Privacy notice
Axivolt Tools LLC · last updated 30 September 2026
This page explains what Cap Engine stores about you, who else sees it, how long it is kept and how to have it deleted. It is written to match what the software actually does.
1. Who is responsible for your data
Cap Engine is operated by Axivolt Tools LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States, which is the controller of the personal data described here. For anything on this page — a question, a copy of your data, or a deletion — write to support@capengine.io.
We will ask you to confirm your identity before acting on a request about your own data, so that nobody else can exercise your rights for you. We have not appointed a data protection officer, because our processing does not meet the thresholds in Article 37 of the GDPR; the address above is the responsible route for everything in this notice.
Cap Engine is operated from Sweden, and it is offered to people and businesses across the European Union and the European Economic Area. Your personal data is therefore protected by the General Data Protection Regulation, and by the Swedish Data Protection Act, which supplements the Regulation in Sweden. Both apply to everything described in this notice.
2. Your account
Sign-in is handled by an outside authentication provider. It holds your name, your email address, your password or the social login you chose, which workspace you belong to and your role in it, and the times and devices you signed in from. Cap Engine itself keeps only the identifiers that provider gives it: one for you and one for your workspace. Those two identifiers are stamped on every record you save, so we can show your workspace its own work and nobody else's.
We also keep which plan your workspace is on and its billing status. Card details are handled by our payment processor and never reach our own systems.
3. Why we are allowed to use it
To give you the service you signed up for (Article 6(1)(b)): your account, your scans, the work you save, the lookups a scan needs, and billing. Without these there is no service.
Because we have a genuine interest in keeping it working and secure (Article 6(1)(f)): error reports, the limits that stop abuse, and the technical records below. We have weighed that against your interests and collect the least we can — no profiling, no advertising, and no automated decision-making that has a legal effect on you.
Because you said yes (Article 6(1)(a)): product analytics, and any marketing email. Where we rely on consent you may withdraw it at any time, and withdrawing it does not affect anything done before you did.
Because the law requires it (Article 6(1)(c)): invoices and the other records we must keep for the period tax and accounting law sets.
We do not collect special-category data under Article 9 of the GDPR, we do not ask for it, and Cap Engine has no field for it. Please do not upload documents containing it.
4. What you put into a scan, and what comes back out
A scan takes the product you are looking at and your own numbers — the price you expect, the order size, your supplier quote, freight and duty assumptions. When you save a scan, a project, an order-size plan, a capital plan or a research report, that input and the full result are stored in our database against your workspace, not against you personally. So is the stage a product is at, and any approval someone in your workspace signed. Anyone signed in to your workspace can see those records.
A scan is also cached for a short time so that repeating the same request does not cost a second paid call. The cache is keyed on the exact request and lives about a day.
Files you upload. Evidence you upload — a supplier quote, a freight rate card, a certificate, a company document — is stored in our database, file and all, together with its name, its type, its size and a checksum, plus who uploaded it and when. Files are not published anywhere and are readable only by your own workspace.
Reading a document for you. Some deployments offer to read an uploaded document so you do not have to type the figures in. When that is switched on and you use it, the file is sent to the model provider that runs the reader, and the figures it found come back for you to check and confirm. Nothing is applied to your scan until you confirm it. The result of a reading is cached so the same document is not paid for twice, and that cache is tied to your workspace: another customer who uploads a byte-identical file gets their own reading and never sees yours. Uploaded documents are not logged, and the reading is not used to train anybody's model. If the feature is switched off for your deployment, no document ever leaves our database.
Technical records. Your address on the network, your browser and device type, the pages you visited and when, and — where something failed — a diagnostic record of what failed.
5. Who else handles it, and what they do
A small number of service providers process personal data on our behalf, under written agreements that bind them to our instructions and to confidentiality. They fall into these categories:
- Hosting and infrastructure — running the web app, the calculation service and the database they both read and write.
- Authentication — verifying who you are when you sign in.
- Error monitoring — recording diagnostics when something fails, so we can fix it.
- Product analytics — only if you allowed it, recording which pages and controls you used.
- Payment processing — taking subscription payments.
- Email delivery — sending the messages the service owes you.
- Document reading — the model provider that reads an uploaded document, where that feature is switched on and you used it.
