Security policy
Version 2026-09 · Capsemble Events By LYBOTECH Group Pty Ltd · ABN 31 693 890 952 · capsemble.com
Architecture: your media never rests with us
Capsemble is designed so the most sensitive data — your photos, videos and voice notes — never resides on Capsemble infrastructure. Media stays on your device or travels directly from the contributor's browser to the event host's connected cloud drive. Our database stores only account, event, permission and media-reference records, and enforces this at the database rules level: fields carrying binary or base64 content are rejected outright.
Access control
Every request is authenticated with Firebase Authentication and authorised against event membership and role (host, co-host, contributor, viewer) both in our API and in Firestore security rules, which are covered by an automated test suite of allowed and denied cases. Invitation codes are stored only as SHA-256 hashes; public share links use unguessable, revocable 192-bit tokens.
AI partners and training
Which partner may receive a request is enforced in code, not only in a contract. Each one carries a data-use verdict; a partner that trains on what it is sent cannot be enabled and is refused at the point of the call. Google requests run on Vertex AI under the Google Cloud terms rather than the free Gemini API, OpenAI requests are sent with storage off, and Capsemble’s own learning is limited to the structure and timing of events — never media, captions, guest lists or contact details.
Logging and traceability
Every request to an AI model is recorded server-side — the account, the part of the app, the model, the time taken, the credits charged and whether it succeeded — as are changes to an event, sign-ins, role changes and administrator actions. These records hold a one-way hash of the IP address and the network block rather than the address itself, the device and browser kind, and the country reported by the network. They are written only by our servers, are unreadable to any client, are restricted to a small number of administrators whose own access is logged, and expire automatically after 180 days.
Credentials and encryption
Traffic is HTTPS-only. Google Drive access uses the narrow drive.file scope, so Capsemble can only ever see files it created. OAuth refresh credentials are envelope-encrypted with Google Cloud KMS before storage in a server-only collection that no client can read, and are never sent to browsers. Disconnecting storage revokes the grant and deletes the stored credential without touching your files. Keys for the AI partners behind Capsemble Studio sit in the same encrypted, server-only vault; hosts and guests never hold them. Generated results pass through our servers in memory only and are saved, at the host's choice, into their own event folder.
Media safety
Upload size, duration and type limits are enforced before any transfer begins, and file types are re-verified from provider-detected content after transfer. Executable files are rejected. Private media is never cached by our service worker and is served with no-store cache headers.
Operations
We log security-relevant actions (deletion, export, storage connection changes) to a restricted audit log, monitor errors centrally, and can roll back deployments immediately. Users see stable error codes — never internal details.
Reporting a vulnerability
If you believe you've found a security issue, email support@capsemble.com with the details. We ask that you avoid accessing other users' data and give us reasonable time to remediate before public disclosure. We'll acknowledge reports promptly and keep you informed of progress.