Privacy Policy
Effective August 19, 2026
Who we are
Kape Tools (kape.tools) is a workspace operated by BrewedOps (Kenneth Villar), based in Quezon City, Philippines. For this policy, BrewedOps is the personal information controller under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations. Questions and data requests: [email protected].
What we collect
- Account data - your email address (which is also your sign-in name), display name, hashed password (scrypt; we never store or see the plain password), whether your email has been confirmed, account dates, plan and access status. Accounts created before August 16, 2026 may also still carry the dates of a signup trial from when this product offered one.
- Google sign-in data - if you continue with Google, Google sends us your email address, whether Google has confirmed it, your name, and a Google account identifier which we store to recognise you next time. That identifier is internal to us and is never shown to other members or included in anything the app sends to your browser. We ask Google for nothing else: no contacts, no Drive, no calendar, and no profile picture. We do not receive or store a Google password, and we do not keep a token that would let us reach your Google account later.
- Account email tokens - when you confirm your address or reset your password, we store a one-way hash of the link's token with an expiry (24 hours for confirmation, 1 hour for a reset). The token itself only ever exists in the email we send you, and each link works once.
- Waitlist data - the email address and feature interest submitted on the old waitlist form. That form closed on August 19, 2026 and nothing new is collected, but addresses given before then are still held.
- Content you create - task boards, sheets, lead searches and results, notes, chat messages in the global chat (visible to other logged-in members), music playlists and library items.
- AI tool inputs - text and files you submit to AI features are processed to generate the output you asked for.
- Upgrade requests - if you ask to go Premium, the name, email and note you type on that form, and the payment screenshot you upload as proof. The screenshot is stored in our object storage and is readable only by the operator reviewing it. We do not ask for, receive or store card numbers, bank credentials or e-wallet logins - the payment itself happens entirely in your own bank or wallet app.
- Technical data - IP address and basic request logs (used for security and rate limiting), and a session cookie.
File tools (PDF, image compressor, converter, background remover, screenshot-to-text) run entirely in your browser - those files are never uploaded to our servers.
Why we process it (purpose and legal basis)
- To provide the service you signed up for - accounts, sign-in, your saved work (contract).
- To send the account emails the service cannot work without - confirming your address, resetting your password, and telling you about attempted signups on your address (contract). These are transactional, not marketing, so they have no unsubscribe link; closing your account stops them.
- To confirm you control the address you signed up with, and to refuse throwaway/disposable mail domains (legitimate interest in preventing abuse).
- To sign you in with Google when you choose to, and to recognise the same Google account on later visits (contract). Choosing that button is what starts it - the site contacts Google only when you press it.
- To have told the waitlist when access opened, which has now happened - the one purpose the email was given for (consent; withdraw any time, and reply to any of our mail to be removed).
- To keep the service secure - rate limiting, abuse prevention, access control (legitimate interest).
- To operate paid access - marking accounts paid and setting access periods (contract).
- To check an upgrade request against the payment it claims, and to keep a record of what was granted and why (contract; and our legitimate interest in an accurate record of money received).
We do not sell personal data, run ads, or use third-party advertising trackers. We do not send marketing email to your account address unless you ask us to.
Who processes data for us
We share data only with processors needed to run the service:
- Anthropic (Claude API) - powers the AI writing tools and KapeAI. Your AI inputs and outputs are processed by Anthropic to return results; under Anthropic's commercial API terms, they are not used to train models by default.
- Groq - transcribes the audio or video you submit to the Subtitle Generator. That file is uploaded to Groq for transcription and the text is returned to you. The other transcription tool (Audio Transcriber) runs in your browser and uploads nothing.
- Cloudflare - sits in front of the site (traffic proxy, caching) and stores some workspace content (boards, sheets, skills, music files) in Cloudflare R2 object storage.
- Resend - delivers our account emails (email confirmation, password reset). Resend receives the recipient address and the contents of that message, and nothing else about you.
- Hostinger - the virtual server in which the application and its database run.
These providers may store data outside the Philippines. Where data leaves the country, we rely on the providers' contractual data-protection commitments, consistent with the Data Privacy Act's accountability principle.
Cookies
bl_session, an HttpOnly session cookie that keeps you signed in for up to 30 days. If you sign in with Google, a second HttpOnly cookie bl_oauth is set for ten minutes to tie the round trip to Google back to the sign-in you started, and is deleted as soon as you return. No analytics or advertising cookies.
Retention
- Account data and your content - kept while your account exists. You can delete the account yourself at any time from the account menu, which removes it and the content it owns; we also action deletion requests sent to [email protected]. A short audit line recording that an account was deleted is kept afterwards, because it is the only remaining record the deletion happened.
- Account email tokens - the hashed confirmation/reset tokens expire in 24 hours and 1 hour respectively, and each is invalidated as soon as it is used or a newer one is issued.
- Unconfirmed signups - an account whose email is never confirmed cannot sign in; tell us and we will remove it.
- Waitlist emails - kept until launch outreach is done or you ask us to remove yours.
- Global chat - only the most recent messages are kept; older ones are automatically deleted.
- Upgrade requests and their payment screenshots - kept while they are the record of a payment we acted on. Ask us and we will delete the screenshot once the membership it paid for has ended; deleting your account removes the request rows with it.
- Rate limiting and abuse counters - your IP address (IPv6 is shortened to a network prefix) is counted against short windows to stop password guessing and spam. A counter is deleted once its window closes, so nothing here is kept beyond about an hour, and no email address, username or message content is stored alongside it.
- Server logs and backups - rotated on a short schedule (backups are kept for 14 days). A backup taken at a given moment can contain the rate-limiting counters described above that were still open at the time.
Your rights under the Data Privacy Act
As a data subject under RA 10173 you may:
- Be informed about how your data is processed
- Access a copy of your personal data
- Correct inaccurate or outdated data
- Object to processing, or withdraw consent you previously gave
- Ask for erasure or blocking of data that is unlawful or no longer necessary
- Ask for your data in a portable, commonly used format
- Be indemnified for damages from inaccurate, incomplete, or unlawfully obtained data
- File a complaint with the National Privacy Commission (privacy.gov.ph)
Send any request to [email protected]. We respond within the timelines set by the NPC.
Security
Passwords are hashed with scrypt, sessions are HttpOnly cookies over HTTPS only, the database is not exposed to the internet, admin surfaces require an admin account, and requests are rate limited. If a breach is likely to harm you, we will notify you and the National Privacy Commission within 72 hours of knowledge, as the Data Privacy Act requires.
A plainer account of all this - which tools never upload anything, what the operator can see, and what stops us - is on the Trust and safety page.
Children
Kape Tools is a work tool for adults. It is not directed at children under 18, and we do not knowingly collect their data.
Changes
If this policy changes materially, we update the effective date above and note it on the sign-in page. Continued use after a change means the updated policy applies.