CapaPlanner for Claude – Privacy Policy

Last updated: 11 October 2026

About this policy

The CapaPlanner connector for Claude stores no customer data on its servers; it passes your requests between Claude and CapaPlanner. This policy explains what it handles, why, and for how long.

The connector is run by Stephan Schott, Stadtstieg 41, 37083 Göttingen, Germany ("CapaPlanner", "we").

This policy covers only the connector at mcp.capaplanner.com. Your use of CapaPlanner itself is covered by the CapaPlanner privacy policy. Your use of Claude is covered by Anthropic's privacy policy.

Who is responsible for your data

For the data in your CapaPlanner workspace, your employer or organisation (our customer) is the controller, and CapaPlanner acts as its processor.

  • Workspace data (employees, shifts, projects, bookings): your organisation decides whether its staff may use the connector. CapaPlanner processes this data on its behalf, under the data processing agreement between them.
  • Connector operation data (sign-in, security logs): CapaPlanner is the controller.
  • Your Claude conversations: Anthropic is responsible, under its own terms and privacy policy.

If you are an administrator: the connector can return personal data of your employees, such as contact details, hourly rates and time off. Inform your staff and decide who may connect, in line with your own privacy obligations.

What data the connector handles

The connector handles three kinds of data, and only while you use it.

Data Where it comes from Why
Your CapaPlanner API keyYou enter it on the sign-in pageTo read CapaPlanner data on your behalf, with your own permissions
CapaPlanner data (for example employees, projects, bookings, shifts, tasks, utilization)CapaPlanner's API, when Claude calls a toolTo answer your request in Claude
Technical data: IP address, time, request type, error codesYour browser or Claude's serversSecurity: rate limiting, detecting misuse, troubleshooting

The connector only reads data. It cannot create, change or delete anything in CapaPlanner.

It does not read your Claude conversations, chat history, memory or files. It receives only the tool requests Claude sends, such as "list resources" with an ID or a date range.

How we use and protect your API key

Your API key is never stored in a database and never shown to Claude or Anthropic.

  1. When you sign in, the connector checks your key with CapaPlanner.
  2. It then seals the key inside an encrypted sign-in token (AES-256 with tamper protection). Only the connector's server can open it.
  3. Claude keeps that token and sends it with each request. The connector opens it, uses your key to call CapaPlanner, and forgets it when the request ends.

The CapaPlanner data returned is passed straight to Claude to answer your request. The connector does not keep a copy.

We use the data only to provide the connector. We do not use it for advertising, profiling or training AI models, and we do not sell it.

Legal basis

Where the GDPR applies, we process data on these grounds (Art. 6(1) GDPR):

Purpose Legal basis
Signing you in and answering your requestsPerformance of the contract with you or your organisation (Art. 6(1)(b)); for workspace data, on your organisation's instructions as processor (Art. 28)
Security logs, rate limiting, misuse detectionOur legitimate interest in a secure service (Art. 6(1)(f))
Answering legal requestsLegal obligation (Art. 6(1)(c))

Who receives the data

Data goes only where it must for the connector to work. We never sell or rent it.

Recipient What they receive Why
Anthropic (Claude)The CapaPlanner data a tool returns, as part of your conversationTo answer you. Anthropic handles it under its own privacy policy
CapaPlanner APIYour API key and the request (for example a project ID)To fetch the data you asked for
Our hosting provider, Hetzner Online GmbH, GermanyEncrypted traffic and server logsTo run the server

We may disclose data if the law requires it, for example a valid court order.

Transfers outside the EU

Our own server is hosted in Germany (Hetzner, Nuremberg).

How long data is kept

A sign-in lasts at most 30 days; after that you sign in again.

Data Kept for
One-time sign-in code5 minutes, usable once
Access token (held by Claude)1 hour
Refresh token (held by Claude)Until used once, at most 30 days after you signed in
CapaPlanner dataNot kept: only for the length of one request
Server logs (IP address, time, errors)30 days, then deleted automatically

The server briefly remembers which codes and refresh tokens were already used, to block reuse. This list holds no API keys or CapaPlanner data and is cleared when the server restarts.

Tokens are not stored on our side, so we cannot list or read them. To end access at once, see the next section.

Your choices and rights

You can stop the connector's access at any time, in two ways:

  • Disconnect in Claude: Settings (or Customize) → Connectors → CapaPlanner → Disconnect. Claude deletes its tokens.
  • Deactivate or replace your API key in CapaPlanner. Every request uses your key live, so access stops immediately, even for tokens already issued.

You may ask us for access to, correction of or deletion of personal data we hold about you, such as log entries with your IP address. Where the GDPR applies, you also have the rights to restrict or object to processing, to data portability, and to complain to a data protection authority. Write to the contact below; we answer within 30 days.

Security

  • All traffic uses HTTPS.
  • Sign-in uses OAuth 2.1 with PKCE, and returns only to Claude's own addresses.
  • Sign-in attempts are rate-limited and failed attempts are logged.
  • Each refresh token works once; reuse of an old one cancels that sign-in.
  • The encryption keys are themselves encrypted by the server's operating system.
To report a security issue, write to stephan@schottai.com.

Changes to this policy

Significant changes will also be announced in the CapaPlanner app.

Contact

Stephan Schott
Stadtstieg 41, 37083 Göttingen, Germany
Email: stephan@schottai.com

Data protection officer: none appointed.

You can also complain to a data protection supervisory authority, for example the Lower Saxony State Commissioner for Data Protection (Die Landesbeauftragte für den Datenschutz Niedersachsen).