← Back to Kapow

Kapow Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Sagi Yaacoby, operating as Kapow (“Kapow,” “we,” “us,” or “our”), processes personal information through gokapow.com, Kapow accounts, subscriptions, license services, support channels, hosted features, and the Kapow desktop application.

Kapow is designed to keep core project and agent data on your device. Kapow does not receive or store core project, task, prompt, file, agent, or output content on Kapow-operated servers merely because that information exists in the desktop application. Data can leave your device when you use account, billing, license, support, consented analytics, hosted, integration, download, or third-party AI features, as described below.

Kapow legal documents Terms of Use & Proprietary License Privacy Policy

Contents

  1. Scope and roles
  2. Information processed
  3. Local and third-party data
  4. How information is used
  5. Cookies and analytics
  6. Service providers and other recipients
  7. Legal bases
  8. Retention
  9. Security
  10. International transfers
  11. Your rights and choices
  12. Children
  13. Changes and contact

1. Scope and Roles

This policy applies when Kapow determines how and why personal information is processed. If an organization provides you access to Kapow, that organization may separately control information about its users, workspaces, permissions, and connected services. Contact that organization about its practices.

Third-party AI providers, model providers, local-model publishers, and integrations process information or provide materials under their own terms, licenses, and privacy policies when you choose to use them. Kapow does not control those independent practices. Depending on the service, your account, and the relevant agreement, a third party may act as Kapow’s service provider, as your service provider, or independently.

2. Information We Process

2.1 Website and Network Information

When you visit gokapow.com, hosting and security systems may process IP address, request time, requested URL, referrer, browser and device information, approximate location derived from IP, response status, and security or diagnostic data. Consent choices are stored in your browser.

2.2 Account and Workspace Information

When you create or use an account, Kapow may process:

  • email address, display name, avatar, account identifier, and authentication-provider metadata;
  • sign-in and account timestamps, account status, system role, and security events;
  • workspace or tenant name, membership, role, invitations, settings, and plan; and
  • communications and preferences associated with the account.

Authentication is provided through Supabase and may use Google, Microsoft, or GitHub sign-in when selected by you. Those providers also process information under their own policies.

2.3 Subscription and Billing Information

Kapow may process plan, billing interval, subscription status, trial and renewal dates, cancellation status, Stripe customer and subscription identifiers, and transaction-related records. Stripe processes payment-card details. Kapow does not receive or store your complete payment-card number.

2.4 License and Entitlement Information

Kapow processes account identifiers, plan and entitlement information, a display prefix for an active license key, a one-way hash of the license key, creation and revocation status, and last-use time. A newly generated raw key is returned once; the stored database value is a SHA-256 hash rather than the reusable raw key.

2.5 Support, Feedback, and Requests

Kapow processes information you submit through support emails, feature requests, comments, bug reports, security reports, and other communications, including attachments and diagnostic details you choose to provide. Do not include credentials or unnecessary sensitive information.

3. Kapow Desktop Application

3.1 Information Stored on Your Device

Kapow is designed so core operational data can remain on your device. Depending on the features you use, local data may include projects, tasks, prompts, messages, outputs, files, tables, workflows, agent and team configurations, memories, knowledge content, settings, logs, diagnostic state, model configuration, browser profiles and cookies, integration configuration, and owner-profile information. Kapow does not automatically receive that content merely because it exists in the application.

The desktop application also stores local account and authentication state needed to keep you signed in and check your plan. This may include account identifiers, email address, access and refresh tokens, expiration information, plan status, and the versions and timestamp of your in-app Terms and Privacy acknowledgement. Protect access to your operating-system account and device.

3.2 Credentials and Secrets

Supported API keys and service credentials placed in the Kapow secrets vault are encrypted at rest in a local file using AES-256-GCM with a key derived from the vault password. When the vault is unlocked or you authorize an agent, provider, or integration to use a credential, the required value may be held in memory and supplied to the relevant local process or external service. Other authentication state, including provider CLI sessions, browser cookies, and Kapow account tokens, may be stored separately from the encrypted vault.

An OpenRouter API key connected through Model Manager is stored separately on the device in a provider-credential file protected for the current Windows user through the Windows Data Protection API. The key may be decrypted in memory when Kapow sends an authorized OpenRouter request and is removed from that provider-credential store when you disconnect OpenRouter.

