Privacy & Data Use

How Capitora collects, uses, and protects information.

Capitora is an institutional intelligence platform. This policy explains, in plain language, what information we collect, how we use it, the safeguards in place, and the rights you have over your data. We collect the minimum required to operate the platform and to evidence usage rights.

Privacy Policy · v0.1·Reviewed quarterly·Data sources·Methodology·Disclosures
00 · Overview

Principles.

Restraint over collection. Transparency over inference. Security as a default posture.

Capitora operates as a research and intelligence platform. We are not a broker-dealer, investment adviser, or fiduciary (see Disclosures). Our data practices follow three principles: collect only what is necessary to deliver intelligence and operate the service; use information for clearly stated purposes; and never sell personal data.

01 · Information collected

What we collect.

  • Account information. Email, authentication metadata, and basic identifiers required to provision your workspace.
  • Onboarding preferences. Sector focus, region focus, capital-flow themes, and persona indicators captured during environment configuration.
  • Workspace configurations. Saved environments, custom layouts, dashboard arrangements, and tier-scoped settings.
  • Watchlists. States, sectors, infrastructure themes, and signals you elect to track.
  • Analytics interactions. Page views, signal interactions, dossier opens, and feature usage at the aggregate level.
  • Exported reports. Metadata of executive briefs, snapshots, and PDFs you generate (timestamp, template, scope).
  • Waitlist & alpha applications. Name, work email, organization, professional role, intended use case, and optional referral.
  • Email preferences. Subscription state for digests, alerts, and onboarding sequences, plus suppression flags.
  • Device & session information. IP-derived region, user-agent, and session metadata for security, fraud prevention, and operational monitoring.
02 · How information is used

Purposes of use.

  • Platform personalization. Tailoring intelligence surfaces to your sector, region, and persona configuration.
  • Intelligence delivery. Generating capital flow maps, hidden winners, executive briefs, and federal momentum signals relevant to your workspace.
  • Workspace persistence. Preserving environments, watchlists, layouts, and saved analyses across sessions and devices.
  • Platform analytics. Understanding aggregate usage to prioritize the signals and features that matter most.
  • Product improvement. Refining signal ranking, evidence weighting, and intelligence quality based on engagement patterns.
  • Digest delivery. Sending executive digests, weekly briefings, and event-driven intelligence to addresses you have opted into.
  • Account security. Authenticating sessions, detecting anomalous access, and enforcing tier-scoped permissions.
  • Operational monitoring. Maintaining reliability, debugging, and protecting the platform from abuse.
03 · Intelligence & analytics data

How analytics inform the platform.

Analytics are used to improve intelligence quality and the experience of using the platform — not to profile users for sale.

We collect interaction analytics, feature usage, onboarding metrics, signal engagement, workspace activity, and retention signals at an aggregated level. These inputs help calibrate ranking, severity scoring, and which intelligence surfaces deserve investment.

Capitora does not sell personal data. We do not rent or trade subscriber information, and we do not enrich our research with non-public personal information about subscribers.

04 · Email & notifications

Communications policy.

  • Executive digests. Periodic intelligence briefings delivered to opted-in subscribers.
  • Alerts. Event-driven notifications based on your watchlists and configured thresholds.
  • Teaser emails. Optional public-intelligence previews for non-subscribers.
  • Onboarding emails. Transactional messages tied to waitlist, alpha access, and account state transitions.
  • Preferences & unsubscribe. Every non-transactional email includes an unsubscribe link. You may also manage preferences from your account.
05 · Data security

Safeguards.

  • Authentication protection. Industry-standard credential handling and session security.
  • Encrypted transmission. Traffic between your device and Capitora is encrypted in transit (TLS).
  • Access controls. Row-level access policies restrict data to its owner; administrative access is logged and scoped.
  • Role-based permissions. Operator, executive, analyst, and observer roles each receive only the surfaces required.
  • Operational safeguards. Continuous monitoring, anomaly detection, and incident-response procedures.
06 · AI & intelligence systems

How our intelligence is produced.

Capitora's intelligence is explainable, evidence-driven, and non-advisory.

Signals are produced by combining public primary sources with documented ranking and classification logic. Every signal is intended to be traceable to its underlying evidence chain (see Methodology and Data sources).

AI-assisted summaries are used to compress and interpret evidence — they are not used to generate predictive recommendations. Outputs are informational and do not constitute investment advice. AI-generated text may contain errors; material corrections are published in the methodology changelog.

07 · Third-party services

Vendors we rely on.

We minimize third-party data sharing and prefer vendors with mature security and privacy postures.

  • Payment providers. Process subscription transactions. Capitora does not store full card details.
  • Analytics services. Aggregate usage measurement used to improve the product.
  • Authentication providers. Identity, session, and credential infrastructure.
  • Email delivery services. Transactional and digest delivery, suppression handling, and unsubscribe management.
  • Infrastructure & cloud providers. Hosting, storage, and compute required to operate the platform.
08 · User rights

Your rights over your data.

  • Access requests. Request a copy of the personal information associated with your account.
  • Deletion requests. Request deletion of your account and associated data, subject to limited operational and legal retention.
  • Export requests. Export workspace configurations, watchlists, and report metadata in a portable format.
  • Notification controls. Manage email subscriptions and notification preferences at any time.
  • Account management. Update profile, role, and tier-scoped settings from your account environment.

To exercise any of these rights, write to privacy@capitora.ai from the email associated with your account. We acknowledge requests within two business days.

09 · Retention

How long we keep information.

Retention is tied to operational necessity, legal obligation, and user control. We delete or de-identify data as soon as those conditions are met.

Active account data

Workspace configurations, watchlists, saved environments, and report metadata.

Until account deletion
Deleted account data — initial hold

Soft-deleted account records and personal identifiers retained for recovery and fraud-prevention purposes.

30 days
Deleted account data — hard purge

Permanent removal of personal identifiers, workspace content, and user-generated configurations.

90 days from deletion
Exported reports & briefs

PDF snapshots, carousel assets, and executive briefs generated by a user. Stored to allow re-download.

180 days from generation
Exported reports — deletion after purge

If the owning account is deleted, report assets follow the account hard-purge schedule or 180 days, whichever is earlier.

90 days from account deletion
Waitlist & alpha applications

Applications, referrals, and feedback submitted through the alpha intake form.

24 months from submission
Declined alpha applications

Records retained for operational reporting and to prevent duplicate submissions.

12 months from decline
Aggregated analytics

Feature-usage, signal-engagement, and retention metrics stripped of personal identifiers.

Indefinite
Security & audit logs

Authentication events, access logs, and tier-scoped permission changes for operational security.

12 months
Transactional records

Payment history, subscription state changes, and billing events.

7 years (legal obligation)
Email delivery records

Send logs, bounce events, and delivery-status metadata for operational deliverability monitoring.

90 days
Email suppression flags

Unsubscribe and suppression records to honor opt-out preferences across systems.

Indefinite (legal requirement)
10 · Disclaimers

Capitora is an intelligence platform — not investment advice.

  • Capitora is a research and intelligence platform, for informational use only.
  • Nothing on Capitora constitutes investment, financial, legal, or tax advice.
  • We make no guarantee of accuracy, completeness, or any particular outcome.
  • Consult a licensed adviser before making investment decisions.
11 · Contact

Privacy contacts.

Final disclosure

Capitora is a research and intelligence platform. Nothing on this site is, or should be construed as, investment, financial, legal, or tax advice. See full Disclosures.