Legal
Privacy Policy
NoCapped PBC, a Delaware Public Benefit Corporation
Effective September 14, 2026 · Version 1.1
This is the only privacy policy NoCapped PBC maintains. Part I applies to everyone. Part II has a section for each product, and only the section for the product you use applies to you.
The short version. We do not sell your personal data. We do not use your photographs to train AI models, and we never will without your explicit opt-in. We collect what we need to run the service and to file copyright registrations you ask us to file. You can get a copy of your data, correct it, or delete it by writing to legal@nocapped.com. The detail below matters, and we have tried to write it so it can actually be read.
Which sections apply to you
More than one may apply. Start with Part I, then read the section for each product you use.
-
Part I. All users
Sections 1 through 9. Applies to everyone, whether or not you have an account. Start here.
-
A. The Pinxt App
Photographs, metadata, GPS, C2PA credentials, copyright registration, and account data.
-
B. The Pinxt Website and Beta Waitlist
pinxt.app, the waitlist form, and the emails we send about the beta.
-
C. This Website, nocapped.com
The corporate site you are reading now.
Where a product section says something different from Part I, the product section governs for that product.
Part I
All users
Sections 1 through 9 apply to everyone, including visitors to our websites who do not have an account. Part I begins at Section 1 immediately below.
1. Who we are
NoCapped PBC is a Delaware public benefit corporation. Our corporate charter obligates our directors to balance the financial interests of stockholders against a stated public benefit: making it easier for visual artists to establish provenance, register copyrights, and defend their rights as creators. That is a legal obligation embedded in our company structure, not a marketing position, and it is the reason this policy reads the way it does.
NoCapped PBC is the data controller for all personal information described in this policy. We are not a law firm and do not provide legal advice. Any copyright registration services requested are facilitated as your authorized agent.
Contact: legal@nocapped.com. Postal address in Section 9.
2. Commitments that apply across every product
- We will never use your photographs to train, fine-tune, or improve any AI model without your explicit opt-in consent.
- We will never sell your personal data.
- We will never license, sell, or otherwise commercialize your photographs, and we will never authorize anyone else to, unless you have specifically authorized that use. Any licensing feature we build will be opt in and controlled by you: you decide which works are offered, on what terms, and you can withdraw a work at any time.
- We do not share your data for cross-context behavioral advertising, and we do not operate advertising SDKs.
- We preserve the metadata embedded in your files rather than stripping it.
- We honor machine-readable do-not-train and data mining declarations embedded in your image files, using the standards our pipeline supports, and we update that support as those standards change. Where a declaration in your file and your in-app setting differ, your in-app setting governs.
- When we act as your agent for a government filing, we will show the government fee and any NoCapped service fee as separate line items, and disclose both before you are charged. We do not inflate or obscure the government fee itself.
- We may introduce advertising or third-party analytics in a product in the future. If we do, we will update this policy before the change takes effect.
3. Your rights
Wherever you live, you can ask us to do the following. Write to legal@nocapped.com with the subject line "Privacy Request." We acknowledge requests within 10 business days and complete them within 45 days unless the law requires us to retain a record.
- Access. Get a copy of the personal data we hold about you.
- Correction. Correct inaccurate information.
- Deletion. Delete any account and any associated data we have retained about you, subject to the retention exceptions in the relevant product section. You do not need an account to make this request.
- Portability. Obtain your data in a portable form.
- Withdraw consent. Turn off anything you previously opted into.
California residents (CCPA and CPRA)
We do not sell or share your personal information as those terms are defined by the California Consumer Privacy Act, and we do not engage in cross-context behavioral advertising. No opt out is necessary because there is nothing to opt out of, but you may still submit a request and we will confirm this in writing.
If we introduce licensing features, any transfer of your work happens only at your direction and under terms you set, which is not a sale of personal information under the CCPA. We will update this section before that changes.
California residents also have the right to know, to delete, to correct, and to limit our use of sensitive personal information. GPS coordinates extracted from your photographs are sensitive personal information under the CPRA and are addressed in Section A.4. We will not discriminate against you for exercising any privacy right.
