Key points
- Kaption collects information needed to provide and secure the service.
- Uploaded media may be processed by contracted infrastructure providers.
- Data is retained according to defined operational and legal needs.
- Users may request access, correction or deletion where applicable.
- Optional cookies remain disabled unless selected.
This summary does not replace the complete policy below.
This Privacy Policy explains how Kaption handles personal data when individuals visit https://kaption.in, register or sign in, upload media, generate captions, transcripts or other content, purchase or use a subscription, join a team, or contact Kaption.
It applies to account holders, website visitors, people acting for a customer or team, and people who contact Kaption. It also explains how information about other people may be present inside media uploaded by a user.
If an organisation provides your Kaption account, that organisation may separately control account access and the content placed in its workspace. Ask the organisation about its own privacy practices.
Kaption is a digital service operated by Yagna Patel, an individual proprietor based in Gujarat, India.
- Trade name
- Kaption
- Legal owner
- Yagna Patel
- Business type
- Individual proprietor
- Business address
- Pavan City Complex, Modasa, Gujarat, India
- Contact email
- support@kaption.in
Kaption collects information that a user chooses to provide while creating an account, using a feature, uploading content, purchasing a plan, joining a team, or sending a message. Fields shown as required must be supplied for the relevant feature; optional fields may be left blank.
The summaries below explain the main categories. Actual data depends on the features used and the information placed in an upload or message.
Detailed data-processing inventory
Account data
- Examples
- Name, email address, account role, language preference and versioned Terms and Privacy Policy acceptance record.
- Purpose
- Create, administer and support the account and retain evidence of the policies accepted during signup.
- Service Provider / Data Recipient
- Kaption and its authentication and database services.
- Retention period
- While the account is active, then only as needed for deletion processing, security, disputes or legal records.
Authentication data
- Examples
- Password hash, Google sign-in token and profile details returned during sign-in.
- Purpose
- Verify identity, issue a session and protect account access.
- Service Provider / Data Recipient
- Google Identity Services and Kaption email/password authentication
- Retention period
- Password hashes are kept while email sign-in remains active; tokens and session data follow their applicable validity and security periods.
Uploaded media and text
- Examples
- Video, audio, image, transcript, subtitle and project files.
- Purpose
- Upload, store, process, transform and deliver the feature requested by the user.
- Service Provider / Data Recipient
- Google Cloud Storage and the service processors needed for the requested feature.
- Retention period
- 30 days under the current automatic storage lifecycle, unless deleted sooner or lawfully retained for a limited exception.
People and information within uploads
- Examples
- Voices, faces, names, conversations, locations or other personal information appearing in media.
- Purpose
- Process the media and produce the captions, transcript, subtitle or other output requested by the user.
- Service Provider / Data Recipient
- The storage and processing services needed to perform the requested operation.
- Retention period
- Generally follows the 30-day uploaded-file lifecycle.
Generated outputs
- Examples
- Captions, transcripts, subtitles, summaries, social content and downloadable files.
- Purpose
- Display, edit and deliver results and maintain the related project.
- Service Provider / Data Recipient
- Kaption, its storage services and any processor needed for the requested output.
- Retention period
- For the project or account lifecycle shown in the service, subject to deletion requests and limited legal or security retention.
Subscription and transaction data
- Examples
- Plan, billing cycle, usage minutes, amount, currency, payment status and transaction reference.
- Purpose
- Provide paid features, record purchases, manage billing and meet accounting or tax obligations.
- Service Provider / Data Recipient
- Cashfree Payments; Kaption receives relevant transaction and subscription records.
- Retention period
- For the subscription relationship and any longer period required for accounting, tax, fraud prevention or dispute records.
Support and grievance communications
- Examples
- Email address, message, attachments, case history and requested resolution.
- Purpose
- Answer questions, resolve complaints, investigate issues and keep an appropriate case record.
- Service Provider / Data Recipient
- Kaption and its email services: Titan Mail, EmailJS.
- Retention period
- For as long as needed to resolve the request and maintain necessary support, legal or grievance records.
Device, browser and log data
- Examples
- IP address, browser or device information, request time, route, errors and security events.
- Purpose
- Operate, diagnose, secure and prevent misuse of the service.
- Service Provider / Data Recipient
- Kaption and its hosting services: Vercel.
