Capno Privacy Policy
Effective date: July 12, 2026
Last updated: July 12, 2026
Capno Labs LLC (“Capno,” “we,” “us,” or “our”) provides CAPNO Studio, an anesthesia education and simulation platform. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit capno.app, use a Capno-operated version of CAPNO Studio (including studio.capno.app), participate in a hosted institutional deployment, request a pilot, or otherwise communicate with us (collectively, the “Service”).
This Privacy Policy does not apply to an independently self-hosted deployment of Capno’s open-source software. The institution or person operating such a deployment determines its privacy practices.
Privacy at a glance
- Simulation only. Capno is designed for fictional simulation cases, not clinical care. Do not enter real patient information or protected health information (“PHI”).
- Local-first. Many Capno features can operate entirely in your browser. Information stored only on your device is not transmitted to Capno unless you enable cloud features, use a hosted institutional service, contact us, or use a feature that expressly sends information to a third party.
- No student account is required for the student monitor. A learner may join a live simulation using a short session code. Faculty may optionally add a learner name or institution-assigned identifier to a debrief or assessment record.
- Institutional control. When an institution uses hosted Capno, the institution controls its scenarios, learner records, session archives, and related education data. Capno processes that information on the institution’s behalf and according to its instructions and our agreement with it.
- No data sales or behavioral advertising. We do not sell personal information or use it for cross-context behavioral advertising.
This summary highlights important points, but the full policy below controls.
1. Scope and our role
For information associated with a Capno customer institution—such as learner identifiers, session results, faculty notes, competency analytics, or debrief archives—the institution generally decides why and how the information is used. In that context, the institution is the data controller or business, and Capno acts as its service provider or data processor.
For information about website visitors, pilot applicants, billing contacts, and faculty account holders that we use to operate our own business, Capno generally acts as the data controller or business.
If you use Capno through a university, hospital, training program, employer, or other organization (an “Institution”), that Institution’s privacy notices and policies may also apply. If this Privacy Policy conflicts with a signed customer agreement or data processing addendum concerning Institution Data, the signed agreement controls to the extent of the conflict.
2. Information we collect
We collect only the information reasonably needed to provide, secure, support, and improve the Service.
A. Account and institutional information
When faculty members, administrators, or other authorized users create or receive an account, we may collect:
- name and display name;
- email address;
- password credentials handled by our authentication provider (we do not receive your plain-text password);
- Institution name, program, membership, role, and permissions;
- account invitations, status, and access history; and
- settings and preferences.
B. Learner and simulation information
Capno does not require learners to create accounts merely to view the student monitor. Depending on how an Institution configures and uses the hosted Service, faculty may enter or generate:
- an optional learner name, initials, or Institution-assigned identifier;
- cohort, course, training level, or group information;
- simulation date, scenario, session code, and participating faculty;
- actions marked by faculty as completed, delayed, missed, or incorrect;
- rubric results, scores, competency measures, and trend analytics;
- timestamps, simulated vital-sign trends, event logs, and session notes;
- faculty observations, feedback, debrief notes, and assessment amendments; and
- reports, exports, and session archives.
This information may be an education record when maintained by or for an Institution. Institutions should collect only the learner information they need and may choose to use an internal identifier instead of a full name.
C. Customer Content
We may process information submitted to or created in the Service, including custom scenarios, fictional patient profiles, learning objectives, expected actions, scoring rubrics, notes, uploaded or imported files, exported reports, and other content (“Customer Content”).
Capno scenarios are fictional by design. Customer Content must not include real patient names, medical record numbers, dates of birth, clinical images, or other information that identifies an actual patient.
D. AI feature information
If you use an AI-assisted feature, such as scenario drafting or the simulation co-pilot, we may process the prompt, relevant scenario context, your instructions, and the generated response. Do not place learner names, education records, PHI, or other sensitive personal information in an AI prompt.
The open-source or bring-your-own-key version may store an API key only in your browser and send requests directly to the AI provider you select. The hosted version may send requests through an AI provider engaged by Capno. Section 6 explains these disclosures in more detail.
