Skip to content
Captiod

Privacy Policy

Plain language about what Captiod collects, what it does with it, and how you stay in control.

Last updated

The short version

  • Captiod requires an account with a verified email address. We do not ask for your contacts, location, or Instagram or TikTok password.
  • What you share to Captiod is sent to our servers and to an AI model provider so it can be analyzed. That is the core of the app. It happens only after you allow AI processing in the app, and only when you share, add or ask something.
  • We do not sell your data, show ads, or track you across other apps and websites.
  • You can delete any save or conversation in the app, or ask us to erase everything.

Who we are

This policy covers the Captiod iOS app, its share extension, and captiod.com. Captiod is operated by Captiod. Contact us about privacy at privacy@captiod.com.

What we collect

Your account and session

We store your email address, a profile name, email verification status, a securely hashed password, and account creation dates in our PostgreSQL database. Better Auth runs on our servers to manage your account. Session records include expiry, IP address and user agent. The iOS app stores session credentials in the system Keychain through SecureStore. The share extension stores queued saves in the app’s shared local storage, without storing session credentials there.

What you save

  • Links you share to Captiod, such as an Instagram Reel, post or TikTok link.
  • Text you add, such as a caption you paste when a post can’t be read.
  • The analysis of each save: title, summary, steps, facts, copyable text, the things the post mentions, links, category and tags, plus the post’s cover image.
  • Your changes: favorites, archived saves, edited titles or categories, and steps you check off.
  • Plan and Ask: the tasks on your plans, and the questions you ask with the answers Captiod gives.

Technical information

When the app talks to our servers, we record basic request information (such as the time, the address requested, the result and how long it took) to keep the service running and to stop abuse. Our hosting providers also process network information such as IP addresses to deliver the service.

The website

captiod.com does not use advertising or analytics cookies and does not load third-party tracking scripts. If that ever changes, this policy will be updated first and we will ask for consent where the law requires it.

How we use it

  • To analyze what you share and show you the results.
  • To keep your library, plans and conversations in sync and available after you reinstall.
  • To answer your questions in Ask and build your Plan from your own saves.
  • To keep Captiod secure, prevent abuse, and fix problems.

We do not use your saves to build an advertising profile, and we do not sell or rent your data.

AI processing and other services

Captiod relies on a small number of service providers. They receive only what they need to do their job for us.

  • AI model provider. To analyze a save, Captiod sends the post’s video or images, its caption and any text you added to a model provider through OpenRouter, which routes the request to the underlying AI model. For Ask and Plan, it sends your question together with short digests of the relevant saves. Captiod asks for your permission in the app before sending anything, and you can withdraw it at any time in Settings → AI processing. While it is off, nothing new is sent.
  • Search provider. To find real links, Captiod may send the names of products, places, tools or books found in a post to Tavily, a web search service. Your device identifier is not included.
  • Hosting and database. Our website, API, background processing and database run on cloud infrastructure providers, including Vercel.
  • Email delivery. Resend receives your email address and the message needed to deliver verification and password-reset codes.
  • Cover storage. Cover images are stored in a private Vercel Blob store and served through an API that checks your account session.
  • Sign in with Apple and Google. If you choose Apple or Google to sign in, that provider confirms your identity and shares your email address (or an Apple private relay address) and, if you allow it, your name. Captiod stores the resulting account identity in its own database.

We require these providers to protect your data at least as well as this policy describes and to use it only to provide their service to us.

Reading public posts

To understand a post, Captiod’s servers request that post from Instagram or TikTok as any visitor would. We never log in to your accounts. Video files are stored only temporarily while a post is analyzed and are deleted when the analysis ends. We keep the post’s cover image so your library looks like what you saved.

How long we keep it

  • Saves, plans and conversations are kept until you delete them, or until we erase your data at your request.
  • Temporary video files are deleted as soon as analysis finishes.
  • Verification codes expire after 10 minutes. Sessions expire after 30 days unless renewed; signing out revokes the current session and password reset revokes existing sessions.
  • Request counters used to limit abuse are periodically removed by our background worker.
  • Deleted covers enter a retryable background deletion queue. Database backups and hosting logs follow the retention settings of the relevant provider.
  • Request logs are kept for a limited period by our hosting providers under their own retention settings.

Your choices and rights

  • Delete a save or conversation at any time in the app. Deleting a save removes it, its analysis and its cover from our servers.
  • Erase everything by following the steps on Delete your data.
  • Stop processing at any time by no longer sharing content to Captiod. Deleting the app removes the copy on your phone but not the data on our servers, so ask us to erase it too.
  • Depending on where you live, you may have rights to access, correct, export or delete your data, or to object to processing. Email privacy@captiod.com and we will respond within the time the law requires.

Security

Production connections use encryption in transit. Access to your library requires a verified account session. Keep your device and credentials protected, and never share verification or reset codes.

Children

Captiod is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has used Captiod, contact us and we will delete the data.

International transfers

Our providers may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for these transfers.

Changes

If we change this policy, we will update the date above. If a change is significant, we will tell you in the app before it takes effect.