Other U.S. states
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights to access, correct, delete, and obtain a copy of their personal data. We honor those requests through the same process, and you may appeal a denial by replying to our response.
EEA, UK, and Switzerland
The Pinxt app launches in the United States only and is not offered in the European Economic Area, the United Kingdom, or Switzerland. Our websites are reachable from those regions. Where we process personal data of individuals there through our websites, our lawful basis is consent for analytics and marketing email, and our legitimate interest in responding to you for correspondence you initiate. You have the right to lodge a complaint with your local supervisory authority. We have not appointed an Article 27 representative, and will do so if and when we offer a product in those regions.
4. How we share information
We share personal information only in the circumstances below. Each product section names the specific service providers that apply to that product.
- Service providers. Vendors who process data on our instructions under written data processing agreements, and who may not use it for their own purposes.
- The U.S. Copyright Office. When you ask us to file a registration, your application data and deposit copies go to a U.S. government agency and become part of a permanent public record.
- Legal requirements. When required by law, court order, or lawful government request, or where necessary to protect the rights, property, or safety of NoCapped PBC, our users, or the public.
- Business transfers. If NoCapped PBC is acquired or merges, user data may transfer to the successor, along with our public benefit corporation obligations. We will give advance notice.
Each provider is bound by contract to protect your data to a standard at least equal to this policy. Where a provider acts as an independent controller for its own purposes, as a payment processor does, its own privacy policy governs that processing and we have confirmed its protections meet or exceed those described here.
5. Security
- Traffic between your device and our websites and app is encrypted in transit over HTTPS. Email is different: a message you send to one of our published addresses travels across the public internet and we cannot guarantee it is encrypted along the way. Please do not send sensitive information by email.
- Data stored with our cloud provider is encrypted at rest.
- Access is scoped so that no user can reach another user's stored content through the platform.
- Passwords are managed by our identity provider as cryptographic hashes. No NoCapped personnel can read them.
- We operate no AI training pipelines over user content.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any required regulator within the timeframes the law requires.
6. Retention
We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires. Specific retention periods appear in the product sections. Two categories are retained even after account deletion, and we want to be direct about why: U.S. Copyright Office registration numbers, because they point to a permanent government record that continues to exist whether or not you have an account with us, and financial transaction records, because tax and accounting law requires it.
7. Children
Our products require users to be at least 18 years old, and our websites are not directed at children. We do not knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we will delete the account and its data promptly. To report an underage account, write to legal@nocapped.com.
8. Changes to this policy
We may update this policy as the company and its products change. The effective date and version at the top of this page always reflect the current version. For changes that materially affect how we handle personal data in a product you use, we will give at least 30 days' advance notice by email and, for the Pinxt app, inside the app, before the change takes effect. Changes that affect only one product section will be described as such, so a change to our website analytics does not require you to re-read the app section.
If you do not accept a revised version, you may stop using the product and delete your account before the effective date.
9. Contact
NoCapped PBC
8 The Green, STE B
Dover, DE 19901, United States
Telephone (302) 251-1150
legal@nocapped.com
For Pinxt, legal@pinxt.app reaches the same inbox. Use legal@nocapped.com for DMCA notices, because it is the address on file with the U.S. Copyright Office.
Part II, Section A
The Pinxt App
Part I, Sections 1 through 9, applies to you as well. It covers our commitments, your rights, how we share information, security, retention, and how to reach us. This section adds only the detail specific to the Pinxt app, and does not replace Part I.
Status. The Pinxt app is in beta and is distributed to invited testers only, through TestFlight on iOS and through testing distribution on Google Play. This section takes effect for you on the date you first create a Pinxt account. Your use of the app is also governed by the Pinxt Terms of Service.
A.1 Account information
When you create a Pinxt account we collect your email address, your username, a password, an optional profile photo, and your confirmation that you are 18 or older. Credentials are managed through Amazon Cognito. We store a cryptographic hash, never the password itself.