- Retention period
- For a limited operational and security period appropriate to the log, then deleted or aggregated unless needed for an incident or legal obligation.
Cookies and local browser data
- Examples
- Authentication, preference and other browser-stored values.
- Purpose
- Keep users signed in, remember choices and provide requested site functions.
- Service Provider / Data Recipient
- Kaption. No analytics provider is identified in the current configuration.
- Retention period
- Session cookies expire with the session; persistent items remain for the duration described in the Cookie Policy or until cleared.
| Data category | Examples | Purpose | Service Provider / Data Recipient | Retention period |
|---|---|---|---|---|
| Account data | Name, email address, account role, language preference and versioned Terms and Privacy Policy acceptance record. | Create, administer and support the account and retain evidence of the policies accepted during signup. | Kaption and its authentication and database services. | While the account is active, then only as needed for deletion processing, security, disputes or legal records. |
| Authentication data | Password hash, Google sign-in token and profile details returned during sign-in. | Verify identity, issue a session and protect account access. | Google Identity Services and Kaption email/password authentication | Password hashes are kept while email sign-in remains active; tokens and session data follow their applicable validity and security periods. |
| Uploaded media and text | Video, audio, image, transcript, subtitle and project files. | Upload, store, process, transform and deliver the feature requested by the user. | Google Cloud Storage and the service processors needed for the requested feature. | 30 days under the current automatic storage lifecycle, unless deleted sooner or lawfully retained for a limited exception. |
| People and information within uploads | Voices, faces, names, conversations, locations or other personal information appearing in media. | Process the media and produce the captions, transcript, subtitle or other output requested by the user. | The storage and processing services needed to perform the requested operation. | Generally follows the 30-day uploaded-file lifecycle. |
| Generated outputs | Captions, transcripts, subtitles, summaries, social content and downloadable files. | Display, edit and deliver results and maintain the related project. | Kaption, its storage services and any processor needed for the requested output. | For the project or account lifecycle shown in the service, subject to deletion requests and limited legal or security retention. |
| Subscription and transaction data | Plan, billing cycle, usage minutes, amount, currency, payment status and transaction reference. | Provide paid features, record purchases, manage billing and meet accounting or tax obligations. | Cashfree Payments; Kaption receives relevant transaction and subscription records. | For the subscription relationship and any longer period required for accounting, tax, fraud prevention or dispute records. |
| Support and grievance communications | Email address, message, attachments, case history and requested resolution. | Answer questions, resolve complaints, investigate issues and keep an appropriate case record. | Kaption and its email services: Titan Mail, EmailJS. | For as long as needed to resolve the request and maintain necessary support, legal or grievance records. |
| Device, browser and log data | IP address, browser or device information, request time, route, errors and security events. | Operate, diagnose, secure and prevent misuse of the service. | Kaption and its hosting services: Vercel. | For a limited operational and security period appropriate to the log, then deleted or aggregated unless needed for an incident or legal obligation. |
| Cookies and local browser data | Authentication, preference and other browser-stored values. | Keep users signed in, remember choices and provide requested site functions. | Kaption. No analytics provider is identified in the current configuration. | Session cookies expire with the session; persistent items remain for the duration described in the Cookie Policy or until cleared. |
Current service providers
| Provider | Service | Data involved | Processing or storage region | Privacy information |
|---|---|---|---|---|
| Vercel | Website or application hosting | Network requests, logs and application data handled by the hosted service. | Not yet verified | Review the provider's current privacy and data-processing terms. |
| Google Identity Services and Kaption email/password authentication | Authentication | Account identifiers, email addresses, sign-in events and session-related information. | Not yet verified | Review Google and Kaption authentication terms as applicable. |
| PostgreSQL Database | Database | Structured account, policy, billing, support and service records. | Not yet verified | Review the database provider's current privacy and data-processing terms. |
| Google Cloud Storage | File storage | Uploaded media, project files and generated assets. | Not yet verified | Review the storage provider's current privacy and data-processing terms. |
| Titan Mail | Email delivery and inbox handling | Email addresses, message content, delivery metadata and attachments when supplied. | Not yet verified | Review the provider's current privacy and data-processing terms. |
| EmailJS | Email delivery and inbox handling | Email addresses, message content, delivery metadata and attachments when supplied. | Not yet verified | Review the provider's current privacy and data-processing terms. |
| Groq | AI functionality | Support-assistant prompts and limited context currently verified in the inspected code. | Not yet verified | Review the provider's current privacy and data-processing terms. |
| Cashfree Payments | Payment processing | Transaction, subscription and payment-status information. | Not yet verified | Review the payment provider's current privacy and data-processing terms. |
Account data may include a name, email address, account identifier, language or interface preferences, role, team or workspace membership, plan, usage balance, account status, and a signup policy acceptance record containing the applicable version identifiers, acceptance source and timestamp. Kaption uses this information to create the account, identify the user, retain evidence of the accepted policies, provide the selected workspace and plan, display settings, measure allowed usage, and communicate about the service.
