Trust and safety
The Privacy Policy and the Terms are written carefully, because they have to be. This page says the same things plainly, including the parts that are not flattering.
The short version
- Most of the tools here never upload your file at all. They run inside your browser.
- KapeAI is not told who you are. Nothing about your account is put in front of it.
- There are no analytics, no trackers and no advertising anywhere in this product.
- We never see a card number, a bank login or a wallet password.
- What you have paid for is enforced on the server, not by hiding buttons.
- You can delete your account, and everything it owns, yourself.
The tools that never send anything
These run entirely in your browser. The file you drop in is opened by your own machine, worked on by your own machine, and saved back by your own machine. It is never uploaded, so there is nothing of it for us to keep, lose or be asked to hand over - and that stays true however sensitive the document is.
- PDF Tools and the PDF Editor
- File Converter, including video and audio
- Image Compressor and Image Upscaler
- Screenshot to Text (OCR)
- Audio Transcriber
- Pixel Editor, Site Showcase and Mockup Studio
This is also why they are free. They cost us nothing to run no matter how heavily you use them, so charging for them would be arbitrary.
The honest exception: anything you deliberately post or upload - a community post image, a chat image, a music track, a payment screenshot - does reach our storage, because that is the point of posting it.
KapeAI is not told who you are
The instructions KapeAI receives are byte-for-byte identical for every member. Your name, email, plan and account history are not in them, because they were never built in - not hidden, not redacted, simply absent. A test in the codebase asserts this by generating the instructions for two different accounts and failing if they differ by a single character.
That design does one thing a policy cannot: it removes the possibility of one member's details surfacing in another member's answer, rather than promising it will not happen. It is also why KapeAI cannot answer questions about your billing - it genuinely does not know.
What it does receive is your message and the product documentation. Those go to Anthropic's API, which under its commercial terms does not use them to train models.
Nothing here follows you around
There is no analytics script, no advertising pixel, no session recorder and no third-party tag on any page of this site. There is one lasting cookie, bl_session, which is what keeps you signed in. Signing in with Google briefly adds a second, bl_oauth, which exists only to check that the trip out to Google and back is the same one you started; it lasts ten minutes and is deleted the moment you land.
The fonts are served from our own server rather than from Google Fonts, so loading a page does not hand your IP address to anyone else. The browser's content security policy is set to refuse connections to outside hosts, which means this is enforced by your browser rather than resting on our good intentions.
Who else can touch your data
Five companies, each doing one job, and the same five listed in the Privacy Policy. Google is a sixth name here but a different kind of thing, and it is explained under the list:
- Anthropic - runs the AI writing features and KapeAI. Sees what you type into them and what comes back. Does not train on it.
- Groq - runs the Subtitle Generator only. The audio or video you submit to that one tool is uploaded and transcribed there. Every other transcription tool here runs on your own machine.
- Cloudflare - sits in front of the site and stores boards, sheets and uploaded files.
- Resend - sends account email. Sees the address and that one message, nothing else.
- Hostinger - the server the application and its database run on.
Those five handle data on our instructions. Google is not one of them and is not doing a job for us: if you press "Continue with Google", Google identifies you to us and tells us your email address and name. It is a company you already have an account with, acting on its own behalf, and it learns that you signed in here. Nothing of yours is sent to Google in return, we ask for no access to your Gmail, Drive, contacts or calendar, and if you sign in with a password instead then Google is never involved at all. The choice is the whole control.
There is no seventh, and no other company sees anything. If that changes we will say so in the Privacy Policy and note it where you sign in, so it is not something you have to discover.
Money
There is no card form here and no payment provider holding your details, because there is no automated checkout. Payment happens inside your own GCash app. What reaches us is the screenshot you choose to send and the name and email you type on the form.
So we never ask for, receive or store a card number, a bank credential or a wallet login. Nothing renews by itself either - there is nothing on file to charge, which is also why a membership that ends simply ends.
Locks that are actually locked
Every paid feature is refused by the server, on every request, by re-reading your plan from the database. The greyed-out card in the interface is a courtesy, not the lock. Someone who edits the page in their browser, guesses the address of a paid download, or calls the API directly gets the same refusal as someone who does nothing at all.
Accounts are separated the same way. Every query for your leads, boards, sheets, clients and applications is written against your account id, so another member cannot reach them by changing a number in a URL.
What we keep, and for how long
- Your password is never stored. What is stored is a scrypt hash, which cannot be turned back into the password - we could not tell you your own password if you asked.
- The sign-in cookie is HttpOnly and expires after 30 days.
- Security counters, used to stop password guessing, record a shortened form of your IP address and are deleted as soon as their window closes - about an hour at most.
- Backups are taken nightly and kept for 14 days.
- The database is not reachable from the internet at all. It listens only to the application on the same machine.
Leaving
Account deletion is a button in the account menu, not an email you have to send and wait on. It asks for your password and your email address, and then removes the account and the content it owns. What survives is a single line recording that an account was deleted, because that line is the only remaining evidence the deletion happened.
What we can see
Every product's trust page lists what it protects. This is the other half, because a list of reassurances with nothing uncomfortable in it should not convince anybody.
- Kape Tools is run by one person. The operator has administrative access to the server and can therefore read the database, including your leads, clients, boards, notes and chat messages. There is no larger company here in which that access is separated - so what you are trusting is a person, and you should size what you put in accordingly.
- Your content is stored as ordinary text. It is not encrypted in a way that would stop the operator, or anyone who obtained the server, from reading it. Encrypting it would mean holding a key that could decrypt it, which moves the problem rather than solving it.
- Global chat is exactly as public as it sounds: every signed-in member can read it, and so can we.
- A payment screenshot is a picture of your wallet app. It is stored until the membership it paid for has ended, and you can ask us to delete it sooner.
- The job boards collect public listings from LinkedIn, JobStreet and OnlineJobs.ph. That is other people's data, gathered from pages anyone can open without signing in, and we keep only what a listing shows publicly.
None of this is unusual for a product this size. It is written down because you would rather know it now than find it out later.
If something goes wrong
If personal data is ever exposed, we will tell the people affected and the National Privacy Commission, within the 72 hours the Data Privacy Act allows, and say what happened rather than what it might have been.
Found something on this page that is not true, or a hole we have missed? Write to [email protected]. A report that costs us an afternoon is cheaper than the alternative, and it will be answered.
If you handle other people's data here
Putting your own clients' or leads' details into Kape Tools makes you responsible for them under the Data Privacy Act, and makes us your processor. The terms of that - what we may do with it, who else touches it, and what happens to it when you leave - are set out in the Terms of Service. Email us if you need a countersigned copy for your records.