01.Who We Are
CapBrief is operated by Two Cores Operations Ltd, a company registered in England and Wales. We are the data controller for the personal data described in this policy, which covers the CapBrief service at roundbrief.com.
If you have any question about this policy or your data, reach us through the contact page.
02.What We Collect
We collect only what the service needs to run:
- Account data. Your email address and password when you create an account, plus an optional company name. Passwords are handled by our authentication provider and are never visible to us.
- Cap table and shareholder data. The CSV files you upload and any corrections you make in the app: shareholder names, share counts, share classes, investment amounts, and dates. You control this content, and we process it only to produce your briefs and reports.
- Branding assets. If you use white label features, the logo, company details, and accent colour you provide for your exports.
- Payment data. Payments are processed by Stripe on its own checkout pages. We store your Stripe customer reference and subscription status. Your card details never touch our servers.
- Usage data. We use Google Analytics 4 to understand how the site is used: pages visited, device type, and approximate location derived from your IP address.
- Newsletter email. If you subscribe to The Brief in the site footer, we collect the email address you enter.
- Contact messages. If you use the contact form, we collect your name, email address, and message so we can reply.
03.How We Use Your Data
We use account and cap table data to provide the service you signed up for (performance of a contract). The shareholder data you enter is processed only to produce your briefs and reports. It is never sold, shared for advertising, or used for any purpose beyond generating your output and operating the service.
We use usage data to keep the site working, improve it, and protect it from abuse (legitimate interests). We send the newsletter only if you subscribed (consent), and you can unsubscribe at any time. Contact messages are used solely to answer your enquiry.
04.AI Processing
To detect columns and infer missing details such as share classes, rows from your uploaded CSV are sent to Anthropic's Claude API for processing. The results come straight back to your session. Your cap table data is not used to train AI models.
05.Third Parties We Rely On
We share data only with the service providers that run CapBrief, and only so they can perform their function for us:
- Supabase: database, authentication, and file storage for your account and reports.
- Stripe: payment processing for subscriptions and one time purchases.
- Netlify: website hosting, and form handling for newsletter signups.
- Google Analytics: aggregated usage statistics.
- Anthropic: AI processing of uploaded cap table rows, as described above.
- Resend: email delivery for contact form messages.
Some of these providers process data outside the UK. Where they do, transfers are protected by recognised safeguards such as adequacy decisions or standard contractual clauses.
06.Cookies
We use essential cookies to keep you signed in to your account, and Google Analytics cookies to measure site usage. We do not use advertising cookies.
07.Retention
We keep your account data for as long as your account is open. Reports, uploaded cap table data, and branding assets are kept until you delete them or close your account, at which point they are removed. You can delete any report from the app at any time.
Demo sessions created without an account expire automatically after around two hours. Newsletter emails are kept until you unsubscribe. Contact messages are kept only as long as needed to handle your enquiry.
08.Your Rights
Under UK GDPR you have the right to access the personal data we hold about you, to have it corrected, and to have it deleted. You can also ask us to restrict processing, object to processing, or provide your data in a portable format.
To exercise any of these rights, contact us through the contact page. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) in the UK.
09.Security
Data is encrypted in transit and stored with row level access controls, so your reports and cap table data can only be read by your own account. Access to production systems is limited to what is needed to operate the service.
10.Changes to This Policy
If we change this policy, we will post the updated version on this page with a revised date at the top. If a change materially affects how we handle your data, we will take reasonable steps to bring it to your attention.