- Data providers — the commercial sources a scan queries: product-data providers for listing details, prices, ranks and reviews; search-result providers for who else sells the same thing; and freight-rate providers for shipping costs. These are asked about PRODUCTS, not about you. We send them the product identifier or the search words the lookup needs, and not your own figures, your files, your name or your workspace.
We name categories rather than companies because the set changes and a list pinned in a notice goes stale. You are entitled to know who they are: write to support@capengine.io and we will send you the current list, with the country each one processes in.
We do not sell personal data and we do not share it with anyone for their own purposes. We disclose it outside this list only where the law compels us to, or to a buyer as part of a merger or sale of the business — in which case we will tell you before it happens.
6. Sending data outside the EEA
Some of the providers in section 5 are established outside the European Economic Area, principally in the United States, so your personal data may be handled there.
Where that happens we rely on one of the safeguards Chapter V of the GDPR permits: an adequacy decision by the European Commission for the country or framework in question, or, where none applies, the Commission’s Standard Contractual Clauses together with a transfer impact assessment and technical measures such as encryption in transit and at rest. We will send you a copy of the relevant safeguard for any specific transfer on request, at the address above.
7. Analytics and error reports
Product analytics is optional. We ask before switching it on, and nothing is collected until you say yes. If you do, our analytics provider records which pages and controls you used. Session recording is off. Decline, and none of it runs; you can change your mind by clearing this site's data in your browser and choosing again.
Error monitoring is not optional, and here is why. When something breaks, our error-monitoring provider sends us the failure so we can fix it — that is the only way a problem you hit reaches us during a beta, and we think everyone is better served by us knowing. We treat it as necessary to keep the service working rather than as something to measure you with, so we strip it down before it is sent: no user or workspace identifier, no address of the device you are on, no cookies, no query strings, and anything that looks like a password or a key is blanked out. What is left is the error, the page it happened on, and the browser.
8. How long we keep things
- Projects, saved scans, plans, research, approvals and uploaded files stay until you or someone in your workspace deletes them, until you ask us to, or until 30 days after your workspace's account is closed. A saved calculation is an immutable record by design: changing an input creates a new one rather than editing the old one, so deleting a calculation deletes the record rather than amending it.
- Account records live with our authentication provider for as long as your account is open, and for 30 days after it is closed so that an accidental closure can be undone.
- Short-lived caches — the repeated-scan cache and the duplicate-request record — expire after about a day.
- A cached document reading is kept against your workspace so a re-read costs nothing, and goes when the workspace's data goes.
- Technical and diagnostic records are kept for 90 days, after which they are deleted or aggregated so that they no longer identify anyone. Analytics events, if you allowed them, are kept under the provider's own retention settings.
- Billing records are kept for the period tax and accounting law requires, which is longer than the periods above and which we cannot shorten at your request.
9. Your rights, and how to use them
Under the GDPR you have the right to:
- Access — be told whether we hold personal data about you and receive a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where one of the grounds in Article 17 applies.
- Restriction — have us stop using your data, while keeping it, in the cases Article 18 lists.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller where that is technically feasible.
- Object — object to processing we base on a genuine interest of ours, and at any time and for any reason to processing for direct marketing.
- Withdraw consent — where consent is the basis, withdraw it at any time.
Write to support@capengine.io and say what you want — a single file, a project, or everything. We answer within one month, and will tell you if we need the extension Article 12(3) allows and why. Exercising a right costs you nothing. When we delete, we delete your workspace's records and confirm when it is done; we may keep a minimal record that the request was made and met.
10. Complaining to a supervisory authority
If you think we have handled your personal data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority. Because Cap Engine is operated from Sweden, ours is Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, at www.imy.se.
You may complain to IMY, or to the supervisory authority in your own European Union or European Economic Area country — where you live, where you work, or where the thing you are complaining about happened. The list of national authorities is published by the European Data Protection Board.
You do not have to come to us first, and nothing in this notice or in our terms takes that right away. We would rather you told us too, at the address above, so that we can put it right.
11. Security
We encrypt data in transit and at rest, scope every stored record to one workspace and check that scope on every read, restrict administrative access to those who need it, and keep an audit record of access to uploaded evidence. No system is perfectly secure; if a breach occurs that is likely to risk your rights and freedoms, we will notify the competent supervisory authority within 72 hours and tell you where Article 34 requires it.
12. Changes to this notice
When we change this notice we update the date at the top of the page. Where a change materially affects how we use personal data we already hold, we will tell you by email before it takes effect, so that you can object or close your account first.