A.2 Photographs and user content
We store your original image files at full resolution, along with smaller system-generated derivative versions used for display, created automatically at upload. We also store captions and other text you add, and the publication status and any first publication date you supply when registering a work.
Your images and their records are stored in the United States, in the AWS US East (Northern Virginia) region. Some parts of the service are delivered through a content delivery network, which keeps temporary cached copies on edge servers to make content load quickly. Those caches are transient, expire automatically, and are not a system of record.
Derivatives are served view-only. The platform does not offer a download control for other users' work, and our Terms of Service prohibit reproducing it by screen capture.
A.3 Photo metadata
We extract and store metadata embedded in your photographs, and we preserve it intact inside your original stored file. We do not strip or alter your embedded metadata. This includes:
- EXIF: camera make and model, lens, shutter speed, aperture, ISO, focal length, capture date and time, color space, orientation, and resolution.
- IPTC: copyright notice, creator name, caption, keywords, contact information, and rights usage terms.
- XMP: extended fields, including machine-readable data mining and AI training declarations.
We read the machine-readable data mining and AI training declarations embedded in your file, currently including the IPTC Photo Metadata Data Mining property, and we honor them. Where a declaration and your in-app setting differ, your in-app setting governs.
We may also check uploads for missing embedded metadata and reject files that appear to have had it stripped.
Technical metadata is shown to viewers by default, because craft context is part of what Pinxt is for. Other fields can be kept private in your settings.
A.4 GPS and location
Pinxt does not request your device's location permission and does not collect real-time location. The only location data we ever hold is GPS coordinates your own camera or phone already embedded in the photograph's EXIF metadata. If you shoot with location services off, there is nothing for us to collect.
We extract those coordinates at upload and store them. GPS is never displayed publicly by default. You must turn location display on yourself, and you can turn it off at any time. When display is off, the coordinates remain in our records and in your original file but are not shown to anyone else. To have coordinates removed entirely, write to legal@nocapped.com and we will delete them.
We treat GPS as sensitive personal information under the CPRA and comparable laws.
A.5 C2PA Content Credentials
If your photograph carries a C2PA manifest, our upload pipeline reads it and preserves it. A manifest may include creation assertions such as device, software, and author, action assertions describing edits, a cryptographic signature chain, and a human-readable provenance summary. We use this data only to display provenance to you and your viewers, and to sign the credential we add. Where a manifest is present, we also read and honor its training and data mining assertion.
A.6 Copyright registration
To prepare an application for the U.S. Copyright Office we collect author information (name, citizenship, year of birth), claimant information (name, address, rights ownership), registration batch details (title list, file references, registration type, deposit copies), and the resulting USCO registration numbers, case numbers, and application status.
We keep this information in your account so future filings are easier, and you can delete it at any time in your settings, independent of deleting your account. Once an application is submitted, the application data and deposit copies become part of a permanent government record that we cannot retract.
Fees and payment
Payment happens on a secure web page outside the app. When you request a registration, we email you to confirm, and that email contains a link where you pay. The app does not collect or process payment and contains no payment SDK.
What you are charged. A registration involves two amounts: the U.S. Copyright Office filing fee, and a NoCapped service fee for preparing and filing the application as your authorized agent. Both are shown to you as separate line items before you are asked to pay. You are never charged an amount that has not been disclosed to you first, and the total you see at the confirmation step is the total you pay.
We may change the service fee, offer promotional pricing, or waive or discount it for particular users, plans, or periods. Any change applies only to registrations you request after the change takes effect. We do not add a markup to the government filing fee itself: the U.S. Copyright Office amount we show you is the amount that office charges, and that office sets and may change its own fees.
We never see your payment card. Payments are processed by Stripe, Inc. Your card details go directly to Stripe and are never received by, stored on, or accessible to NoCapped systems or personnel. Stripe acts as an independent controller for payment data under its own privacy policy.
We retain a transaction record: amount, date, a confirmation identifier, the registration it relates to, and status. These are kept for seven years for tax and financial recordkeeping, including after account deletion.