Users should keep account information accurate. Team administrators may be able to see membership and manage access within their workspace, but should not receive more personal information than needed for that role.
Kaption supports email-and-password sign-in and Google sign-in. Passwords are transformed into password hashes before storage; the application does not need to retain the readable password to verify a later sign-in.
For Google sign-in, Kaption receives and verifies a Google identity token and may receive basic profile information needed to identify or create the account, such as an email address and name. Kaption then issues its own authenticated session token. Users should protect their credentials and notify support@kaption.in if they suspect unauthorised access.
Users may upload videos, audio, images, text, subtitles, transcripts, fonts, project information and related media so Kaption can provide the requested feature. Technical information about an upload may include the file name, media type, size, storage location, project relationship, upload status and expiry time.
Do not upload information that is unnecessary for the requested service. Keep independent copies of source media and important outputs because Kaption is not a permanent archive.
Uploaded media can contain personal data about people other than the account holder. This may include a person's voice, face, image, name, conversation, location, opinions, background, identifiers, or other information that can reveal who they are or facts about them.
Users should apply extra care before uploading sensitive recordings, children's information, confidential meetings, health information, financial information, government identifiers or content that could create a serious risk to another person.
Kaption may create captions, transcripts, subtitles, translations, summaries, social-media content, edited media, project data and other AI-assisted outputs from user instructions and uploads. Those outputs may contain personal data copied, inferred or reorganised from the source material.
Kaption uses generated outputs to display, edit, save and deliver the requested result. Users must review outputs before publication because automated results may be incorrect, incomplete or inappropriate.
When paid features become available, Kaption may process plan, billing cycle, price, currency, taxes, usage minutes, add-ons, transaction reference, payment status, renewal or cancellation state, and limited billing contact details.
Payment collection is provided by Cashfree Payments. Where the provider hosts the payment form, card or payment-account details are entered directly with that provider, and Kaption receives the transaction and subscription information needed to provide the purchase and maintain records.
If a person contacts support, privacy, copyright or grievance channels, Kaption receives the contact details, message, attachments, relevant account or project references, and follow-up correspondence they provide.
Kaption uses this information to answer the request, verify identity where needed, investigate an issue, provide support, handle a legal notice or grievance, prevent repeated abuse, and keep an appropriate record of the outcome.
The website, application servers and service providers may generate technical records when Kaption is used. Depending on the request, these can include an IP address, device or browser type, operating system, requested route, request time, response status, error details, performance information and security events.
This information is used to deliver requests, keep sessions working, diagnose errors, monitor reliability, enforce limits, investigate suspicious activity and protect accounts and infrastructure. Kaption does not describe every technical record as personally identifying, but treats it carefully where it can be linked to a person or account.
Kaption may use cookies or similar browser storage for sign-in, security, preferences and other requested functions. Some items are necessary for the service to work; others, if introduced, should be explained and controlled as required by applicable law.
No analytics provider is identified in the current legal configuration. Kaption must update this policy and the Cookie Policy before enabling a third-party analytics service.
See the Cookie Policy for more detail about browser storage and available controls.
Kaption processes personal data only for relevant purposes such as:
- creating, authenticating and securing accounts;
- providing workspaces, plans, team access and usage balances;
- receiving uploads and producing the captions, transcripts, subtitles, content or downloadable outputs requested by the user;
- operating, maintaining and troubleshooting the service;
- responding to support, privacy and grievance requests;
- managing purchases, subscriptions and business records;
- preventing fraud, abuse, infringement and security incidents;
- enforcing service terms and protecting users or third parties;
- meeting legal obligations and responding to lawful requests; and
- improving reliability and user experience using information appropriate for that purpose.
