.
These providers process information only as needed to perform services for Capsule and are subject to contractual confidentiality, security, and data-protection obligations where applicable. Capsule’s contracts and DPA govern subprocessor processing on Capsule’s behalf. Where our DPA applies, Capsule makes information about its current subprocessors and notice of new subprocessors available to customers as described in the DPA.
Third parties selected or enabled by a customer or user, including an AI assistant provider, receive information at the customer’s or user’s direction. Their own terms and privacy policies apply to their processing. For example, when a user connects Capsule to Claude, Anthropic receives the Capsule tool inputs and results described in Section 3; users should review Anthropic’s Privacy Policy.
8Storage, location, retention, and deletion
Storage and location
Capsule’s primary application, media, database, and processing infrastructure is hosted in the United States. Uploaded and generated media is stored in managed cloud media storage, and application, project, metadata, and transcript data is stored in Capsule’s managed application databases and processing systems. Video rendering also uses managed U.S.-based render infrastructure. Some edge delivery, network, support, or provider-managed processing may occur in other countries.
Where required, Capsule uses safeguards for international transfers, including the European Commission’s Standard Contractual Clauses and the UK Addendum or International Data Transfer Agreement.
Retention periods and criteria
| Data type | Retention |
|---|---|
| Customer Content, including uploaded media, project data, transcripts, and generated or derived content | Generally remains available in the customer’s workspace during the active service term unless the customer deletes it or requests deletion. Following termination, Capsule returns or deletes Customer Personal Data at the customer’s choice as provided by the DPA. Unless a different contract, instruction, or legal requirement applies, Customer Personal Data in the product may be retained for up to three months after contract termination to complete offboarding and deletion. |
| Database backups | May be retained for up to one year after contract termination. Backup data is protected and isolated from routine processing and is deleted through the applicable backup lifecycle unless retention is legally required. |
| Trial customer data | Deleted within one month after the trial ends, unless the account converts to a paid service or another lawful basis requires retention. |
| Connector tool inputs and results | Capsule may record tool inputs, tool results, and related operational metadata in logs as needed to provide, secure, monitor, and troubleshoot connector tools. The same information may also be stored separately as Customer Content or project or account data when required to perform the user’s requested Capsule action. Capsule does not retain a separate copy of the user’s broader assistant conversation history. |
| Connector widget or interface state | Limited account-linked interface state, such as draft fields, workflow progress, and user selections, may be retained for as long as it remains reasonably useful to restore or support the user’s prior interactive experience, including after the active session ends, and as otherwise needed for security, legal, or contractual purposes. The state is associated with the user’s account and may be deleted as part of deleting the associated account data. |
| OAuth tokens | Connector access tokens expire after one hour. Single-use, rotating refresh tokens are retained in Capsule’s token store until used or until they expire after 30 days. After disconnection, credentials may remain technically valid until they expire unless invalidated earlier. |
| Security, error, request, and performance logs | Retained for periods reasonably necessary for security, incident investigation, troubleshooting, availability, audit, and legal obligations, then deleted or de-identified under Capsule’s retention schedule. Capsule does not intentionally log extraneous AI assistant conversation data. |
| Account, contract, billing, support, and business records | Retained for the customer relationship and afterward as reasonably necessary for account closure, audit, tax, legal, dispute, security, and compliance purposes. |
| Website cookies and similar identifiers | Retention varies by technology and purpose. Some analytics, advertising, form, or scheduling identifiers expire after a session or a provider-configured period; others may persist for months or up to two years. Some identifiers stored in browser local storage do not expire automatically and remain until they are replaced or cleared. |
Capsule securely deletes or de-identifies information when it is no longer required. Deletion from active systems does not always remove protected backup copies immediately; backups age out under the backup lifecycle. Capsule and its subprocessors may retain limited information when required by law, to establish or defend legal claims, or to maintain a record of a privacy choice such as a marketing opt-out.
9Security
Capsule maintains administrative, technical, and physical safeguards designed to protect personal information. These measures include encryption in transit and at rest, identity and access controls, multi-factor authentication, least-privilege access, logging and monitoring, environment and network protections, backup and recovery processes, vulnerability management, incident response, vendor risk management, and personnel confidentiality and security obligations.