Refund terms for registration fees are commercial terms rather than a privacy matter, and are set out in the Pinxt Terms of Service.
A.7 Interaction and social data
We collect comments you post, likes, follow relationships, reports you submit about content or users, and blocks you place. Pinxt does not include direct messaging.
Reports and blocks are confidential. If you report content we do not tell the poster who reported it, and if you block someone they are not notified. We retain reports and blocks to enforce our Terms of Service and to identify repeat violators.
A.8 Technical and device data
- IP address, used solely for security monitoring. We do not use it for analytics, advertising, or to infer your location. Server access logs are kept for 90 days.
- Device type, operating system, and app version.
- Push notification tokens, collected only if you enable notifications, and deleted when you disable them.
At launch, Pinxt uses no third-party analytics or crash reporting SDKs.
A.9 Content safety screening
Uploaded photographs and captions are screened for material that violates our Content Standards, including sexual content involving minors, non-consensual intimate imagery, graphic violence, and hateful imagery. Screening is automated: a content classification service analyzes the image at upload and returns a safety assessment. Flagged content may be blocked from posting or routed to a human reviewer at NoCapped for a decision, and if you appeal an enforcement action a person will look at your content.
Two distinctions matter here. This is analysis, not training: the classifier returns a result and does not retain or learn from your photograph. This is not our AI training position: safety screening applies to everyone and is not optional, while training on your work requires your explicit opt-in and always will.
A.10 What the app does not collect
- Real-time device location. We do not request location permission.
- Your contacts or address book.
- Photographs you have not selected for upload. There is no background library scanning.
- Advertising identifiers (IDFA or GAID).
- Biometric or facial recognition data.
- Payment card numbers, bank details, or any full payment credential.
A.11 Service providers for the app
- Amazon Web Services: storage, database, authentication, API, transactional email, compute, and content safety screening, in us-east-1, under the AWS Customer Agreement and GDPR Data Processing Addendum. Content delivery runs on AWS infrastructure under the same agreements.
- Stripe, Inc.: payment processing for registration fees, on a web page outside the app.
- Apple Push Notification service and Google Firebase Cloud Messaging: device tokens, if you enable notifications.
A.12 Retention for the app
| Data | Retention |
|---|---|
| Account data, photographs, metadata, GPS | Until you delete it, or account deletion plus 30 days to purge primary systems |
| Backups | Deleted within the backup rotation cycle, 90 days maximum |
| CDN edge caches | Transient, expire automatically, not a system of record |
| Registration application data | Account lifetime, then 30 days, or earlier on request |
| USCO registration numbers | Retained indefinitely, disassociated from your account after deletion |
| Server access logs including IP | 90 days |
| Push tokens | Until notifications are disabled or the account is deleted |
| Payment and transaction records | 7 years from the transaction date |
A.13 Deleting your account
You can delete your Pinxt account, and the photographs, metadata, and personal data associated with it, from inside the app. Deletion is permanent. Data is purged from primary systems within 30 days and from backups within the 90 day rotation. USCO registration numbers and payment records are retained as described above.
You can also request deletion without using the app. Write to legal@nocapped.com from the address on your account with the subject line "Delete Account." We acknowledge the request within 10 business days and complete it on the same timeline as an in-app deletion. You do not need to have the app installed to make this request.
Part II, Section B
The Pinxt Website and Beta Waitlist
Part I, Sections 1 through 9, applies to you as well. It covers our commitments, your rights, how we share information, security, retention, and how to reach us. This section adds only the detail specific to the Pinxt website and the beta waitlist, and does not replace Part I.
B.1 What the waitlist form collects
We collect everything you enter on the waitlist form, including fields that are optional. Some fields are required and some are not, but we store and use what you give us either way. The form collects:
- Your name and email address
- Country, and state or region
- Your photography background, for example professional, semi-professional, serious amateur, or student
- Your primary genres, for example portrait, commercial, editorial, wedding, landscape, street, or fine art
- Where your work lives, meaning the platform you select and the handle or URL you provide
- How you heard about us
- Your confirmation that you are 18 or older
- Your consent choices, and your agreement to the Beta Waitlist Terms
We also record the date and time of your submission and your waitlist status as it changes from applied to invited to activated.