The data table in section 3 connects each main category with its purpose, usual recipient and retention approach.
The lawful or permitted basis depends on the data, the feature, the person's location and the law that applies. Kaption may process data because it is necessary to provide a service requested by the user or perform a contract; because the person has given valid consent; for a use permitted or required by applicable law; to comply with a legal obligation; or for legitimate operational, security and business purposes where that basis is recognised and does not override the person's rights.
Where processing depends on consent, the request should explain the relevant purpose and allow consent to be withdrawn. Withdrawal does not make earlier lawful processing invalid and may prevent Kaption from providing a feature that requires the data.
The application creates an authenticated project record and a controlled upload location for an authorised user. The user's browser sends the file to configured cloud storage. Kaption records enough file and project information to associate the upload with the correct account and requested operation.
The file may then be read, copied, converted, analysed, transcribed, captioned, reformatted or combined with instructions only as needed to provide, secure and support the requested feature. Outputs may be made available to the authenticated user through controlled access. Kaption may also process a file when reasonably necessary to investigate abuse, solve a support issue or comply with law.
Kaption does not claim ownership of original uploads. The Terms of Service provide only the limited operational licence needed to host, process, transform and deliver the requested service.
Kaption relies on third parties for parts of hosting, authentication, data storage, email and AI-enabled functionality. Each provider should receive only the information reasonably needed for its assigned service and may process it under its own documented terms, privacy notice and contractual duties.
Providers can change as the product develops. Kaption should update this policy before a new provider materially changes how personal data is handled. The following sections identify providers confirmed by the current code and legal configuration and separately flag provider categories that remain unconfirmed.
Kaption uses Vercel for website and application hosting. These providers may process network requests, IP addresses, request and error logs, application data and other information transmitted through the parts of the service they host.
Authentication is provided through Google Identity Services and Kaption email/password authentication. Google may process sign-in information under Google's own privacy terms when a user chooses Google sign-in. Kaption also processes email addresses, password hashes and session information for its own email-and-password sign-in flow.
Kaption's application uses a PostgreSQL database for structured account and service records.
The configured database service provider is PostgreSQL Database.
Uploaded project media is stored using Google Cloud Storage. The service uses controlled upload and download access and associates stored objects with the authenticated owner's project.
The configured storage lifecycle schedules uploaded project files for automatic deletion after 30 days.
The AI provider confirmed in the code and legal configuration is Groq. The verified current integration supports Kaption's support assistant and can receive the user's support question and limited conversation context needed to answer it.
The inspected code does not establish that uploaded media is sent to Groq for caption or transcription processing. Kaption must separately identify and disclose every provider that receives uploaded media before enabling that processing in paid production.
Kaption uses Titan Mail and EmailJS for email services. Depending on the message, they may process sender and recipient addresses, subject lines, message content, attachments, delivery information and related email metadata.
Avoid sending passwords, full payment credentials or unnecessary sensitive media by email.
Kaption uses Cashfree Payments as its payment provider. Where payment collection is hosted by that provider, payment-account or card details are processed directly by the provider, while Kaption receives the payment status, transaction reference and subscription information needed to provide the purchase and maintain records.
No third-party analytics provider was confirmed in the inspected code or legal configuration. This does not mean the application produces no operational logs. It means Kaption will not name or describe an analytics provider until one is verified. This policy and the Cookie Policy must be updated before a provider is enabled.
Kaption operates from India, while service providers may store or process information in other countries. This means personal data may be transferred to and processed outside the user's state or country, where privacy laws and government-access rules may differ.
Where applicable law requires safeguards for a transfer, Kaption should use an available lawful transfer mechanism and appropriate provider terms, and assess the information, destination and processing involved. This policy does not claim a particular transfer certification that has not been verified.
Kaption keeps personal data only for as long as reasonably necessary for the relevant service, account, project, security, support, transaction or legal purpose. Retention can differ by category.
- Uploaded project files follow the 30-day automatic storage lifecycle described below.
- Account and project records may remain while the account or project is active and during deletion processing.
- Subscription, transaction, tax and accounting records may be kept for periods required by applicable law.
- Support, grievance, fraud and security records may be kept long enough to resolve the issue, prevent repeated harm and meet legal obligations.
