Privacy model
CapyRoute privacy notice
Effective July 26, 2026 · review before public launch
Data we need
We process account email, password hash, verification and recovery state, opaque sessions, registered device public keys, entitlements, activation source, support correspondence, and security audit events.
VPN operations
Nodes report aggregate load, peer counts, and byte totals associated with short-lived leases so CapyRoute can enforce allowances, operate capacity, diagnose connection categories, and prevent abuse.
Data we do not collect
We do not collect browsing history, visited URLs, DNS history, packet contents, or destination traffic logs. Access Mode nodes enforce a signed allowlist, but do not create a history of which supported website a person used.
Retention and rights
Short-lived replay and recovery data is removed automatically. Privacy-safe analytics and node samples use limited retention; security and commercial audit records are kept only as required for fraud, accounting, and legal obligations. Contact privacy@capyroute.com for access, correction, deletion, or objection requests.
International service
Providers may process data in the region needed to operate the service. CapyRoute will publish the operating legal entity, subprocessors, and jurisdiction-specific rights before accepting public customers.