No system is completely secure. If you believe you have found a security vulnerability, contact security@capsule.video. Do not include sensitive Customer Content in an initial vulnerability report.
10Your privacy rights and choices
Depending on where you live and the circumstances, you may have the right to:
- know whether Capsule processes your personal information and obtain information about the categories, sources, purposes, and recipients;
- access or receive a portable copy of your personal information;
- correct inaccurate personal information;
- delete personal information;
- restrict or object to certain processing;
- withdraw consent where processing relies on consent;
- opt out of targeted advertising, sale, or sharing as those terms are defined by applicable law;
- appeal Capsule’s denial of a request where applicable; and
- lodge a complaint with a data protection authority.
To exercise a right, email legal@capsule.video. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising a privacy right.
If Capsule processes information on behalf of a customer, we may direct the request to that customer and assist it as required. Customer administrators and authorized users can also delete content through available Capsule controls or request assistance from Capsule support.
Marketing and cookies
Capsule’s public websites may use analytics, advertising, customer-relationship, form, scheduling, and content-delivery technologies. Depending on the page and technology, providers may receive browser or device information, IP address, page URLs and titles, visitor or advertising identifiers, and information about page interactions. Information entered into a marketing, registration, or scheduling form may be processed by the provider that hosts or supports the form, including as the visitor interacts with it.
You can use your browser settings or extensions to block or clear cookies and similar browser storage. Blocking these technologies may affect site functionality. Depending on where you live, you may also contact legal@capsule.video to exercise an applicable right to opt out of sale, sharing, or targeted advertising. You may unsubscribe from marketing emails using the link in the message or by contacting that address.
Disconnecting an AI assistant connector
You can disconnect Capsule from the AI assistant’s connector or integration settings. Disconnecting causes the assistant to discard its connection credentials and stops ordinary future connector use. Capsule access tokens expire after one hour and single-use, rotating refresh tokens expire after 30 days; credentials may remain technically valid until they expire unless invalidated earlier. Disconnection does not automatically delete:
- content already stored in your Capsule account;
- information already returned to the assistant provider; or
- information the assistant provider retains under its own agreement and privacy policy.
You can delete Capsule content through the Services or request assistance. An authorized customer administrator may request account or workspace deletion, subject to the customer agreement, legal requirements, and the retention periods above.
11U.S. state privacy disclosures
In the preceding 12 months, Capsule may have collected the categories described in Section 2, including identifiers, customer records information, commercial information, internet or network activity, general geolocation derived from IP address, audio or visual information, professional information, and inferences or derived outputs created to provide requested features. Capsule collects those categories from the sources described in Section 2, uses them for the purposes described in Sections 3 through 5, and discloses them to the recipient categories described in Sections 6 and 7.
Capsule does not sell personal information for money. As explained in Section 6, marketing-site cookies or pixels may constitute a sale or sharing under certain state laws. Capsule does not knowingly sell or share the personal information of people under 18. Capsule does not use or disclose sensitive personal information to infer characteristics about individuals. Capsule does not offer financial incentives in exchange for personal information.
12Sensitive data, health data, and children
Capsule’s standard Services and connector are not designed or intended for protected health information, regulated health data, or other sensitive or special-category personal information. Capsule’s standard DPA prohibits customers from submitting sensitive or special-category personal data. Do not submit that data to Capsule or through a connector unless Capsule has expressly agreed in writing to the specific use case and required safeguards.
The Services are intended for business users who are at least 18 years old. Capsule does not knowingly collect personal information from children. If you believe a child has provided personal information to Capsule, contact legal@capsule.video.
13Changes to this Policy
We may update this Privacy Policy as our Services, providers, and legal obligations change. We will post the updated Policy at this URL and revise the effective date. If a change materially affects how we process personal information, we will provide additional notice where required by law or contract.
14Contact us
For privacy questions, requests, or complaints:
Capsule.Video, Inc.6815 Biscayne Blvd
Suite 103 #218
Miami, FL 33138-6292
legal@capsule.video
For product or connector support: hi@capsule.video
For security vulnerability reports: security@capsule.video