Privacy Policy
Last updated: August 17, 2026
Scope
This policy covers the Capydocs applications and the capydocs.com website. Capydocs is a local-first document editor and file manager. Your documents are stored on your device unless you choose an operating-system sharing feature or connect an optional cloud synchronization provider.
Capydocs ships separate Lite and Full desktop products for Windows and macOS. The paid Android and iOS product can optionally synchronize a local Vault with Dropbox, OneDrive, or Google Drive. Cloud synchronization is not required to use a local mobile Vault.
Desktop applications
The Windows Store and Mac App Store applications read and write the files and settings that you choose on your device. They do not upload your documents to Capydocs-operated servers.
Mobile cloud synchronization
When you connect Dropbox, OneDrive, or Google Drive, Capydocs synchronizes the local Vault with the remote folder that you select. Provider requests are sent directly from the installed app to that provider. Your document contents are not proxied through or stored on Capydocs-operated servers.
Google Drive data access
Google's consent screen grants Capydocs permission to view and manage files in your Google Drive. Capydocs uses the restricted https://www.googleapis.com/auth/drive OAuth scope.
Capydocs accesses the following Google user data:
- OAuth access tokens and, on platforms that provide them, refresh tokens.
- Folder and file metadata needed for synchronization, including names, Google Drive identifiers, parent relationships, file types, sizes, modification times, versions, checksums, revision metadata, and trash or removal state.
- Folder listings used by the in-app picker under the Capydocs Vault area.
- The Google Drive change feed. This feed can return identifiers and metadata for changes elsewhere in My Drive. Capydocs processes those entries only to determine whether they belong to the selected Vault tree and retains synchronization state only for that tree.
- File contents and relevant prior revisions inside the selected Vault tree when needed to download, upload, compare, or merge a synchronized file.
Capydocs does not request Google Contacts, Gmail, Calendar, Photos, advertising, or payment data through this permission.
How Capydocs uses Google Drive data
Capydocs uses Google Drive data only to provide and improve the user-facing, bidirectional Vault synchronization feature that you choose to enable. This includes:
- letting you browse, create, and select the remote folder used by a Vault;
- downloading remote files and folders into the local Vault;
- uploading local additions and edits to the selected Drive folder;
- detecting and applying remote additions, edits, moves, renames, and deletions;
- comparing metadata, checksums, and revisions to avoid unnecessary transfers and overwrites;
- preserving both versions when local and remote content changed independently; and
- keeping the local synchronization cursor and file-state catalog needed to resume safely.
The full Drive scope is required because the selected Vault tree can contain files created by Google Drive for desktop, drive.google.com, or another Drive client. The narrower drive.file scope covers files created by Capydocs or explicitly opened or shared with it, but it cannot provide reliable visibility into every independently created descendant needed for automatic folder synchronization. Although the OAuth permission covers Drive, Capydocs limits file-content operations to the Vault folder tree that you select.
Capydocs does not use Google Drive data for advertising, marketing, analytics, account licensing, credit decisions, lending, AI model training, or any unrelated product feature. Google Drive data is not combined with Google Sign-In data.
Google Drive data sharing and disclosure
Capydocs does not sell, rent, share, transfer, or disclose Google Drive user data to advertising platforms, data brokers, analytics providers, AI providers, or other third parties. Normal operation does not give Capydocs personnel access to your Drive files. We can receive a file only when you deliberately send it to support, and we use it only to provide the support you requested.
Drive data is exchanged only between your device and Google to provide synchronization. We may disclose information only if required by applicable law or when necessary to investigate a security incident, and only to the extent allowed by the Google API Services User Data Policy.
Capydocs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google Drive data protection
- Google Drive API traffic uses HTTPS encryption in transit.
- OAuth authorization uses platform-supported installed-app authorization. iOS uses authorization code with PKCE. Android uses Google Play services and binds authorization to the application package and signing certificate.
- OAuth tokens, pending authorization data, and provider connection metadata stored by Capydocs are encrypted at rest with AES-GCM using a random installation-local key. They are stored in the application's private local data, outside synchronized Vaults.
- Android stores only short-lived Google Drive access tokens. Other supported flows can store a refresh token locally so synchronization can continue after an access token expires.
- Tokens, authorization codes, PKCE verifiers, and document contents are not written to product analytics or application diagnostics. The local message history can contain a bounded provider error, synchronization phase, and Vault-relative path for troubleshooting. This history remains on your device and is not sent to Capydocs.
- Local document copies are ordinary files inside the app's local Vault and are protected by the device's application sandbox, access controls, encryption, passcode, backups, and other operating-system settings. Capydocs does not apply separate document encryption.
- Local synchronization metadata stores only the information needed to reconcile the selected Vault, such as relative paths, Drive item and parent identifiers, revisions, timestamps, sizes, and checksums. It does not store document contents or OAuth credentials in that catalog.
Google Drive data retention and deletion
Capydocs does not retain Google Drive user data on Capydocs-operated servers.
Local copies of synchronized documents remain in the local Vault until you delete those files or delete the Vault. Files in Google Drive remain there until you delete them under Google's retention rules. A synchronized deletion moves the corresponding Google Drive item to trash instead of permanently deleting it.
Disconnecting Google Drive removes the connection for that Vault. The encrypted Google credential is deleted from Capydocs after no local Vault remains connected to Google Drive. Disconnecting does not delete local files, remote files, or the non-secret local synchronization catalog, so you do not lose documents unexpectedly. Delete the local Vault or its files to remove retained local copies. Delete or empty trash in Google Drive to remove remote copies according to Google's controls.
You can also revoke Capydocs access from your Google Account's third-party connections page. Revocation stops future Drive API access but does not itself delete local or remote files. Uninstalling Capydocs removes its application data from the device subject to the operating system's backup and restore behavior.
Google Sign-In is separate
The optional Google Sign-In used on the Capydocs account website is separate from Google Drive synchronization. It uses basic account identity information for authentication and does not request Drive access. Google Drive contents, metadata, and tokens are never used to sign in, manage licenses, show products, or process purchases.
Website and updates
Capydocs web pages and update checks may request public resources from capydocs.com or id.capydocs.com. These requests do not include Google Drive files, metadata, or OAuth tokens.
Contact
For privacy questions or requests, contact [email protected].