E. Billing and transaction information
Our payment processor, currently Stripe, may collect payment-card and billing information directly from the payer. Capno does not receive full payment-card numbers. We may receive limited transaction details such as payer name, billing contact information, amount, subscription status, invoice history, and the last four digits or brand of a payment method.
F. Communications and business information
We collect information you provide when you request early access or a pilot, ask for support, complete a form, respond to a survey, participate in a product interview, or otherwise communicate with us. This may include contact information, message content, scheduling information, feedback, and details about your Institution’s needs.
G. Device, log, and usage information
When you access a Capno-operated website or hosted Service, we and our infrastructure providers may automatically receive limited technical information, including:
- IP address and approximate location derived from it;
- browser, device, operating system, language, and screen information;
- dates and times of access, requested pages, referring page, and diagnostic events;
- authentication, security, and error logs; and
- cookie, local-storage, service-worker, or similar identifiers needed to maintain a session, remember settings, support offline use, or prevent abuse.
The core app does not use third-party advertising trackers. If we add optional analytics or other non-essential tracking, we will update this Privacy Policy and provide any choices required by law.
3. How information is collected
We collect information:
- directly from you when you create an account, enter content, request a pilot, pay an invoice, or contact us;
- from your Institution when it creates or manages your account, assigns your role, imports information, or records a simulation;
- automatically from your browser or device when you use a Capno-operated Service;
- from service providers involved in authentication, hosting, payments, support, or security; and
- from integrations your Institution chooses to connect, if any.
4. How we use information
We use personal information to:
- provide, operate, synchronize, and maintain the Service;
- authenticate users and administer Institution roles and permissions;
- run simulations, save scenarios, create debriefs, calculate faculty-directed rubric results, and provide Institution-requested analytics and reports;
- process subscriptions, invoices, and payments;
- provide onboarding, training, customer support, and service communications;
- personalize settings and remember user preferences;
- monitor availability, diagnose errors, prevent fraud and abuse, and protect accounts, users, and the Service;
- improve accessibility, reliability, usability, and performance using aggregated or de-identified information where practicable;
- communicate about pilots, product changes, security, and administrative matters;
- comply with law, enforce our agreements, and establish or defend legal claims; and
- carry out another purpose disclosed at the time of collection or authorized by you or your Institution.
We do not use identifiable learner records to advertise to learners or to train general-purpose AI models. Capno-generated scores reflect rules, rubrics, and action statuses selected or reviewed by faculty. Capno does not make admissions, employment, licensure, or other decisions that produce legal or similarly significant effects about learners.
5. Local, realtime, and cloud processing
Local use
Scenarios, preferences, and session archives may be stored in browser storage on the device being used. If information remains only in local browser storage, Capno cannot view, recover, export, or delete it for you. Clearing site data, resetting the browser, removing the app, or losing the device may permanently delete locally stored information.
Live session synchronization
A student display may receive simulated monitor information through a local browser channel or an enabled realtime service. Live monitor state may be broadcast using a short session code. Capno is designed not to require a learner account for this display, and per-tick simulated monitor state is not intended to become a separate permanent record unless incorporated into a saved session archive.
Hosted cloud features
When an Institution enables hosted accounts, cross-device synchronization, archives, analytics, or reporting, relevant account and simulation information is transmitted to and stored in Capno’s contracted cloud infrastructure. Institution administrators may access and manage this information according to their assigned permissions.
6. How we disclose information
We may disclose information in the following circumstances:
A. To your Institution
Authorized faculty and administrators may access information associated with their Institution, including account membership, custom scenarios, session archives, learner identifiers, debriefs, results, and analytics. The Institution determines who is authorized and how the information may be used within its program.
B. To service providers
We use contracted providers to perform services on our behalf, such as:
- website and application hosting;
- databases, storage, authentication, and realtime synchronization;
- billing and payment processing;
- email, communications, and customer support;
- application security, error diagnosis, and infrastructure monitoring;
- document or report delivery; and
- AI model or API processing when an AI feature is used.