- The inspected application code does not define or verify a database or storage-backup retention schedule. Active product records and cloud objects are deleted through the process below, but Kaption cannot promise immediate removal from provider-managed or administrator-managed backups. If backups are enabled, copies should remain isolated from ordinary product use and expire under the applicable backup schedule. That schedule must be documented before paid production launch.
The account-deletion completion period is not yet confirmed in the legal configuration and is not guessed in this policy.
An authenticated user can delete a project from its project menu. The confirmation screen inventories the project, its uploaded source and any registered subtitle, transcript, export or temporary-processing objects. The server checks project ownership; storage paths and signed URLs are not shown.
Once the server accepts the request, the project is hidden from the active project list so it does not reappear after refresh. Kaption records a processing-cancellation request, deletes objects below the project's protected prefix from its configured primary, output and temporary Google Cloud Storage buckets, and then deletes the registered artifact and project records in a database transaction. The inspected code has no search index or CDN integration, so there is currently no separate search-index or CDN purge step.
If part of storage deletion fails, the project remains unavailable and the deletion is queued for retry. After the automatic retry limit, the request is marked failed for operational follow-up rather than falsely reported as complete. A minimal audit records the project and user identifiers, source type, status, attempts, failed system scopes and timestamps; it does not retain the deleted media, filenames, storage keys or signed URLs.
Captions edited in Kaption are stored with their project and are removed with it. The inspected application does not currently create separately stored server-side exports. A file already downloaded to a user's device is outside Kaption's control and must be deleted by the user. Future processors must register separately stored subtitles, transcripts, exports and temporary files so the same project-deletion cascade includes them.
If an expected deletion control is unavailable, email privacy@kaption.inwith enough information to identify the account and item. Do not send a password. Kaption may verify the requester's identity and authority before acting.
Deletion may be limited or delayed where data must be retained for a legal obligation, transaction record, security investigation, active dispute, fraud prevention or another permitted purpose. Any retained copy should be restricted to that purpose.
The configured cloud-storage lifecycle schedules uploaded project files for deletion after 30 days. Project records also store an expiry time based on that period.
This automatic lifecycle is configured on the primary upload bucket and is a backstop, not a substitute for a user-requested deletion. Separate output or temporary buckets, if configured, are included in the user-requested deletion process but no unverified automatic retention schedule is claimed for those buckets.
Users should download completed outputs and keep their own source backups before the retention period ends. A file may be removed sooner when the user deletes the project, when necessary to enforce the service rules, or when required by law.
The inspected application uses measures including password hashing, authenticated API routes, signed session tokens, ownership checks for project access and deletion, controlled upload and download links, file-type and size validation, and provider access credentials kept in server-side environment configuration.
Kaption should combine technical measures with limited staff access, secure configuration, software updates, monitoring, incident response and appropriate provider controls. No method of internet transmission or storage is completely secure.
This policy does not claim end-to-end encryption, ISO 27001, SOC 2, or any other certification or security property that has not been technically verified.
If Kaption becomes aware of a suspected personal-data breach, it should investigate, contain the incident, preserve relevant evidence, assess the affected data and people, correct the cause where practicable, and document the response.
Kaption should notify affected people and the appropriate authority when and within the time required by applicable law. A notice may explain what happened, the likely effect, steps taken and practical steps a person can take. This policy does not invent a fixed notification deadline where the applicable requirement has not been established.
Depending on the law that applies and the circumstances, a person may have rights to know about processing, access personal data, obtain information about recipients, correct inaccurate or incomplete data, request erasure, withdraw consent, object to or restrict certain processing, obtain a copy in an available format, nominate another person where law provides, or raise a grievance with Kaption or an appropriate authority.
Rights are not absolute. Kaption may need to verify identity, authority and account ownership and may refuse or limit a request where the law permits or requires it. Kaption should explain a refusal unless legally prohibited from doing so.
Submitting a Privacy Request
Signed-in users can submit and track requests directly inside Account Settings > Privacy & Data. If you cannot sign in, submit a request or track progress via the public fallback channel at Privacy Request Portal.
To request access, email privacy@kaption.in from the account email where possible. Describe the account and the information sought. Kaption may ask for reasonable proof of identity and clarification to avoid disclosing information to the wrong person.
