← Back to Kapow

Kapow Privacy Policy

Last updated: August 20, 2026

This Privacy Policy explains how Sagi Yaacoby, operating as Kapow (“Kapow,” “we,” “us,” or “our”), processes personal information through gokapow.com, Kapow accounts, subscriptions, license services, support channels, hosted features, and the Kapow desktop application.

Kapow is designed to keep core project and agent data on your device. That does not mean no data leaves your device: account, billing, license, support, consented analytics, hosted-feature, integration, and third-party AI data flows are described below.

Kapow legal documents Terms of Use & Proprietary License Privacy Policy

Contents

  1. Scope and roles
  2. Information processed
  3. Local and third-party data
  4. How information is used
  5. Cookies and analytics
  6. Service providers and disclosure
  7. Legal bases
  8. Retention
  9. Security
  10. International transfers
  11. Your rights and choices
  12. Children
  13. Changes and contact

1. Scope and Roles

This policy applies when Kapow determines how and why personal information is processed. If an organization provides you access to Kapow, that organization may separately control information about its users, workspaces, permissions, and connected services. Contact that organization about its practices.

Third-party AI providers and integrations process information under their own terms and privacy policies when you choose to use them. Kapow does not control those independent data practices.

2. Information We Process

2.1 Website and Network Information

When you visit gokapow.com, hosting and security systems may process IP address, request time, requested URL, referrer, browser and device information, approximate location derived from IP, response status, and security or diagnostic data. Consent choices are stored in your browser.

2.2 Account and Workspace Information

When you create or use an account, Kapow may process:

  • email address, display name, avatar, account identifier, and authentication-provider metadata;
  • sign-in and account timestamps, account status, system role, and security events;
  • workspace or tenant name, membership, role, invitations, settings, and plan; and
  • communications and preferences associated with the account.

Authentication is provided through Supabase and may use Google, Microsoft, or GitHub sign-in when selected by you. Those providers also process information under their own policies.

2.3 Subscription and Billing Information

Kapow may process plan, billing interval, subscription status, trial and renewal dates, cancellation status, Stripe customer and subscription identifiers, and transaction-related records. Stripe processes payment-card details. Kapow does not receive or store your complete payment-card number.

2.4 License and Entitlement Information

Kapow processes account identifiers, plan and entitlement information, a display prefix for an active license key, a one-way hash of the license key, creation and revocation status, and last-use time. A newly generated raw key is returned once; the stored database value is a SHA-256 hash rather than the reusable raw key.

2.5 Support, Feedback, and Requests

Kapow processes information you submit through support emails, feature requests, comments, bug reports, security reports, and other communications, including attachments and diagnostic details you choose to provide. Do not include credentials or unnecessary sensitive information.

3. Kapow Desktop Application

3.1 Information Stored on Your Device

Kapow is designed so core operational data can remain on your device. Depending on the features you use, local data may include projects, tasks, prompts, messages, outputs, files, tables, workflows, agent and team configurations, memories, knowledge content, settings, logs, diagnostic state, model configuration, browser profiles and cookies, integration configuration, and owner-profile information. Kapow does not automatically receive that content merely because it exists in the application.

The desktop application also stores local account and authentication state needed to keep you signed in and check your plan. This may include account identifiers, email address, access and refresh tokens, expiration information, and plan status. Protect access to your operating-system account and device.

3.2 Credentials and Secrets

Supported API keys and service credentials placed in the Kapow secrets vault are encrypted at rest in a local file using AES-256-GCM with a key derived from the vault password. When the vault is unlocked or you authorize an agent, provider, or integration to use a credential, the required value may be held in memory and supplied to the relevant local process or external service. Other authentication state, including provider CLI sessions, browser cookies, and Kapow account tokens, may be stored separately from the encrypted vault.

3.3 Information Sent from the Desktop Application

Data may leave your device when you:

  • authenticate, manage an account, purchase a plan, or validate a license;
  • submit support, feedback, feature-request, or security information;
  • use a hosted Kapow feature;
  • configure or approve an agent, plugin, browser, API, repository, email, or other integration that sends data elsewhere; or
  • send prompts, instructions, files, project or task context, outputs, or technical metadata to a third-party AI provider.

When you use a Claude, Codex, API-key, or other external-provider connection, the selected provider receives the information required to perform the request under the provider account and settings you use. Kapow provides the local environment and orchestration; the provider independently determines how it processes information under its own terms and privacy policy. Review provider retention, model-training, and data-control settings before sending sensitive information.

3.4 Local Models, Browsers, Updates, and Downloads

When you select a local model, inference requests are sent to the configured local model runtime, which normally runs on your device. Installing or updating local models, the application, browser components, voice components, or other optional components may contact GitHub, Hugging Face, Lemonade, NVIDIA, npm, or another source identified by the installer or feature. Those sources receive standard network request information.

Browser and integration features contact the websites and services you select and may maintain local browser profiles, cookies, or authenticated sessions. The Mind Map feature may retrieve its D3 software dependency from jsDelivr when used. Plugins, skills, and user-configured services may introduce additional destinations. Review agent plans, integration permissions, destination services, and network activity; Kapow cannot list every third-party destination you choose to configure.

4. How We Use Information

Kapow uses information to provide and secure accounts and the Service; authenticate users; manage workspaces, plans, subscriptions, billing, and licenses; provide support; diagnose failures; prevent fraud and abuse; understand consented website usage; communicate service and legal notices; enforce agreements; comply with law; and establish, exercise, or defend legal claims.

