Privacy policy · Last updated 27 June 2026
This page explains what personal data we collect when you visit
capacitor.kurrent.io, sign up for a Capacitor workspace, or
contact us, why we collect it, where it lives, and how to get rid of it.
We have tried to write this in plain English first and lawyer second.
Kurrent, Inc. operates Capacitor and is the data controller for the purposes of GDPR and equivalent laws. Contact for anything in this policy, including subject access and deletion requests: privacy@kurrent.io.
Capacitor captures your team’s coding-agent sessions — prompts, code, diffs, and the surrounding activity — into your own workspace. That content is yours. We do not use it for anything other than running the service for you. We do not mine it, profile you with it, sell or share it, or use it to train AI models — ours or anyone else’s — and it is never fed into the website analytics or advertising described below. We access workspace content only where strictly necessary to operate the service or to provide support you have asked for. Your Capacitor workspace and its data run on servers located in the European Union.
The rest of this policy concerns the data we collect through the
capacitor.kurrent.io website. Your workspace content is
governed by the commitment above and by your service agreement with us.
When you sign up for a workspace you authenticate through
WorkOS, our authentication provider. WorkOS runs the
sign-up and passes us your email address, whether it is
verified, your name if your identity provider supplies
one, and WorkOS user and organization identifiers. We keep you signed in
with a single encrypted, HttpOnly session cookie
(wos-session); a short-lived wos-oauth-state
cookie is used only to protect the sign-in round-trip against CSRF.
When you create your workspace we also store the organization name and workspace URL (slug) you choose, the plan you pick, any trial start and end dates, and the provisioning state of your workspace. To enforce one free trial per organization, we store a key derived from your email domain for trial signups.
Legal basis: performance of a contract — providing the Capacitor workspace you asked us to create — and our legitimate interest in preventing trial abuse.
Where it goes: authentication is processed by WorkOS, Inc. (United States) under their privacy policy; the workspace record is stored in a Cloudflare D1 database in the EU region, used only by Capacitor to provision and operate your workspace. WorkOS's sign-up protections guard the form against bots.
Retention: your workspace record is kept for as long as the workspace exists, and removed when the workspace is deleted or on request.
When you submit the Enterprise contact form, you give us:
Legal basis: our legitimate interest in evaluating enquiries, and (once we reply) the steps taken at your request before entering into a contract.
Where it goes: the form posts to a Cloudflare Worker we run on this domain. Submissions are stored in a Cloudflare D1 database in the EU region, used only by the Capacitor team to triage enquiries. The data is not synced to any CRM, marketing tool, or third party. Cloudflare’s privacy policy applies to its infrastructure role.
Retention: if we don’t move forward with your enquiry, we delete the entry. If we do, the entry is kept for the duration of our working relationship and removed afterwards on request.
If you click Accept on the cookie banner, we load PostHog, which records page URL, referrer, viewport, browser, OS, and a coarse country/region inferred from your IP (the raw IP is discarded at ingest). PostHog assigns an anonymous identifier so repeat visits can be told apart from new ones.
When you submit the Enterprise contact form or create a self-serve
workspace, we link that anonymous identifier to the email address you
provide (an identify call) so your earlier browsing and the
submission read as one person’s history rather than a stranger’s.
Alongside the email we record your GitHub organization (Enterprise form)
or your plan tier and workspace name (workspace signup). This happens
only after you have accepted analytics cookies.
Legal basis: your consent. You can withdraw it any time from the cookie policy page.
Where it goes: events are sent to
phog.kurrent.io, a first-party reverse proxy we run on our
own domain, which forwards them to PostHog’s EU ingest and EU-hosted
storage. Routing through our own domain stops domain-based ad blockers
from silently dropping analytics; it does not change who receives the
data — PostHog, in the EU. PostHog autocapture and session recording
are enabled; we don’t run heatmaps. Advertising measurement via the
Reddit Ads pixel is described separately in section 2b.
Retention: PostHog’s default retention applies (currently seven years for events). We do not query analytics data that is older than is useful for product decisions.
Independent of the cookie banner, our signup Worker sends a small number of operational events to PostHog (EU) for pipeline reliability — for example, when an email fails to send or when a submission is rejected by Turnstile.
What is sent: event name, processing stage, error code, HTTP status, coarse country (ISO two-letter), a generated request ID, and a timestamp. What is not sent: your email address, your IP, any identifier derived from your IP, your user agent, your GitHub organization name, or any other personally identifiable information.
Legal basis: legitimate interest under GDPR Art. 6(1)(f) — operating the signup form reliably. Because no personal data is sent, this telemetry is not consent-gated.
If you click Accept, we also load the Reddit Ads pixel. It records a page-visit event on each page, and a conversion event — tagged with a random per-submission id — when you submit the access-request form, so we can measure which Reddit ads bring people to the site.
What is sent: the event name, the per-submission id, and the standard browser and cookie data Reddit’s pixel collects for ad attribution. What is not sent: your email address or your GitHub organization.
Legal basis: your consent — the same banner choice as analytics. Where it goes: Reddit, Inc. in the United States. Withdraw: declining, or withdrawing consent from the cookie policy page, stops the pixel loading on future page views.
If you click Accept, we also load Reo.dev, a B2B visitor-analytics tool. It records page-view and interaction signals and uses your IP address and user agent to infer the company a visit is likely associated with, so we can understand which organizations are interested in Capacitor.
What is sent: page-view and interaction signals, your IP address, and your user agent, plus the cookies Reo sets for tracking. What is not sent: your email address or your GitHub organization.
Legal basis: your consent — the same banner choice as analytics. Where it goes: Reo.Dev, Inc. in the United States. Withdraw: declining, or withdrawing consent from the cookie policy page, stops Reo loading on future page views.
The site runs on Cloudflare Workers. Cloudflare receives standard HTTP request metadata (IP, user agent, requested URL, timestamps) to serve and protect the site. We don’t use Cloudflare Analytics; the request logs are processed by Cloudflare on our behalf under their data-processing terms.
Legal basis: legitimate interest in operating and protecting the website.
We use the following sub-processors. We do not sell personal data. If you accept cookies, we share page-visit and conversion signals with Reddit for advertising measurement, as described in section 2b; we do not share your email, GitHub organization, or signup-form submissions with any advertiser.
Kurrent, Inc. is based in the United States. PostHog analytics data and the workspace and contact-form records in Cloudflare D1 stay in the EU. Authentication is processed by WorkOS, Inc. in the United States. If you accept cookies, the Reddit Ads pixel sends visit and conversion data to Reddit, Inc., and Reo sends visit data to Reo.Dev, Inc., both in the United States. Cloudflare operates a global network and may route requests through nodes outside your country.
If your data is covered by GDPR or UK GDPR, you have the right to:
To exercise any of these, email privacy@kurrent.io. We aim to respond within 30 days.
If we change this policy in a way that affects you, we will update the “last updated” date at the top and, where the change is material, give visible notice on the site.