These providers may process information only to perform services for us, subject to contractual and legal restrictions. For the hosted Service, we do not authorize AI providers to use Customer Content or identifiable learner information to train their general-purpose models.
If you use a bring-your-own-key AI feature, your chosen provider receives the information you submit, and its own terms and privacy policy apply. Capno does not control that provider’s independent practices.
C. For legal, safety, and security reasons
We may disclose information when we reasonably believe disclosure is necessary to comply with law or valid legal process; protect the rights, safety, or security of Capno, our users, an Institution, or others; investigate fraud, abuse, or security incidents; or enforce our agreements. When legally permitted, we will seek to direct requests for Institution Data to the relevant Institution or notify it before disclosure.
D. During a business transaction
Information may be reviewed or transferred as part of a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. Any recipient will be required to handle personal information consistently with applicable law and the commitments governing the information at the time of transfer.
E. With professional advisers or authorization
We may disclose information to lawyers, accountants, auditors, insurers, and other professional advisers subject to confidentiality obligations, or to another party when you or your Institution directs or authorizes us to do so.
F. Aggregated or de-identified information
We may use and disclose information that has been aggregated or de-identified so that it cannot reasonably identify an individual. We do not attempt to re-identify de-identified learner information except to test whether our de-identification methods are effective, where permitted by law.
7. No sale, targeted advertising, or financial incentives
We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, and we do not use personal information for targeted advertising. We do not offer financial incentives in exchange for personal information.
Because we do not engage in these activities, we do not currently provide a “Do Not Sell or Share” link. We will recognize browser-based opt-out preference signals, such as Global Privacy Control, if and to the extent required by applicable law.
8. Data retention and deletion
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, follow an Institution’s instructions, comply with contractual and legal requirements, maintain security and business records, resolve disputes, and enforce agreements.
Retention depends on where and why information is stored:
- Local browser information remains until the user clears it, removes the app, resets the browser or device, or overwrites the information.
- Institution Data is retained according to the Institution’s settings, instructions, and customer agreement. During a subscription, authorized Institution users may delete supported records or request export or deletion. Following termination, Capno will return or delete Institution Data as stated in the applicable agreement or data processing addendum, subject to a limited backup cycle and legal retention obligations.
- Account and relationship records are generally retained while an account or customer relationship is active and for a reasonable period afterward for security, support, audit, and dispute-resolution purposes.
- Billing and transaction records are retained as required for accounting, tax, fraud-prevention, and legal obligations.
- Support, security, and technical logs are retained for periods proportionate to their operational or security purpose.
Deletion from active systems may not immediately remove information from encrypted backups. Backup copies are isolated from ordinary use and removed or overwritten through the normal backup cycle unless law requires longer retention. We may retain aggregated or de-identified information that no longer identifies an individual.
An Institution may establish a more specific retention schedule in its customer agreement or data processing addendum.
9. Data security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. Depending on the Service configuration, these measures include encryption in transit, authentication, role-based permissions, database access controls, logging, vendor review, software testing, and incident-response procedures.
No method of transmission or storage is completely secure. Users are responsible for securing their devices, browsers, account credentials, exported files, locally stored archives, and any self-hosted deployment. If we learn of a security incident affecting personal information, we will investigate and provide notice as required by law and applicable customer agreements.
10. Educational records and FERPA
The Family Educational Rights and Privacy Act (“FERPA”) applies to education records maintained by U.S. educational agencies and institutions that receive applicable federal funding; it does not make every piece of information in Capno an education record.
When an Institution provides Capno with personally identifiable information from education records under FERPA’s school-official exception or another lawful basis, our agreement with the Institution is intended to ensure that:
- Capno performs an institutional service or function for which the Institution would otherwise use its own employees;
- the Institution retains direct control over Capno’s use and maintenance of the information;
- Capno uses the information only for the authorized educational purpose and does not use or re-disclose it except as directed by the Institution and permitted by law;
- service providers receiving the information are subject to appropriate restrictions;
- Capno supports the Institution in responding to lawful access, correction, export, and deletion requests; and
- the information is returned or destroyed when no longer needed for the authorized purpose, according to the Institution’s agreement.
