Some of you save very personal information, like medical information or journals in Capacities, while others work with important data from their company.
We built Capacities to be the place for all our thoughts, ideas, plans, and knowledge. We are aware of our responsibility and live up to it as best as possible. Because of that, we designed our infrastructure to be secure and private by default.
Here we share our principles on how we live up to these values.
Capacities is a cloud-based service with some upcoming offline capabilities. To follow our vision and to provide the best service possible we are convinced that storing data on servers is crucial. It allows us to make Capacities work across devices, and in the future, it will enable you to exchange content with other users in a global network or within a team. On top, having access to service and compute infrastructure that goes beyond what you can do on a single computer is a huge advantage for developing algorithms to support your work.
Like with any cloud-based service, the disadvantage of it is that you need to trust a company. We are aware of your concerns with this, so we defined principles that ensure that our interests are aligned with yours. We as co-founders of Capacities are personally very data-sensitive and well informed on that topic, we see these principles not as a necessary burden but as core values of our philosophy.
Let us explain them to you. But first, we need to define the involved objects to make sure there are no misunderstandings in the following. When it comes to data and data access we have the following agents:
That’s what we’re doing with this document and our privacy policy. If there is anything unclear with it, feel free to reach out to us.
We strictly protect all your data against any access from third parties. This is very crucial, not even our cloud provider can access your data. Only you, us, and Capacities could have access to your data. In reality, not even us, but only you and Capacities have access to your data (see Principle 5).
About the technicalities:
Although the data is stored on Capacities’ servers, we do not claim any ownership of it. We do not use your data for any other purpose than providing a service to you (see principle 4).
Owning your data means that you always have access to it. Having access does not only mean that you can see, use and create it but that you can also at any point export it into commonly used formats. To read more about this read about exports and backups.
Capacities is GDPR compliant. The General Data Protection Regulations are among the highest data protection laws in the world. They are the foundation for data rights for all citizens in the European Union. At Capacities, we give these rights not only to them but to all of our users globally.
These regulations are based on well-reasoned principles that we think are fundamental for a society of free and self-determined human beings in a digital world. It’s really hard to comply with these regulations and as a company, we lose a lot of insight that we otherwise could simply use to create a better product, but we are convinced that this is fundamentally important, and we would like to see any tool that in any way processes information to be GDPR compliant.
A central aspect of the GDPR are regulations on processing personal identifiable information (PII), which is data that can or even could be mapped back to a user. The opposite is fully anonymized data, where it’s impossible to determine its creator.
PII should only be created and stored if it is required for the service provided and only as long as it is required (Principle of Data Minimization). If PII is used for other purposes the user needs to actively agree to that.
At Capacities, we decided to not share any tracking PII with other service providers. For example, we only do the following analytics:
Other than that, you need to consent before Capacities can share any of your information. This only happens in the following two places:
See more on that in our privacy policy.
The only reason Capacities collects and reads your data is to provide services to you. Our business model is fully transparent. We only earn money by providing a paid version with an extended feature set to the free version (more under Pricing). We will never use any of your data for advertisement or any other purposes nor will we ever sell your data for any money.
Your personal data can only be accessed by Capacities through a verified account with your login credential. We created a very strict and secure policy and permission system that is regularly tested. The only exception for extended access rights is if you in the app decide to share your content. But even then it will only be accessible to users you share that content with.
Like with any cloud based service you use, in theory, we at Capacities could access, read and manipulate your data because it is stored on our servers. A few words about why this should not be a concern to you: First of all, as outlined above we do not by any means have any interest to get access to that data, our business model is based on providing a service to you. We would only destroy your trust which would only harm us.
To ensure that reading your data cannot even happen by accident, we put a few mechanisms in place. Our production environment (the servers where your data is stored) is completely isolated from our development. So in everyday work we don't even get close to any of your data (they are different physical machines). The only way that the production environment can be accessed is from only one of our computers with a password-protected secret key. And even if we accessed that environment all services would be containerized and they would only communicate with each other. In plain English: Even if someone had access to that they would not read everyone's notes. It would require an infrastructure change and quite some technical effort and knowledge to get direct access to any of your data.
These measure and barriers were created by us intentionally to protect your data from any violation. They make our work more difficult but your data more secure.
Data protection and security are complex but very important topics. And we advise you to care about it for any service you use. We hope that this document helps you to have an informed decision on whether you want to use Capacities. You are storing data on our servers, we are aware of that responsibility and we promise to never violate our principles. What's life worth if you don’t even live up to your own personal principles? We are building Capacities because we have a vision and a dream. We don't want to destroy this dream for no reason. Our incentives are in line with yours and we hope this works for you.
Data Protection at Capacities
As a European company, we value your privacy and are committed to protecting it. Data protection isn't just a legal requirement for us—it's a core value that shapes how we build and operate Capacities.
Capacities Student Discount
Capacities grew out of our founders’ experience at university, where they saw how limited the tools for learning and thinking were. Before building Capacities, they spent years studying and trying to work within the systems they had, convinced there must be a better way. That experience shaped the way we design Capacities: a calm, focused space where you can think, learn, and create without distraction.