We use this information to run the beta program: to decide who to invite, to shape a tester group that reflects a range of practices and genres, and to communicate with you about the beta. We do not use it for advertising, we do not sell it, and we do not share it with anyone outside the service providers named below.
Consent is separated deliberately. Agreeing to be considered for the beta is a different choice from agreeing to receive marketing email, and you can make one without the other.
B.2 Email
We use Customer.io to manage waitlist status and to send waitlist and beta email. Customer.io processes this data on our instructions under a data processing agreement. Our email platform records delivery events and may record whether a message was opened and whether links in it were clicked. We use that only to tell whether our own operational messages are reaching people.
Every marketing email includes an unsubscribe link. Unsubscribing from marketing does not remove you from the waitlist, and transactional messages about your waitlist status will still reach you. To leave the waitlist entirely, write to legal@nocapped.com and we will delete your record.
B.3 Website analytics
The Pinxt website uses analytics that are activated only after you give explicit consent through the cookie banner. If you decline, no analytics cookies are set and no analytics data is collected. Advertising storage is denied for every visitor, including those who accept analytics. Analytics retention is 14 months. Google Analytics 4 does not log or retain IP addresses: Google receives your IP address with the request, uses it to derive approximate location, and discards it.
B.4 Retention
Waitlist records are kept until you ask us to delete them, or until 12 months after the beta program closes, whichever comes first. Email engagement records are kept for 24 months.
Part II, Section C
This Website, nocapped.com
Part I, Sections 1 through 9, applies to you as well. It covers our commitments, your rights, how we share information, security, retention, and how to reach us. This section adds only the detail specific to the corporate website you are reading now, and does not replace Part I.
C.1 What we collect
This site has no forms, no accounts, and no logins. If you write to one of the email addresses listed on this site, we receive what you send us and use it to answer you. We do not add correspondents to any marketing list.
C.2 Cookies and analytics
Analytics on this site are activated only after you accept them through the cookie banner. If you decline, no analytics cookies are set and no analytics data is collected. We record your choice so we do not ask again, and you can change it at any time using in the footer.
| Cookie or storage | Purpose | Set when | Expiry |
|---|---|---|---|
| nc_cookie_consent | Remembers your cookie choice | When you choose | Until you clear site data |
| _ga | Distinguishes unique visitors | Only if you accept analytics | 2 years |
| _ga_9L38PW6RRG | Maintains analytics session state | Only if you accept analytics | 2 years |
Until you accept, this site loads nothing from a third-party server. No fonts, no scripts, no tracking assets. Nothing about your visit reaches anyone else before you have consented.
If you accept analytics, we load Google Analytics 4 from Google's servers, and from that point Google receives your IP address as part of the request. Google uses it to derive approximate location and does not log or retain it. We have configured the property so that Google Signals is turned off and data is not used for advertising personalization. Advertising storage, ad user data, and ad personalization are set to denied for every visitor, including those who accept. We run no session replay, no heatmaps, and no advertising cookies.
If you decline, or if you later change your choice to decline, we delete any analytics cookies already set on your browser.
C.3 Service providers for this website
- Amazon Web Services: hosting and content delivery, under the AWS Customer Agreement and GDPR Data Processing Addendum.
- Google LLC (Google Analytics 4): website analytics, loaded only after you accept, and processing data on our instructions under the Google Ads Data Processing Terms. Analytics data retention is set to 14 months.
C.4 Hosting
This site is hosted on AWS in the United States and delivered through a content delivery network. Standard server logs, including IP addresses, are generated by the hosting provider for security and operational purposes and are retained for 90 days.
NoCapped PBC · A Delaware Public Benefit Corporation ·
legal@nocapped.com
Privacy Policy version 1.1, effective September 14, 2026.