Capno does not determine whether a particular Institution may disclose learner information without consent. Each Institution is responsible for providing required notices, obtaining any necessary permissions or consents, defining authorized users, and using the Service consistently with FERPA and its own policies.
Learners seeking access to or correction of an education record should ordinarily contact their Institution first. We will assist the Institution as required by our agreement and applicable law.
11. No patient data or HIPAA use
Capno is an educational simulation product, not a clinical system or medical device. It is not designed to create, receive, maintain, or transmit PHI. Use fictional patient information only.
Unless Capno and an Institution have signed a separate Business Associate Agreement that expressly covers the applicable Service, Capno does not offer the Service for workflows requiring HIPAA-regulated PHI. Do not enter, upload, import, display, or transmit real patient information through Capno, including in scenarios, notes, debriefs, reports, support requests, or AI prompts. If you believe patient information has been submitted accidentally, contact us promptly at hello@capno.app.
12. Your choices and privacy rights
Account and communication choices
You may update certain account information through the Service or through your Institution administrator. You may opt out of non-essential marketing email by using the unsubscribe link in the message. We may still send transactional, security, account, or service notices.
You can control local browser storage through your browser or device settings. Disabling cookies, local storage, or service workers may prevent offline operation, authentication, saved preferences, or other features from working properly.
Privacy rights
Depending on where you live and subject to applicable law, you may have the right to:
- confirm whether we process your personal information and access that information;
- correct inaccurate personal information;
- delete personal information;
- obtain a portable copy of personal information you provided;
- opt out of sale, targeted advertising, or certain profiling;
- limit certain uses of sensitive personal information;
- withdraw consent where processing is based on consent; and
- appeal a denial of a privacy request.
Capno does not discriminate against a person for exercising an applicable privacy right.
To submit a request, email hello@capno.app with the subject line “Privacy Request.” To appeal a decision, use the subject line “Privacy Appeal.” We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification.
If your request concerns Institution Data, we may direct you to the Institution because it controls that data. We will support the Institution in responding as required by law and our agreement. We will respond within the period required by applicable law. Some information may be exempt from a request, such as information needed for security, fraud prevention, legal compliance, billing records, or the rights of others.
13. Children’s privacy
The Service is intended for faculty, administrators, and learners in professional or postsecondary education and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If we learn that we collected such information without legally sufficient authorization, we will delete it or take other steps required by law. A parent or guardian who believes a child has provided personal information may contact hello@capno.app.
14. International users and data transfers
Capno is based in the United States, and personal information may be processed in the United States or another country where our service providers operate. Those countries may have privacy laws different from the laws where you live. Where required, we use contractual or other recognized safeguards for cross-border transfers. An Institution’s order form or data processing addendum may specify additional hosting-region or transfer terms.
Where applicable, our legal bases for processing include performing a contract, taking steps requested before entering a contract, pursuing legitimate interests such as operating and securing the Service, complying with legal obligations, and consent. You may contact us for more information about the legal basis applicable to a particular activity.
15. Third-party services and self-hosted deployments
The Service may link to third-party websites or allow an Institution to connect third-party services. Their privacy practices are governed by their own policies, not this Privacy Policy.
If you or your Institution independently deploys, modifies, or operates Capno’s open-source software, Capno Labs LLC does not control that deployment and ordinarily does not receive information from it. The operator is responsible for its own notices, consents, security, retention, integrations, and legal compliance.
16. Changes to this Privacy Policy
We may update this Privacy Policy as the Service or law changes. We will post the revised version and update the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice when required, such as through the Service, by email, or through the relevant Institution. Institution Data remains subject to any notice, consent, and contract requirements in the applicable customer agreement.
17. Contact us
Questions, privacy requests, or concerns may be sent to:
Capno Labs LLC
Email: hello@capno.app
United States