You hand Kapari decisions that have not been announced yet. So here it is, straight: where they are stored, what leaves our servers, what we never keep, and how it all gets erased. Every claim on this page is checked against the infrastructure we actually run.
The Kapari engine runs in Paris, on dedicated European infrastructure. The database sits in Paris too (AWS region eu-west-3, operated through Supabase). Your accounts, Kaps, folders, and profiles are stored there. The exports you generate, PDF and Excel, are built and cached on those same French servers. To produce a result, some text does leave these servers, part of it for the United States: the next section says which text, and where it goes.
A simulation needs a language model. Your decision text is processed by a model built by the French company Mistral AI, running in the European Union. Since September 18, 2026, that call goes straight to Mistral, encrypted end to end: it no longer passes through the US API router we used until then. To check the meaning of some steps without writing anything (for instance, keeping only the studies from our base that actually bear on your decision), the decision and its context, the panel's simulated profiles and reactions, sentences of the note to be checked, items taken from a page you have Kapari read by link, and facts drawn from your case file may also go, item by item, to the Jev model by TypeSafe AI (United States), which answers yes or no; written confirmation of its contractual safeguards has not yet been obtained. Kapari can also look up public facts about a company or a public figure you name. We call that public memory. When it runs, your text may go to a search API (Google, United States) as well. And when you run "Search public facts", only the queries you have reviewed and approved go to Perplexity, through OpenRouter (United States): not your decision, not your context, not your documents. In every case, we send only the text the simulation needs: never your identity, never your credentials. Outside the simulation, the service's emails (credentials, password reset, trial expiry notices) are sent through Resend (US), which receives your address and the text of the message, nothing else.
And one thing we never do: Kapari does not train any model on your decisions. Your content produces your result. It does not feed a model.
Attach a document (Word, PDF, text) to ground the panel and the text is pulled out locally, in your browser. The file itself never reaches our servers. Only the text you approve goes to the simulation.
An image you test, an ad or a mockup, passes through just long enough to produce a neutral description, which you review. The image is stored nowhere. Only the text description goes into the Kap.
What actually happened in a folder feeds the panel on YOUR next Kaps. A shared result never carries that detail. At most, it shows a count.
A Kap is visible to your account and no one else. It becomes reachable by link only when you click share, and you can delete it.
Every account is walled off. No other account can read your Kaps, folders, panels, or profiles. Passwords are hashed with scrypt, sessions are signed, and everything travels over HTTPS. Leaving is as easy as signing up. Delete your account and everything goes with it: Kaps, folders, panels, profiles. We keep no courtesy copy.
Kapari assembles a panel of simulated voices and maps how their reactions break down, so you can decide before you announce. The panel is simulated: no one is interviewed, nothing is predicted, and these voices measure no real population. This page describes the infrastructure we run today. When it changes, this page changes with it.
Put yours on the bench. A panel of voices reacts, and you read the range before you announce. What is yours stays yours.
Kapari measures its audience with Google Analytics, to know how many people read these pages. Nothing is stored on your device until you accept.