Legal

Privacy policy. What we hold, and why.

Capitaly works in your inbox and documents, so it handles what is in them. Here is all of it.

Updated September 2026

01

Who this covers

This policy explains how CAPITALY.ai, based in Sydney, New South Wales, Australia, collects, uses, shares and protects information when you visit the site or use the product. It covers visitors, account holders and the investors and contacts whose details pass through an account.

02

What we collect

From your team: name, work email, sign in details, organisation, role and what they do in the product.

From billing: your plan and subscription status. Card details are collected and held by our payment processor, never by us.

From your inbox: the investor threads Capitaly reads and sends, and the contact details in them.

From your tools: the documents, metrics and investor records you choose to connect, and the keys and tokens that connect them, which we store encrypted.

From the agents: what each run read, wrote, sent and changed, with timestamps, so every action can be checked.

From the site: which pages were visited, device and browser details, through Google Analytics, and which company a visit came from, through Apollo. No advertising trackers.

From the newsletter: your email and whether you open and click editions. It is delivered through Substack under Substack's own terms.

03

How we collect it

From you directly when you sign up, connect a tool or write to us, automatically as you use Capitaly, through logs and cookies, and from the services that run parts of it, such as payments, sign in and analytics.

04

Why we hold it

To find investors, send and answer email, book meetings, run the deal room and show you what happened. The log of every action is how you check what the agents did, and how we fix it when they got it wrong.

Also to take payments, keep the service secure, prevent fraud and abuse, support you, understand what to improve, send service and security messages, send marketing you can opt out of, and meet our legal obligations.

05

Legal bases

Where the GDPR or a similar law applies, we rely on our contract with you to run the service, our legitimate interest in keeping it secure and improving it, your consent for non essential cookies and marketing, and the legal obligations we have to meet.

06

Who else sees it

Only the services that make the product work: cloud hosting, the database and storage providers, payments, sign in, email delivery, analytics, and the model provider that reads the content.

The email providers, calendars and tools you connect receive what the agents send them, at your direction.

We share information when the law or a valid legal process requires it, to protect people or Capitaly from harm, or as part of a merger, acquisition or sale of assets, under this policy.

Each provider is bound to use it only to provide that service to us. We do not sell your data or your investors' data, and we never have.

07

Where it lives

In encrypted databases and storage run by our infrastructure providers.

Information may be processed in countries other than yours, including by the models that read an email or document. Where we move personal data across borders we use safeguards such as standard contractual clauses. Model providers are not permitted to keep it or train on it.

08

How long

For as long as your account is open, and you can delete any thread or document sooner. After an account closes we delete or anonymise what remains within a reasonable period.

Account and billing records stay for seven years after you close, because tax law asks us to, and anything else only as long as the law, security or a dispute requires.

09

How we protect it

Encryption in transit and at rest, separate accounts that cannot see each other, encrypted storage of connected keys, access limited to the people who need it, and monitoring. No system is perfectly secure, so we review these measures regularly.

10

Your rights

Depending on where you are, including under the Australian Privacy Act, the GDPR and the CCPA, you can ask to access, correct, export, restrict or delete your personal data, object to some processing, and withdraw consent. Using these rights never counts against you.

Much of it you can do in your account settings, and every marketing email has an unsubscribe link. For anything else write to [email protected]. We may need to confirm who you are, and you can also complain to the Office of the Australian Information Commissioner or your local data protection authority.

11

Investors' rights

An investor or contact can ask what we hold about them, ask for a copy, or ask for it to be deleted. Send it to [email protected] and we will action it within thirty days. Where we hold it for an account, we pass the request to that account too.

12

Cookies

We use cookies to keep you signed in, remember preferences and, with your consent, measure how the site is used. The cookie policy lists them and how to turn them off.

13

Children

Capitaly is for business use and not for anyone under 18. We do not knowingly collect children's data, and we delete it if we learn we have.

14

If something goes wrong

If data is exposed in a way likely to cause harm, we will tell affected account holders and the relevant data protection authority, as the law requires.

15

Changes

When this policy changes we update the date above, and for a change that matters we tell account holders before it takes effect.

16

Asking us about it

[email protected]. A person reads it.