Effective date: August 2, 2026 · Last updated: August 2, 2026
This Privacy Policy (the "Policy") describes how Cape ("Cape," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information in connection with the Cape website, applications, integrations, and related services (collectively, the "Services"). This Policy forms part of, and is incorporated by reference into, our Terms of Service.
By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not access or use the Services. Capitalized terms not defined in this Policy have the meanings given to them in the Terms of Service.
Where Cape determines the purposes and means of processing personal information, Cape acts as a "controller" (or equivalent) under applicable data protection laws. Where Cape processes personal information on behalf of and under the documented instructions of a business customer, Cape acts as a "processor" or "service provider," and the applicable customer agreement or data processing addendum governs that processing to the extent of any conflict with this Policy.
We collect information you submit to us, including your name, work email address, job title, employer, stated use case, referral source, and any information you include in communications with us or in waitlist, support, or account registration forms.
If you elect to connect a third-party account — such as Gmail, Slack, LinkedIn, HubSpot, Crossbeam, or Google Sheets — you authorize Cape to access that account solely within the scope of the permissions you grant at the time of authorization. You may revoke that authorization at any time as described in Section 7.
With respect to email and messaging accounts, and subject at all times to Section 3, Cape derives and retains only limited relationship metadata, which may include:
This metadata is used to construct the relationship graph that powers the Services. Except as expressly permitted under Section 3, Cape does not retain the subject lines, body text, message contents, or attachments of your email or messaging communications.
When you use the Services, we automatically collect technical and usage information, including IP address, browser and device type, operating system, referring URL, pages viewed, features used, session duration, and timestamps. We and our service providers may use cookies and similar technologies to operate, secure, and improve the Services, and to measure their performance.
We may receive business-contact and firmographic information from third-party data providers and publicly available sources, and may combine that information with information we hold in order to improve the accuracy and completeness of the relationship graph and opportunity recommendations.
This Section 3 governs and, to the extent of any inconsistency, controls over any other provision of this Policy with respect to the contents of your email and messaging communications.
By default, and unless and until you provide the consent described in Section 3.2, Cape does not store, retain, persist, archive, log, index, or otherwise create a durable copy of the verbatim contents of your emails, including message bodies, subject lines, quoted text, and attachments.
To generate the metadata described in Section 2.2, message content may be transmitted to and processed by Cape's systems on an ephemeral, in-memory basis. Such processing is limited to what is strictly necessary to derive that metadata, and the underlying content is discarded upon completion of processing and is not written to durable storage.
Cape will store the verbatim contents of your emails only where you have provided prior, specific, informed, and freely given consent through an affirmative opt-in action. Any such consent will:
Upon revocation of consent, Cape will cease the consent-based storage and will delete or irreversibly de-identify the affected stored content in accordance with Section 8, except where retention is required by applicable law.
Notwithstanding Sections 3.1 through 3.3, Cape may access or temporarily retain message content without separate consent only where strictly necessary to: (a) comply with a binding legal obligation, subpoena, court order, or lawful governmental request; (b) investigate, prevent, or take action regarding suspected fraud, security incidents, or violations of our Terms of Service; or (c) respond to a support request that you initiate and in which you voluntarily furnish the content in question. Any such access will be limited in scope and duration to the purpose that justifies it.
Cape uses the data you connect exclusively to help you find and act on opportunities. Specifically, we process personal information for the following purposes:
We will not process your connected data for any purpose that is materially different from, or incompatible with, the purposes set out in this Section 4 without first providing you notice and, where required by applicable law, obtaining your consent.
For the avoidance of doubt, Cape does not:
Where the General Data Protection Regulation ("GDPR"), the UK GDPR, or a comparable framework applies, we rely on the following legal bases: (a) performance of a contract, to provide the Services you have requested; (b) legitimate interests, to secure, support, and improve the Services, where those interests are not overridden by your rights and freedoms; (c) consent, for the storage of verbatim email contents under Section 3.3 and for any non-essential cookies or marketing communications; and (d) compliance with a legal obligation, where processing is required by law. Where we rely on consent, you may withdraw it at any time.
We disclose personal information only in the following circumstances:
You may at any time disconnect any third-party integration, revoke the permissions you have granted to Cape through the relevant provider's account settings, withdraw any consent given under Section 3.3, or request deletion of your account and associated data.
Subject to applicable law, you may also have the right to: request access to the personal information we hold about you; request correction of inaccurate or incomplete information; request deletion or erasure; request restriction of, or object to, certain processing; request a portable copy of information you provided to us; and not be subject to unlawful discrimination for exercising these rights.
To exercise any of these rights, contact us at hello@joincape.ai. We will respond within the period required by applicable law. We may need to verify your identity before acting on your request. If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority.
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Relationship metadata is retained for the duration of your account and is deleted or irreversibly de-identified within a commercially reasonable period following account termination or a valid deletion request. Any verbatim content stored under Section 3.3 is retained only for the period disclosed to you at the time of consent and is deleted promptly upon revocation of consent or account termination, whichever occurs first.
We implement and maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit and at rest, access controls limiting internal access to personnel with a legitimate business need, and periodic review of our security practices. No method of transmission or storage is completely secure, and we therefore cannot guarantee absolute security.
Cape is based in the United States, and personal information we process may be transferred to, stored in, and processed in the United States or other jurisdictions whose data protection laws may differ from those of your jurisdiction. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we implement an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required.
The Services are intended for business use by individuals who are at least 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will delete it promptly.
We may update this Policy from time to time. If we make a material change — including any change that would expand the categories of data we retain or the purposes for which we process it — we will provide notice through the Services or by email before the change takes effect, and, where the change concerns the storage of verbatim email content, we will obtain your consent as required under Section 3.3. The "Last updated" date at the top of this Policy indicates when it was last revised.
If you have questions, concerns, or complaints about this Policy or our privacy practices, contact us at hello@joincape.ai.