Privacy Policy
Last updated: September 2026
This Privacy Policy explains how Social Intents, LLC ("Social Intents", "we", "us") collects, uses, and shares personal data in connection with CapyScout (the "Service"). It covers both people who use the Service (customers) and individuals whose business contact data may be processed through the Service.
1. Data we collect
- Account data: name, work email, password hash, and billing details when you register or subscribe.
- Usage data: log data, device and browser information, API call metadata, and product interactions.
- Input data: email addresses and optional context (domain, source, message) you submit for enrichment.
- Enrichment data: business information we compile from public sources, third-party providers, and automated models about companies and professional contacts.
2. How we use data
- To provide, operate, secure, and improve the Service.
- To generate enrichment results, scores, and recommended actions.
- To bill you, provide support, and communicate about your account.
- To detect abuse, enforce our Terms, and comply with legal obligations.
3. Third-party enrichment sources
To build company and professional-contact enrichment, we obtain data from third-party providers and public sources (see our sub-processors page). The categories of personal data we may process about a professional contact include name, job title, seniority, professional social profiles (such as LinkedIn), business location, employer/company, and - where enabled - a business phone number. Because this data is not always collected directly from the individual, we provide this notice in line with Article 14 of the GDPR. You can ask us to access, correct, delete, or stop processing this data at any time using our data request form.
4. Google user data and Limited Use
Connecting a Google account is optional. If you connect Google Calendar, CapyScout requests read-only scopes only (calendar.events.readonly and calendar.calendarlist.readonly, plus openid and email to label the connection). CapyScout never creates, edits, or deletes anything on your calendar.
- What we access: for upcoming events on the calendars you select, the event title, start time, organizer, and attendee email addresses and display names. Events with no attendees from outside your own company are ignored, as are personal mailbox domains such as gmail.com.
- What we use it for: a single purpose, which is producing the pre-meeting brief you asked for. We derive the outside company's domain from attendee addresses, research that company from public and third-party business sources, and assemble the brief.
- What we store: the event id, title, start time, attendee list, and the generated brief, so you can re-read it in the app. OAuth tokens are encrypted at rest.
- What we share: we do not sell Google user data or share it for advertising. Limited meeting context is sent to our AI sub-processor as described below.
- Deletion: disconnecting the calendar in Settings revokes and deletes the stored tokens. You can delete stored briefs, or request full deletion through our data request form.
CapyScout's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
5. AI and machine learning
CapyScout uses third-party large language models to write briefs and summaries. When you request a pre-meeting brief, we send the model a limited prompt containing the meeting title, the outside attendees, and the business facts we compiled about their company.
We do not use, transfer, or sell Google user data, whether raw, aggregated, or derived, to develop, train, test, or improve foundational or generalized artificial intelligence or machine learning models. Data from Google Workspace APIs is transferred to our AI sub-processor solely to provide the user-facing feature you requested, under contractual terms that prohibit the sub-processor from using it to train or improve its models. We do not use Google user data to train any model of our own, and we do not retain it for any purpose beyond the ones described in this Policy.
6. Cookies
We use strictly necessary cookies to operate the Service (for example, to keep you signed in). With your consent, we may use optional cookies to understand product usage. You can accept or reject optional cookies via the banner shown on your first visit, and change your mind by clearing your browser storage for this site.
7. Legal bases
Where required, we process personal data based on your consent, our contract with you, our legitimate interests in operating and improving a business-to-business service, and compliance with legal obligations. Enrichment of professional contact data relies on legitimate interests balanced against the rights of the individuals concerned.
8. Sharing
We share data with service providers (for example, hosting, data enrichment, payment processing, and analytics) under contract, and with authorities where legally required. We do not sell personal data. Enrichment providers are used to compile business information and are bound by their own terms.
9. Retention
We retain account data for as long as your account is active and as needed to comply with legal obligations. Enrichment results are cached to avoid duplicate processing and refreshed or deleted according to internal retention windows. You may request deletion as described below.
10. Security
We use administrative, technical, and organizational measures to protect data, including hashing of secrets and API keys, encryption in transit, and access controls. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing or request portability. Individuals in the EU, UK, and similar jurisdictions can find more detail on our GDPR page. To exercise any of these rights - including opting out of enrichment processing - use our data request form. We may need to verify your identity before completing certain requests, and we aim to respond within 30 days.
12. International transfers
We may process data in the United States and other countries. Where required, we use appropriate safeguards such as standard contractual clauses (and, where applicable, the EU-US Data Privacy Framework) for cross-border transfers.
13. Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect data from children.
14. Changes and contact
We may update this Policy from time to time; the "last updated" date reflects the latest revision. For privacy questions or requests, use our data request form or contact Social Intents, LLC via socialintents.com.