Skip to content

Privacy Policy

Last updated: September 2026

Overview

Captio provides live translated captions as a web service. This policy describes what data we collect, how we store it, and how long we keep it.

Session Transcripts

What is stored

When a host enables the “Save session transcripts” setting, Captio stores the text of what was spoken during a session, along with translations into any target languages selected by the host. No audio is ever stored. Only the transcribed text is retained.

Data location

Transcript files are stored on Cloudflare R2 in the European Union region. Session metadata (timestamps, language selections) is stored in our Supabase Postgres database, also in the EU.

Retention periods

Transcript files are automatically deleted after the following periods, based on your plan:

  • Starter plan: 30 days
  • Growth plan: 90 days
  • Pro plan: 1 year (365 days)
  • No active subscription: 30 days

Hosts can also set a shorter retention period in their organization settings. Transcripts are purged automatically each night.

How to delete

Hosts can delete any individual session transcript at any time from the Sessions page in their dashboard (Sessions → [session] → Delete). Deletion is immediate and permanent.

To delete all transcripts or close your account entirely, email us at privacy@captio.dev. We will process your request within 30 days.

Audience members

Audience members do not have accounts. We store no personal data about audience members. The only client-side state is a cookie that remembers their preferred caption language — this cookie never leaves their device. The providers that deliver captions and report errors (Ably and Sentry, listed below) process connection metadata such as IP address in the course of doing so. Aggregate visit statistics are measured as described under Analytics below; they carry no identifier for the reader.

Authentication data

Host accounts are authenticated via magic link or Google OAuth, managed by Supabase Auth. We store your email address and session tokens. No passwords are ever stored. You can delete your account at any time by emailing privacy@captio.dev.

Analytics

We use Vercel Web Analytics and Vercel Speed Insights to count page views and measure how fast pages load. Both are cookieless: they set nothing on your device, assign no visitor ID, and do not follow you across other websites. What they record is the page address, the referring site, an approximate country, and your device, browser and operating system type.

Caption text is never sent to them — neither tool reads page content. Page addresses are filtered before they are reported: sign-in links and any other credentials in the address are removed, and our own internal pages are excluded entirely.

Service providers

We rely on the following providers to run the service. Each processes only the data needed for its purpose.

  • Supabase — database and authentication (host accounts, sessions, glossaries, billing ledger). EU region.
  • Vercel — hosts the website and dashboard; also analytics as described above. EU region for server code.
  • Hetzner — runs the audio processing worker. Finland.
  • LiveKit — carries the host's live audio from browser to worker. Audio is not recorded.
  • Deepgram — converts speech to text.
  • DeepL — translates caption text and stores host glossaries.
  • Ably — delivers captions to audience devices.
  • Cloudflare — DNS, CDN, and transcript file storage (R2, EU jurisdiction).
  • Upstash — short-lived cache of translated phrases.
  • Stripe — payments. We never see or store card numbers.
  • Resend — sends account emails such as payment notices.
  • Sentry — error reporting for the website and worker.

Contact

Questions about your data? privacy@captio.dev