CapaPlanner for Claude – Privacy Policy
Last updated: 11 October 2026
About this policy
The CapaPlanner connector for Claude stores no customer data on its servers; it passes your requests between Claude and CapaPlanner. This policy explains what it handles, why, and for how long.
The connector is run by Stephan Schott, Stadtstieg 41, 37083 Göttingen, Germany ("CapaPlanner", "we").This policy covers only the connector at mcp.capaplanner.com. Your use of CapaPlanner itself is covered by the CapaPlanner privacy policy. Your use of Claude is covered by Anthropic's privacy policy.
Who is responsible for your data
For the data in your CapaPlanner workspace, your employer or organisation (our customer) is the controller, and CapaPlanner acts as its processor.
- Workspace data (employees, shifts, projects, bookings): your organisation decides whether its staff may use the connector. CapaPlanner processes this data on its behalf, under the data processing agreement between them.
- Connector operation data (sign-in, security logs): CapaPlanner is the controller.
- Your Claude conversations: Anthropic is responsible, under its own terms and privacy policy.
If you are an administrator: the connector can return personal data of your employees, such as contact details, hourly rates and time off. Inform your staff and decide who may connect, in line with your own privacy obligations.
What data the connector handles
The connector handles three kinds of data, and only while you use it.
| Data | Where it comes from | Why |
|---|---|---|
| Your CapaPlanner API key | You enter it on the sign-in page | To read CapaPlanner data on your behalf, with your own permissions |
| CapaPlanner data (for example employees, projects, bookings, shifts, tasks, utilization) | CapaPlanner's API, when Claude calls a tool | To answer your request in Claude |
| Technical data: IP address, time, request type, error codes | Your browser or Claude's servers | Security: rate limiting, detecting misuse, troubleshooting |
The connector only reads data. It cannot create, change or delete anything in CapaPlanner.
It does not read your Claude conversations, chat history, memory or files. It receives only the tool requests Claude sends, such as "list resources" with an ID or a date range.
How we use and protect your API key
Your API key is never stored in a database and never shown to Claude or Anthropic.
- When you sign in, the connector checks your key with CapaPlanner.
- It then seals the key inside an encrypted sign-in token (AES-256 with tamper protection). Only the connector's server can open it.
- Claude keeps that token and sends it with each request. The connector opens it, uses your key to call CapaPlanner, and forgets it when the request ends.
The CapaPlanner data returned is passed straight to Claude to answer your request. The connector does not keep a copy.
We use the data only to provide the connector. We do not use it for advertising, profiling or training AI models, and we do not sell it.
Legal basis
Where the GDPR applies, we process data on these grounds (Art. 6(1) GDPR):
| Purpose | Legal basis |
|---|---|
| Signing you in and answering your requests | Performance of the contract with you or your organisation (Art. 6(1)(b)); for workspace data, on your organisation's instructions as processor (Art. 28) |
| Security logs, rate limiting, misuse detection | Our legitimate interest in a secure service (Art. 6(1)(f)) |
| Answering legal requests | Legal obligation (Art. 6(1)(c)) |
Who receives the data
Data goes only where it must for the connector to work. We never sell or rent it.
| Recipient | What they receive | Why |
|---|---|---|
| Anthropic (Claude) | The CapaPlanner data a tool returns, as part of your conversation | To answer you. Anthropic handles it under its own privacy policy |
| CapaPlanner API | Your API key and the request (for example a project ID) | To fetch the data you asked for |
| Our hosting provider, Hetzner Online GmbH, Germany | Encrypted traffic and server logs | To run the server |
We may disclose data if the law requires it, for example a valid court order.
Transfers outside the EU
Our own server is hosted in Germany (Hetzner, Nuremberg).How long data is kept
A sign-in lasts at most 30 days; after that you sign in again.
| Data | Kept for |
|---|---|
| One-time sign-in code | 5 minutes, usable once |
| Access token (held by Claude) | 1 hour |
| Refresh token (held by Claude) | Until used once, at most 30 days after you signed in |
| CapaPlanner data | Not kept: only for the length of one request |
| Server logs (IP address, time, errors) | 30 days, then deleted automatically |
The server briefly remembers which codes and refresh tokens were already used, to block reuse. This list holds no API keys or CapaPlanner data and is cleared when the server restarts.
Tokens are not stored on our side, so we cannot list or read them. To end access at once, see the next section.
Your choices and rights
You can stop the connector's access at any time, in two ways:
- Disconnect in Claude: Settings (or Customize) → Connectors → CapaPlanner → Disconnect. Claude deletes its tokens.
- Deactivate or replace your API key in CapaPlanner. Every request uses your key live, so access stops immediately, even for tokens already issued.
You may ask us for access to, correction of or deletion of personal data we hold about you, such as log entries with your IP address. Where the GDPR applies, you also have the rights to restrict or object to processing, to data portability, and to complain to a data protection authority. Write to the contact below; we answer within 30 days.
Security
- All traffic uses HTTPS.
- Sign-in uses OAuth 2.1 with PKCE, and returns only to Claude's own addresses.
- Sign-in attempts are rate-limited and failed attempts are logged.
- Each refresh token works once; reuse of an old one cancels that sign-in.
- The encryption keys are themselves encrypted by the server's operating system.
Changes to this policy
Significant changes will also be announced in the CapaPlanner app.Contact
Stephan Schott
Stadtstieg 41, 37083 Göttingen, Germany
Email: stephan@schottai.com
Data protection officer: none appointed.
You can also complain to a data protection supervisory authority, for example the Lower Saxony State Commissioner for Data Protection (Die Landesbeauftragte für den Datenschutz Niedersachsen).