Privacy model

CapyRoute privacy notice

Data we need

We process account email, password hash, verification and recovery state, opaque sessions, registered device public keys, entitlements, activation source, support correspondence, and security audit events.

VPN operations

Nodes report aggregate load, peer counts, and byte totals associated with short-lived leases so CapyRoute can enforce allowances, operate capacity, diagnose connection categories, and prevent abuse.

Data we do not collect

We do not collect browsing history, visited URLs, DNS history, packet contents, or destination traffic logs. Access Mode nodes enforce a signed allowlist, but do not create a history of which supported website a person used.

Retention and rights

Short-lived replay and recovery data is removed automatically. Privacy-safe analytics and node samples use limited retention; security and commercial audit records are kept only as required for fraud, accounting, and legal obligations. Contact privacy@capyroute.com for access, correction, deletion, or objection requests.

International service

Providers may process data in the region needed to operate the service. CapyRoute will publish the operating legal entity, subprocessors, and jurisdiction-specific rights before accepting public customers.