3.3 Information Sent from the Desktop Application

Data may leave your device when you:

  • authenticate, manage an account, purchase a plan, or validate a license;
  • submit support, feedback, feature-request, or security information;
  • use a hosted Kapow feature;
  • configure or approve an agent, plugin, browser, API, repository, email, or other integration that sends data elsewhere; or
  • send prompts, instructions, files, project or task context, outputs, or technical metadata to a third-party AI provider.

When you use Anthropic Claude, OpenAI services or Codex, OpenRouter, or another external-provider connection, the selected provider receives the information required to perform the request under the provider account and settings you use. Kapow provides the local environment and orchestration; the provider determines how it processes information under its own terms and privacy policy. Review provider retention, model-training, geographic, and data-control settings before sending confidential, regulated, personal, or third-party information.

When you use OpenRouter, prompts, instructions, files, project or task context, images, audio, video, outputs, and technical request information may pass through OpenRouter to a downstream model provider selected by you or through OpenRouter’s routing. Provider fallback may cause another provider offering the requested model to handle the request unless applicable routing settings restrict that behavior. OpenRouter and downstream providers may have different logging, retention, training, security, and international-transfer practices. Review the current OpenRouter Privacy Policy, data-collection information, and provider directory before use.

3.4 Local Models, Browsers, Updates, and Downloads

When you select a local model, inference requests are sent to the configured local model runtime, which normally runs on your device, and the prompt and response normally remain on the device unless you also authorize an external tool, integration, or destination. Installing or updating local models, the application, browser components, voice components, or other optional components may contact GitHub, Hugging Face, Lemonade, NVIDIA, npm, or another source identified by the installer or feature. Those sources receive standard network request information and may receive identifiers or telemetry according to their own software, account, and privacy settings.

Browser and integration features contact the websites and services you select and may maintain local browser profiles, cookies, or authenticated sessions. The Mind Map feature may retrieve its D3 software dependency from jsDelivr when used. Plugins, skills, and user-configured services may introduce additional destinations. Review agent plans, integration permissions, destination services, and network activity; Kapow cannot list every third-party destination you choose to configure.

4. How We Use Information

Kapow uses information to provide and secure accounts and the Service; authenticate users; manage workspaces, plans, subscriptions, billing, and licenses; provide support; diagnose failures; prevent fraud and abuse; understand consented website usage; communicate service and legal notices; enforce agreements; comply with law; and establish, exercise, or defend legal claims.

Kapow does not sell personal information. Kapow does not use your private local project content to train AI models. Third-party AI providers may process data under their own policies based on the account and settings you use.

5. Cookies, Local Storage, and Website Analytics

Kapow uses browser storage necessary to remember your cookie choice and may use storage required for authentication and security. Optional analytics load only after you select “Accept” in the cookie banner. Selecting “Decline” prevents the Kapow analytics loader from loading Google Analytics and Microsoft Clarity. You can reopen cookie preferences from the cookie icon.

ServiceData and purposeRetention information
Google Analytics 4Page views, sessions, approximate country, device/browser, referral source, and interaction measurements for website analytics. Advertising storage and personalization are signaled as denied by Kapow’s loader.User-level and event-level retention is controlled by the property setting; Kapow’s current disclosed configuration is 14 months.
Microsoft ClarityPage structure and user interactions such as clicks, scrolling, navigation, device information, and session reconstruction for usability analysis. Form and sensitive-content masking depends on Clarity and site configuration.Playback data is retained for 30 days. Click and heatmap data, labeled sessions, and favorite sessions may be retained for 9 months under Microsoft’s current service rules.

See Google Analytics privacy information and Microsoft Clarity privacy information. Browser settings and provider opt-out tools may offer additional controls.

6. Service Providers and Other Recipients

Kapow uses service providers for the limited hosted services it operates. The desktop application also contacts independent services selected by you and download sources required by features you choose. A recipient’s legal role depends on the service, account, and applicable agreement; listing a recipient here does not mean every recipient acts as Kapow’s processor in every context.

