Privacy Policy
Last updated: 2026-05-20 · Effective: TBD
1. Who we are
CapitalSource.ai operates the CapitalOps platform and the CSG-1003 reference implementation. This policy describes how we handle personal information collected through the service.
2. What we collect
- Account data: name, email, organization, role, authentication via Clerk.
- Applicant data: CSG-1003 fields you submit, including business and personal-guarantor information.
- Usage data:
usage_eventsledger entries, request logs, audit events, billing reconciliation traces. - Operational telemetry: error reports, performance metrics, and structured logs with
request_id,org_id,user_idcontext.
3. How we use it
We use applicant and account data solely to deliver the service: running the agent workforce, certifying packages, and operating the usage ledger. We do not sell personal information. We do not use customer-tenant applicant data to train third-party LLMs; provider integrations run with no-train headers where the provider supports them.
4. Sub-processors
Stripe (payments), Clerk (authentication), DigitalOcean (hosting and storage), Anthropic and OpenAI (LLM providers, gated via lib/ai/router.ts). The full sub-processor list will publish at GA.
5. Retention
Application records and audit logs are retained for the duration of the customer relationship plus seven years for regulatory compatibility, then purged. Tenants may request earlier deletion subject to legal-hold exceptions.
6. Your choices
Export and deletion are handled manually today — there is no self-serve export endpoint and no erasure endpoint. An account owner emails privacy@capitalsource.ai from the address on the account; we confirm the request, assemble the organization's records, and return them in a machine-readable form. We aim to complete access and portability requests within 30 days and deletion requests within 30 days of confirmation, subject to the retention exception in section 5. When self-serve export ships, this section will name the endpoint.
7. Security
See /security for the technical controls we enforce in code.
8. Contact
Questions or requests: privacy@capitalsource.ai.