Kapow does not sell personal information. Kapow does not use your private local project content to train AI models. Third-party AI providers may process data under their own policies based on the account and settings you use.

5. Cookies, Local Storage, and Website Analytics

Kapow uses browser storage necessary to remember your cookie choice and may use storage required for authentication and security. Optional analytics load only after you select “Accept” in the cookie banner. Selecting “Decline” prevents the Kapow analytics loader from loading Google Analytics and Microsoft Clarity. You can reopen cookie preferences from the cookie icon.

ServiceData and purposeRetention information
Google Analytics 4Page views, sessions, approximate country, device/browser, referral source, and interaction measurements for website analytics. Advertising storage and personalization are signaled as denied by Kapow’s loader.User-level and event-level retention is controlled by the property setting; Kapow’s current disclosed configuration is 14 months.
Microsoft ClarityPage structure and user interactions such as clicks, scrolling, navigation, device information, and session reconstruction for usability analysis. Form and sensitive-content masking depends on Clarity and site configuration.Playback data is retained for 30 days. Click and heatmap data, labeled sessions, and favorite sessions may be retained for 9 months under Microsoft’s current service rules.

See Google Analytics privacy information and Microsoft Clarity privacy information. Browser settings and provider opt-out tools may offer additional controls.

6. Service Providers and Other Disclosures

Kapow uses service providers for the services it operates, and the desktop application may contact third-party providers or download sources when you use the relevant feature. Recipients include:

  • Supabase for authentication, database, and account infrastructure—privacy policy;
  • Stripe for payment and subscription processing—privacy policy;
  • Vercel for website hosting and serverless functions—privacy notice;
  • Google Analytics and Microsoft Clarity for optional consented website analytics;
  • GitHub and component or model sources when the desktop application checks for or downloads an update, model, browser, voice component, runtime, dependency, or other selected component;
  • jsDelivr when the desktop Mind Map retrieves its D3 dependency; and
  • professional advisers, authorities, or counterparties where reasonably necessary for legal compliance, safety, fraud prevention, claims, financing, reorganization, merger, acquisition, or transfer of the relevant business.

When you direct data to an AI or integration provider, that provider receives the data as an independent service selected by you. Review its current terms and privacy policy.

7. Legal Bases for Processing

Where data-protection law requires a legal basis, Kapow relies as applicable on performance of a contract; legitimate interests in providing, securing, supporting, and improving the Service; consent for optional analytics; compliance with legal obligations; and establishment, exercise, or defense of legal claims. You may withdraw consent without affecting earlier lawful processing.

8. Data Retention

Kapow retains personal information only as long as reasonably necessary for the purposes described, including providing an active account, completing transactions, maintaining security and audit records, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, or compliance obligations.

  • Account and workspace records are generally retained while the account is active and for a limited period after closure or deletion.
  • Subscription, transaction, and invoice-related records may be retained for legally required financial and tax periods.
  • License-key hashes, prefixes, status, and use timestamps are retained while needed to provide and protect entitlements and investigate abuse.
  • Support, security, and legal communications are retained as needed to resolve the matter and document the response.
  • Analytics retention is described in Section 5 and is also subject to provider settings and policies.
  • Local application data remains on the device until you delete it, remove the relevant profile or workspace, uninstall it using options that remove local data, or a feature rotates it. Copies may remain in backups you control.
  • Local account tokens and authentication state remain until sign-out, expiration, revocation, manual deletion, or removal by the application.
  • Backups and logs may persist for a limited period after deletion before routine rotation.

Kapow may retain information longer where required by law, litigation hold, fraud prevention, safety, or an unresolved dispute.

9. Security

Kapow uses administrative, technical, and organizational safeguards appropriate to the nature of the information. Current measures include HTTPS/TLS for website traffic, access controls, database row-level security for applicable hosted data, hashing of stored license keys, restricted access to license-key records, encryption of supported hosted integration secrets, and AES-256-GCM encryption at rest for values placed in the local secrets vault. These measures do not encrypt every local file, browser profile, session, or account token.

No security measure is perfect. You are responsible for securing your device, operating system, local data, backups, accounts, credentials, agents, and integrations. Report suspected Kapow vulnerabilities privately to contact@gokapow.com.

10. International Transfers

Kapow and its providers may process information in the United States and other countries. Where required, Kapow relies on contractual, adequacy, or other lawful transfer mechanisms. Protections and government-access rules may differ from those in your country.

11. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; or complain to a supervisory authority. Rights may be subject to identity verification and legal exceptions.

  • Manage available profile, subscription, and cookie controls directly in the Service.
  • Request privacy assistance at contact@gokapow.com.
  • Contact the relevant third-party provider regarding data it controls.
  • Delete local application data directly from your device, subject to backups you control.

Kapow will respond within the period required by applicable law. Kapow may retain information that law permits or requires it to retain.

12. Children

The Service is not directed to anyone under 18, and Kapow does not knowingly offer accounts to children. Contact contact@gokapow.com if you believe a child provided personal information.

13. Changes and Contact

Kapow may update this policy to reflect product, legal, or operational changes. Material changes apply prospectively after notice required by law. The “Last updated” date identifies the current version.

Privacy questions, security reports, legal notices, and general support: contact@gokapow.com.