Privacy notice
This is a draft for review. It is not yet in force and will change before Boss opens to anyone outside the team.
Boss holds things you have not finished thinking about. This notice explains, in plain terms, what we keep, why, where it lives, and what you can do about it.
Who we are
Boss is provided by [LEGAL ENTITY] (Capisso), [REGISTERED ADDRESS], company number [COMPANY NUMBER]. You can reach us about privacy at privacy@capissoboss.com.
Two kinds of data, two roles
Your account. Your name, email address, sign-in methods and devices. We decide how this is used, so for this data we are the controller.
What is captured into a business. Notes, voice notes, emails, links, photos and files, and everything Boss files from them. The owners of that workspace decide what goes in and who can see it. We store and process it on their behalf, so for this data we act as their processor. If you have a question about something in a business you are part of, the workspace owners are the first people to ask.
What we collect
Account data
- Name and email address.
- Passkeys you register (a public key only; the private key never leaves your device).
- Sessions and devices: device type, when you signed in and when a session was last used.
- Memberships and invitations: which workspaces and businesses you belong to, and your role.
Captured content
- Whatever you or other members send in: text, audio, emails and their attachments, photos, files and links.
- What Boss makes from it: transcripts, text read from images and documents, the text of pages behind links, titles, tags, summaries and the contacts mentioned.
Records we keep to run the service safely
- An audit log of events such as sign-ins, invitations, membership changes, connections to Claude or ChatGPT, exports and deletions. It records who did what and when, never the content.
- A log of rejected incoming email: sender address, time and reason, never the message.
- Operational logs with reference numbers and error details. We do not write captured content into logs.
How we use it
- To sign you in, keep your account secure and tell you about new sign-ins.
- To store what you capture, file it, and let the people you choose search it.
- To send you emails you need: sign-in codes, invitations, verification codes and notices about your account or a business you belong to.
- To keep costs and misuse under control, for example limits on sign-in codes and a monthly processing budget per workspace.
We do not sell your data, show advertising, or use captured content to train AI models.
Where it is kept
The database and your stored files are held by Cloudflare in its EU jurisdiction, which keeps them within the European Union.
A few supporting services are not guaranteed to stay in the EU: the search index built from your content, the job queue that tells Boss what to process next (it carries reference numbers only, never content), and the sign-in tokens for Claude and ChatGPT connections. Where data leaves the EU, it is protected by the providers’ standard contractual clauses or equivalent safeguards.
Who else processes it
We use a small number of providers. Each receives only what it needs.
| Provider | What it does for us | What it receives |
|---|---|---|
| Cloudflare | Hosting, database, file storage, incoming email, job queues and the search index | All account data and captured content, as our host |
| Resend | Sends our emails, such as sign-in codes and invitations | Recipient address and the content of those emails. Its account data and delivery logs are kept in the United States |
| Anthropic | Files captures: type, title, tags, summary and contacts | The text of a capture while it is being filed. Kept for up to 30 days under its standard API terms, and not used for training |
| OpenAI | Writes out voice notes | The audio of a voice note while it is transcribed. Not used for training under its API terms |
If you connect Boss to Claude or ChatGPT, search results you ask for are sent to that service under your own account and its terms. You choose which businesses a connection can see, and you can remove it at any time.
How long we keep it
- Captured content and filed entries: until you or a workspace owner delete them.
- A deleted business or workspace: recoverable by an owner for 30 days, then permanently removed.
- Rejected email log: 30 days.
- Audit log: 2 years.
- Your account: until you delete it. See how to delete your account.
Your rights
You can ask to see, correct, export or delete your personal data, to restrict or object to how we use it, and to take it elsewhere. Much of this you can do yourself: export a business, correct how something was filed, delete a capture, or delete your account. For anything else, write to privacy@capissoboss.com. If a request is about content in a business, we will work with that workspace’s owners.
If you are unhappy with how we handle your data, you can complain to [SUPERVISORY AUTHORITY]. We would be grateful for the chance to put it right first.
Changes
If we change this notice in a way that matters, we will tell members by email before the change takes effect.