1. At a glance
- Local scans, recognized text, and supported Apple Intelligence results stay in Kapier's storage on your iPhone unless you choose a connected feature.
- Creating an account sends account information to our authentication provider. It does not upload your local archive by itself.
- Cloud backup stores selected files and text encrypted at rest. To create its search index, it also sends readable text chunks to Cloudflare Workers AI and stores the resulting vectors separately. The design is server-readable, not zero-knowledge storage.
- Cloud intelligence sends selected document pages for OCR and sends recognized text to an AI model for an informational summary.
- We do not sell personal data, serve behavioral advertising, or use Kapier data for cross-app tracking.
Cloud intelligence is not yet enabled for general production use. This policy describes the connected service chain prepared for the launch version, which will remain unavailable until launch checks are complete.
2. Who is responsible
The controller responsible for Kapier under the General Data Protection Regulation (GDPR) is:
Nestor Code Crafters UG (haftungsbeschränkt)Kolonnenstr. 8
10827 Berlin
Germany
contact@nestorcodecrafters.com
3. Data we process
Local mode
Kapier stores captured page images, document titles, recognized text, summaries, possible action items, mentioned dates, and app settings locally on your device. Kapier does not receive that content in local mode. Your operating-system settings, including Apple device backups, may separately copy app data under Apple's terms.
Account and sign-in data
If you create an account, we process your email address, account ID, authentication records, session information, and any name you choose to provide. If you use Sign in with Apple, Apple supplies a unique identifier and, when you allow it, your name or email address.
Connected document data
If you enable backup or Cloud intelligence, we may process the selected page images, document metadata, recognized text, language, page structure, and generated results. Results can include a title, summary, possible action items, dates, amounts, identifiers, warnings, uncertainty, and evidence references to the original pages.
Backup is not passive storage-only. During a backup, Kapier's Cloudflare Worker sends each non-empty recognized-text chunk to Cloudflare Workers AI model BGE-M3 to create a search embedding. The text chunk is then stored with Kapier's application-layer encryption, while the resulting vector and a content hash are stored separately in Supabase. Those vectors remain personal data linked to your account and document.
Official documents can contain sensitive personal data about you or other people. Only use a connected feature for content you are entitled to process. The prepared Cloud intelligence path is not currently approved for special-category data under GDPR Article 9 or criminal-offence data under Article 10. Do not send those documents to Cloud intelligence unless Kapier later identifies the document class as supported. Local mode remains available.
People named in a selected document
A document you select may contain personal data about someone other than the account holder. Kapier receives that data from the user who chose the connected feature, not from the person named. We process it only for the same feature, recipients, and retention periods described in this policy. A person named in a document may contact us about their rights, subject to the account holder's rights and applicable legal exceptions.
Purchases and entitlement data
Apple handles payment details. Kapier and RevenueCat receive purchase and subscription records, an app user identifier, entitlement status, transaction identifiers, and limited device or technical information needed to provide and restore paid access. They do not receive your document content for billing.
Operational and support data
Connected services process IP address, request timing, coarse device or app version, account and job identifiers, consent records, usage totals, error classes, and security events. Kapier's application logs and billing records are designed not to include document images, recognized text, document names, summaries, dates, amounts, or identifiers extracted from a document.
If you contact us, we process your email address, message, attachments, and the information needed to answer. Vercel hosts this website and processes ordinary request and security data such as IP address, user agent, requested URL, and timestamps to deliver and protect it. The website currently has no contact form, advertising, or marketing analytics.
4. Why we process data and our legal bases
| Purpose | GDPR legal basis |
|---|---|
| Create and secure an account; provide backup, paid access, support, and user-requested Cloud intelligence | Contract performance, Article 6(1)(b) |
| Prevent abuse, secure the service, diagnose content-free failures, and establish or defend legal claims | Legitimate interests, Article 6(1)(f), balanced against your rights |
| Keep invoices, usage records, and required legal records | Legal obligation, Article 6(1)(c) |
| Optional processing for which we specifically ask permission | Consent, Article 6(1)(a) |
You can refuse Cloud intelligence and continue using local mode. Deleting the cloud result withdraws future use of the retained result, without affecting processing already completed lawfully. Kapier must establish an appropriate Article 9 or Article 10 condition and matching provider coverage before supporting documents that contain those protected categories in Cloud intelligence.
Kapier generates informational output but does not make decisions that produce legal or similarly significant effects about you. Summaries can be wrong and are not legal, tax, medical, or financial advice.
6. Retention and deletion
- Local content remains until you delete it or remove app data.
- Account and profile data remains while your account is active and for any limited period needed to complete deletion or meet law.
- Encrypted backups, linked search embeddings, and completed cloud results remain until you delete the relevant cloud copy, document, result, or account.
- Decrypted page bytes and raw provider responses are not intentionally stored by Kapier after the active processing step.
- Abandoned uploads and sources for cancelled or permanent failures are scheduled for deletion after 24 hours. Retryable-failure sources may remain for up to 30 days.
- Failed or cancelled attempt metadata remains for 30 days; content-free security and operational events remain for 12 months.
- Billing usage is retained for the applicable accounting period; Kapier's current engineering period is seven years.
User-triggered cloud deletion disappears from product reads immediately and is designed to finish durable cleanup within 24 hours. Providers may keep limited request content or security records under their own documented retention periods; the current AI chain is not configured for zero data retention.
7. How we protect connected data
We use transport encryption, access controls, private object storage, encryption at rest, server-side ownership checks, rate and spend limits, provider kill switches, and content-minimized operational logging. Connected document encryption is intentionally readable by authorized Kapier services when needed to provide the selected feature. No system is perfectly secure, and we do not describe this design as end-to-end or zero-knowledge encryption. Backup search vectors and their content hashes are stored separately from the encrypted text and are not covered by Kapier's application-layer document encryption.
8. Your choices and rights
Product controls
- Use local mode without an account.
- Keep backup disabled or disable it for a document.
- Decline Cloud intelligence for any document.
- Delete a cloud result or cloud document copy.
- Manage or cancel subscriptions in your Apple account settings.
- Contact us to request account deletion or exercise a privacy right.
Data-protection rights
Depending on the law that applies, you may request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time for the future. We may need to verify your identity before acting on a request.
You may also complain to a supervisory authority. For our Berlin establishment, the competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit. You may instead contact the authority where you live or work.
9. Children
Kapier is not directed to children under 16. If you believe a child has created an account or sent personal data without appropriate authorization, contact us so we can investigate and delete it where required.
10. Changes to this policy
We will update this page when Kapier's data practices materially change and will revise the date at the top. When a change requires notice or renewed consent, we will provide it in the app or through an appropriate contact channel before the change applies.
11. Contact
For privacy questions, access or deletion requests, or concerns about a connected document, email contact@nestorcodecrafters.com. Please do not attach a sensitive document unless we specifically ask for it through an appropriate support process.