RecipientPurpose and information involvedMore information
SupabaseAuthentication, account and workspace records, plan and entitlement infrastructure, and related security information.Privacy policy
VercelWebsite hosting and serverless functions, including ordinary request, network, security, and diagnostic information.Privacy notice
StripePayment and subscription processing. Stripe receives payment-card details; Kapow receives subscription and transaction identifiers and status.Privacy policy
Google, Microsoft, or GitHubAuthentication when you choose the corresponding sign-in method. The selected provider receives information required for that sign-in.The selected provider’s current privacy policy
Google Analytics and Microsoft ClarityOptional website analytics described in Section 5, loaded only after the applicable consent choice.Links in Section 5
Anthropic and OpenAIUser-selected AI processing through the account, subscription, CLI session, or API access you connect. Prompts, files, context, outputs, and technical information required for a request may be transmitted.Anthropic policies; OpenAI policies
OpenRouter and downstream model providersUser-selected AI processing routed through OpenRouter. OpenRouter and the provider selected by you or through routing may receive the request information described in Section 3.3.Terms; Privacy; providers and data practices
Lemonade, Hugging Face, GitHub, NVIDIA, npm, and other identified sourcesRuntime, application, model, browser, voice, dependency, and component checks, installation, and downloads requested through the desktop application.The source, model card, license, and privacy information presented by the applicable source
jsDelivrDelivery of the D3 dependency when the desktop Mind Map feature requests it.Privacy policy

Kapow may also disclose information to professional advisers, authorities, or counterparties where reasonably necessary for legal compliance, safety, fraud prevention, claims, financing, reorganization, merger, acquisition, or transfer of the relevant business. When you direct data to an AI or integration provider, that provider receives the data as a service selected by you. Review its current terms, license, and privacy policy.

7. Legal Bases for Processing

Where data-protection law requires a legal basis, Kapow relies as applicable on performance of a contract; legitimate interests in providing, securing, supporting, and improving the Service; consent for optional analytics; compliance with legal obligations; and establishment, exercise, or defense of legal claims. You may withdraw consent without affecting earlier lawful processing.

8. Data Retention

Kapow retains personal information only as long as reasonably necessary for the purposes described, including providing an active account, completing transactions, maintaining security and audit records, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, or compliance obligations.

  • Account and workspace records are generally retained while the account is active and for a limited period after closure or deletion.
  • Subscription, transaction, and invoice-related records may be retained for legally required financial and tax periods.
  • License-key hashes, prefixes, status, and use timestamps are retained while needed to provide and protect entitlements and investigate abuse.
  • Support, security, and legal communications are retained as needed to resolve the matter and document the response.
  • Analytics retention is described in Section 5 and is also subject to provider settings and policies.
  • Local application data remains on the device until you delete it, remove the relevant profile or workspace, uninstall it using options that remove local data, or a feature rotates it. Copies may remain in backups you control.
  • Local account tokens and authentication state remain until sign-out, expiration, revocation, manual deletion, or removal by the application.
  • Backups and logs may persist for a limited period after deletion before routine rotation.

Kapow may retain information longer where required by law, litigation hold, fraud prevention, safety, or an unresolved dispute.

9. Security

Kapow uses administrative, technical, and organizational safeguards appropriate to the nature of the information. Current measures include HTTPS/TLS for website traffic, access controls, database row-level security for applicable hosted data, hashing of stored license keys, restricted access to license-key records, encryption of supported hosted integration secrets, and AES-256-GCM encryption at rest for values placed in the local secrets vault. These measures do not encrypt every local file, browser profile, session, or account token.

No security measure is perfect. You are responsible for securing your device, operating system, local data, backups, accounts, credentials, agents, and integrations. Report suspected Kapow vulnerabilities privately to contact@gokapow.com.

10. International Transfers

Kapow and its providers may process information in the United States and other countries. Where required, Kapow relies on contractual, adequacy, or other lawful transfer mechanisms. Protections and government-access rules may differ from those in your country.

11. Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; or complain to a supervisory authority. Rights may be subject to identity verification and legal exceptions.

  • Manage available profile, subscription, and cookie controls directly in the Service.
  • Request privacy assistance at contact@gokapow.com.
  • Contact the relevant third-party provider regarding data it controls.
  • Delete local application data directly from your device, subject to backups you control.

Kapow will respond within the period required by applicable law. Kapow may retain information that law permits or requires it to retain.

12. Children

The Service is not directed to anyone under 18, and Kapow does not knowingly offer accounts to children. Contact contact@gokapow.com if you believe a child provided personal information.

13. Changes and Contact

Kapow may update this policy to reflect product, legal, or operational changes. Material changes apply prospectively after notice required by law. The “Last updated” date identifies the current version.

Privacy questions, security reports, legal notices, and general support: contact@gokapow.com.