A response may include available account data, relevant processing purposes, provider or recipient categories, retention information and a copy of eligible personal data, subject to other people's rights and lawful exceptions.
Users should update editable account information through available settings. If information cannot be corrected there, email privacy@kaption.in and identify what is inaccurate or incomplete and the requested correction.
Kaption may verify the request and, where appropriate, correct its records and notify relevant processors. Correcting an AI-generated transcript or caption may require the user to edit or regenerate the output because it is a generated project result rather than verified identity data.
A person may request erasure of eligible personal data by using available project controls or emailing privacy@kaption.in. State whether the request concerns an upload, output, project, communication or the entire account.
Kaption may retain limited information where necessary for legal compliance, accounting, fraud prevention, security, disputes or the rights of others. Information in an active team workspace may also require confirmation of the requester's role and the organisation's instructions.
Where Kaption relies on consent, the person may withdraw it by using the relevant setting or contacting privacy@kaption.in. Withdrawal applies going forward and does not invalidate processing that was lawful before withdrawal.
If the requested service cannot work without the relevant data, withdrawal may require Kaption to stop that processing, remove the associated feature or close the affected account or project. Other permitted or legally required processing may continue.
Privacy grievances can be sent to grievance@kaption.in. Include the account email, a clear description of the issue, relevant dates, the requested resolution and any useful evidence. Do not send passwords or unnecessary sensitive files.
Kaption should acknowledge, investigate and respond through the contact channel provided, subject to identity verification and applicable legal timelines. Full instructions and the grievance contact are available on the Contact and Grievance page.
A signed-in user can open Account settings, choose Delete account, receive a six-digit code at the account email address, and type DELETE to confirm. Email verification is the recent-authentication step for both password accounts and Google sign-in accounts. The server also requires a one-time security token bound to the deletion challenge and an idempotency key.
When a verified request is accepted, Kaption marks the account as deletion pending and increments its session version. Existing signed sessions and access tokens then stop working, and normal or Google login is refused. Kaption queues all projects and registered uploaded, generated and temporary files through the ownership-checked storage deletion process, asks Cashfree to cancel an active subscription, and sends a confirmation containing a unique deletion reference.
After the required provider steps are confirmed, Kaption replaces the account email with a non-deliverable deletion address, removes the profile name, resets preferences, replaces the password hash and marks the account deleted. A one-way hash of the former email may be retained to prevent the deleted account from being used to sign in or silently recreated. Kaption does not currently persist user API tokens; if such tokens are introduced, they must be revoked by this workflow.
Kaption targets account deletion within 30 days, while provider-managed backups and records retained for law, accounting, security, fraud prevention or disputes follow their applicable schedules.
Invoices, tax records, payment references, fraud-prevention or security records, unresolved grievances and records subject to a legal hold may remain restricted for the required purpose. The deletion-request record retains its reference, user identifier, status, attempts, timestamps and failed system scopes, but not the readable verification code or password. Provider or administrator-managed backups are not represented as being deleted instantly because their actual expiry schedule is not configured in this codebase.
Kaption is intended for people aged at least 18. A person below that age must not create an account or use the service.
Users must take special care before uploading media containing children and must have every lawful permission required for that processing. If you believe an ineligible child created an account or supplied personal data, contact privacy@kaption.in so Kaption can investigate and take appropriate action.
Kaption may update this policy when the product, providers, data practices or applicable requirements change. The effective and last-updated dates shown at the top identify the current version.
If a change materially affects how personal data is used, Kaption should provide an appropriate additional notice through the service, account email or another reasonable channel and obtain consent where law requires it.
- Privacy requests
- privacy@kaption.in
- Grievances
- grievance@kaption.in
- General support
- support@kaption.in
- Website
- https://kaption.in
Use the Contact and Grievance page for the grievance process. Cookie and browser-storage information is available in the Cookie Policy.
Registered address: Pavan City Complex, Modasa, Gujarat, India.
Contact
Privacy questions or requests
Contact Kaption's privacy channel to ask about this policy or exercise a privacy right.
- Business
- Kaption (operated by Yagna Patel as an individual)
- Registered address
- Pavan City Complex, Modasa, Gujarat, India
- privacy email
- privacy@kaption.in
- Grievance contact
- Yagna Patelgrievance@kaption.in