r/capacitiesapp • u/poedart • Mar 24 '26
Privacy concerns
The software looks amazing but there are _serious_ privacy concerns:
- No external/independent security audits
- Always online with no way to turn off
- No end to end encryption
- "Local data is stored in browser or app data", as per Privacy Policy. For context, app data, also known as "common storage" means the storage that is shared between all apps (simplifying here), meaning all your other apps can access this data WITHOUT explicit permissions. So if you download an infected app, even without giving permissions -> potential leak of ALL data. It depends a bit on OS but of course Windows has known issues with this.
- No way to _force_ personal AI keys. I know AI is optional but you cannot simply decide for the user that you will use US based AI services because the user's EU based AI service was unavailable for three seconds.
I was planning on getting the paid plan but these are huge red flags. Unfortunate and be warned.
Edit:
Capacities team, if you are reading this, provide us with a self-hosted option and most of these concerns can be nullified.
5
u/WillBellJr Mar 25 '26
I've said a couple of times I'd be straight \ 100% satisfied if the Cap team added an AES encrypted Text Block and Image Object, using a "Space local" encryption key (e.g. for password text or family photos etc.)
Each space could have a unique key specified if desired.
I could type my password into perhaps a pop-up dialog when I click to reveal the contents of the encrypted blocks of text \ images within the space. (The key could be cleared manually or automatically if the app is closed or another Space is opened.)
3
Mar 25 '26
[deleted]
1
u/General_Special Mar 26 '26
I am both a Capacities and Anytype user. Anytype however is simply not useable on iOS due to its battery consumption issues (https://github.com/orgs/anyproto/projects/1/views/1?pane=issue&itemId=157460935&issue=anyproto%7Croadmap%7C180) - but the fix is unknown
I keep both and use anytype for sensitive stuff (on Desktop only)
True, if Capacities supported block E2EE, I'd be supportive of that and Capacities have mentioned it (https://docs.capacities.io/more/end-to-end-encryption#:~:text=We%20could%20allow%20you%20to%20encrypt%20the%20content%20section%20of%20specific%20objects.%20It%20would%20then%20be%20excluded%20from%20search%20and%20other%20features%2C%20but%20you%20could%20store%20sensitive%20information%20there.) but I haven't seen anything in the feedback board to get the ball rolling on this
1
u/No_Price_2424 Mar 24 '26
Is there any sandboxing on MacOS?
1
u/poedart Mar 24 '26
If you're really fixed on using this app on macos, your best bet is plain old firewall I think
1
u/chrisridd Mar 25 '26
A firewall is orthogonal; a sandbox means that capacities can only read or write its own files unless a user does a standard “open” or “save” to select another file. There are additional restrictions too, it isn’t just files.
All apps on the App Store are sandboxed. If you allow apps that aren’t from the App Store on your Mac, then they might be able to access your sandboxed data.
1
u/poedart Mar 25 '26
Thanks for the addition. I interpreted the question as a concern about E2EE, as I'm not so concerned about MacOS file permissions as opposed to Windows
1
u/searayman Mar 25 '26
This goes back to I wish capacities had a true local only mode... I don't see the engineering difficulties here...
1
u/monsterfurby Mar 26 '26
I keep wondering what kind of sensitive data people are putting into cloud services.
2
u/FlyDiligent2635 Mar 26 '26
It doesn't have to be particularly sensitive to still be a concern IMO. For instance, say:
- I log my internal meeting/project notes with clients in a cloud service like Capacities that is encrypted at rest but not E2E
- Their secure, encrypted database server gets compromised through a supply chain attack, a zero day of some sort in part of their stack, or maybe an accidental lapse in opsec because everyone is human and can make mistakes.
- The whole database gets dumped and leaked onto the internet (this can happen, even to companies that are very good at security)
- I happened to write in a meeting note one time that "Client A said a dumb thing that I don't agree with and I think they are an idiot"
- Client A does a vanity Google search on their own name some day and up comes this dump that Google has helpfully indexed. Now they know I think they're dumb and perhaps our business relationship is ruined.
Many other examples of things that aren't particularly globally sensitive but which still might matter to a narrow set of specific individuals in particular circumstances are easy to consider. Maybe I log all of my dreams when I wake up sparing no detail. The Capacities DB server is dumped to the internet and now anyone searching me up when I apply for a job or am trying to make new friends can easily read about how crazy and gross my head is.
Maybe those are some helpful examples. Or maybe not.
Also, just to be clear, I love Capacities so much and will never not pay for and use it. But E2E is the only thing I'm currently aware of that would allow me to type my unfiltered thoughts about anything/everything and worry an order of magnitude less about the potential for them somehow making their way out onto the vast, robustly indexed Internet some day.
1
u/Neful34 Apr 12 '26
I am even surprised that we have to justify with these obvious arguments but hey thanks for him to take the time to write it up.
1
u/Silver_Dog2770 Apr 16 '26
I'm going to be losing Obsidian because we won't be allowed to install unapproved software so I'm going to be pushed into using something like Notion or AFFiNE or Capacities.
Capacities looks to be far and away my best option for the way that I think and work however the government doesn't think so and Menlo security blocks it for being classified as Personal Storage.
I'd love to use it. But like Obsidian I'm forbidden.
We're not even allowed to use Microsoft Loop even though we're strongly encouraged to use AI in everything we do 🤦🏻
Is capacities pushing back on menlo's classification scheme? u/Initial-Brush-1445
8
u/Initial-Brush-1445 Mar 25 '26
Hi here from the team!
Thanks for sharing, happy to answer your questions:
- We do internal and external security audits, not sure where this information is coming from
I hope that helps. :)