Legal Center
Subprocessors
This list reflects what the codebase actually calls out to as of the date above (docs/LEGAL-BETA-INVENTORY.md). Location and formal Data Processing Agreement status for each vendor still need confirmation.
App appearance preference
The System, Light, or Dark app appearance choice is first-party state stored in Kaptly's account database and, for signed-out fallback, in the browser. Choosing or resolving a theme does not call a subprocessor or send the preference to a third party.
AI document import
Vendor: Anthropic. Data shared: text extracted from a document you upload to auto-generate form fields (only when this feature is used). Location / DPA status: [CONFIRM].
Owner-directed Slack delivery
Service: Slack, selected and configured by the form owner. Data shared: only the resolved plain-text automation message; it can include respondent answers, hidden URL values, score, or price only when the owner puts those references in the template. A blank template sends the owner-facing form name only. Kaptly uses no Slack OAuth connection and cannot browse the workspace or channels.
The incoming-webhook URL is stored in plain text with the form, version snapshots, and database backups. Slack controls who can read delivered messages and how long they remain. Location, DPA status, controller/processor roles, and retention are governed by the owner's relationship and workspace configuration with Slack and require separate legal review; Kaptly does not invent those facts.
Error monitoring
Vendor: Sentry (Functional Software, Inc.). Data shared: technical details of application errors — the error message, the stack trace, the URL path, the HTTP method, and the account id of the signed-in user where there is one. Purpose: to detect and fix faults that would otherwise go unnoticed, such as a submission failing to save.
Form answers, uploaded files, cookies, session tokens, request headers, query strings, email addresses and IP addresses are removed before any report is sent. Error monitoring does not run on public form or embed pages, so nothing is collected from respondents' browsers. Location / DPA status: [CONFIRM].
Payment processing
Kaptly does not integrate with any payment processor directly — no API keys, checkout sessions, or webhooks connect Kaptly to a payment provider's servers. The payment field is a plain link the form owner supplies to a provider of their own choosing (Stripe, PayPal, Gumroad, or similar); Kaptly only stores that link, not any data about the resulting transaction. See the Payment Feature Notice for how the field works.
Transactional email
Vendor: Google, via SMTP on a personal Gmail account (support@getkaptly.com itself is a separate Titan/Hostinger-hosted mailbox; outbound sending currently relays through the Gmail account, not through that mailbox's own servers). Data shared: recipient email address and message content for password resets, response notifications, and automation emails. Location / DPA status: [CONFIRM — a personal Gmail account has no separate business Data Processing Agreement in place; whether to move to a dedicated transactional-email provider is still open.]
Fonts
Vendor: Google Fonts. Data shared: visitor IP address and browser info when a form loads a custom font (fonts are fetched live, not self-hosted). Location / DPA status: [CONFIRM].
Sign-in prompt
Vendor: Google (One Tap / Google Identity Services). Data shared: visitor IP address and browser info whenever the Kaptly sign-in or sign-up page loads — the script runs before any visitor action, so this happens whether or not the prompt is used. It no longer loads on the home page or any other public page. If you do use it, Google returns your account identifier, name, email address and profile picture to Kaptly. Location / DPA status: [CONFIRM].
Analytics
Vendor: Google (Google Analytics 4). Data shared: visitor IP address (anonymised), browser info, and which Kaptly pages were visited — but only after the visitor accepts the cookie banner. Decline, or simply don't answer, and the script is never loaded, so Google receives nothing. Never active on public form pages (/f/…) or embedded forms. Advertising and personalisation signals are disabled. Location / DPA status: [CONFIRM — Google Analytics has its own Data Processing Terms that need to be accepted in the GA property's admin settings.]
Spam protection
Vendor: Google reCAPTCHA. Data shared: visitor IP address, browser info, and interaction data on forms where it's enabled. Location / DPA status: [CONFIRM].
Hosting / infrastructure
Vendor: [CONFIRM HOSTING PROVIDER]. Data shared: the full application database and uploaded files (all account, form, and response data resides here). Location / DPA status: [CONFIRM].
Donations / support
Vendor: Ko-fi. Data shared: whatever a supporter enters directly into Ko-fi's own checkout (Kaptly does not receive payment details) — this is separate from Kaptly's own product and covered by Ko-fi's own policies.