Shared memory capsule

Privacy Policy

Last updated:

Capsoul preserves shared memories for people to reopen together. This policy explains the information used to operate and protect that experience, including the separate local-first Personal mode.

1. Information we process

Depending on the features you use, we may process:

  • Account and authentication data: email address, optional phone number, display name, avatar URL, user ID, sign-in method, account timestamps, verification and recovery records, and Apple sign-in identifiers when used.
  • Recipient and sharing data: designated recipient account IDs or contact details, confirmation and invitation records, sender disclosure choice, delivery status, opening status, opening progress, and withdrawal state.
  • Capsule and media data: titles, text, emotion design, opening time, Shared or Personal mode, photos, videos, voice recordings, files, music references, optional places and weather, media metadata, and integrity values.
  • Device and operational data: device and app environment, APNs token, preferred notification language, upload and delivery state, security events, error diagnostics, and limited logs needed to operate and troubleshoot the service.
  • StoreKit and entitlement data: product identifiers, verified transaction and original-transaction identifiers, subscription status and paid period, account binding, Shared balance and ledger activity, Personal allowance, grants, reservations, refunds, reversals, and reconciliation state. Capsoul does not receive full payment-card details.
  • Support data: the messages and non-sensitive references you choose to send, contact address, issue time, app version, and our response history.
  • Safety and abuse data: report category and description, reporter and reported-account references, relevant capsule reference, moderation status, evidence needed for review, fraud signals, and blocking relationships.

2. How we use information

We use this information to authenticate users; create, store, release, and deliver Shared Capsouls; identify intended recipients; show opening progress; enforce Personal allowances and authorized key release; process verified purchases and memberships; send service notifications; respond to support; prevent fraud and abuse; investigate reports; enforce blocks; process account deletion; and meet legal obligations.

We do not sell or rent personal data, and we do not share it with third parties for advertising.

3. Personal capsules are local

Personal capsule documents remain local to the user’s device. Personal text and media are encrypted on-device with AES-256-GCM in an account-bound .capsoul document excluded from cloud backup. Capsoul does not upload Personal plaintext or media and does not provide a cloud library, synchronization, discovery, or backup for the Personal payload.

CloudBase may still process the limited account-scoped allowance, entitlement, reservation and commit state, hashed identifiers, encrypted-package integrity values, scheduled opening time, and wrapped-key metadata necessary to enforce the feature and authorize key release. Exported and imported Personal documents remain encrypted and account-bound.

4. Shared delivery and service providers

Tencent CloudBase and related Tencent Cloud services act as service providers for functions such as authentication support, database operations, Shared object storage and delivery, email or SMS delivery, and optional recommendation features. Apple provides Sign in with Apple, App Store and StoreKit services, and the Apple Push Notification service (APNs). These providers process information only as needed to provide their services and operate Capsoul.

Access controls limit Shared content to the sender, designated recipients, and authorized service operations under the applicable release and safety rules. We use APNs tokens and locale data to deliver service notifications without putting private capsule content in the notification payload.

For eligible Shared Capsouls, a verified local document may be saved after the relevant feature is enabled and its claim conditions are met. After required durable local copies are confirmed or the applicable claim period ends, eligible cloud media may later be cleaned up. This is conditional lifecycle behavior, not a promise that cleanup is active for every account or capsule. A local document controlled by another person’s device cannot be remotely deleted through account deletion.

5. Reports, blocks, and safety retention

A report sends the limited information needed for review, such as account and capsule references, category, optional description, relevant service evidence, and moderation status. A reported user is not told who submitted the report. A block is a separate relationship and remains while active unless you unblock the account.

Closed report records and review history are normally retained for 180 days. Limited records may be kept longer when reasonably needed for safety, fraud prevention, disputes, or legal compliance, including an active investigation or legal hold.

6. Retention and account deletion

We retain account, unopened Shared capsule, purchase, entitlement, and operational information for as long as needed to provide the service and satisfy the rules in the Purchase & Preservation Policy. Verification codes, upload sessions, notification attempts, and other transient data use shorter operational periods where practicable.

You can request deletion in the app through Profile → Delete Account, or contact Support if you cannot access the app. After verification, we delete or anonymize account data and associated service content within 30 days, except for limited records needed for security, purchase accounting, safety, disputes, fraud prevention, or law.

After server deletion succeeds, the app attempts to remove that account’s Personal packages, keys, and temporary plaintext from the current device. If server deletion fails, the app keeps the session and local key material so a failed request does not prematurely destroy local access. Account deletion does not cancel an Apple subscription and cannot remotely erase user-controlled local copies on other devices.

7. Permissions and choices

You may correct profile information, omit optional media and location, choose recipients, select sender disclosure, withdraw an eligible unopened Shared Capsoul under the app’s rules, manage blocks, and request deletion. Device permissions such as camera, microphone, photo library, location, contacts, and notifications are requested only for the related feature and can be managed in system settings. Capsoul does not continuously track location.

8. Children, security, and international processing

Capsoul is not directed to children under 13, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information.

We use access controls, server verification, encryption where described, and data minimization appropriate to the service. No system can guarantee absolute security. Information may be processed where our service providers operate, subject to applicable safeguards and law.

9. Changes and contact

We may update this policy and will provide appropriate notice of material changes. For privacy questions or requests, visit Support or email support@capsoul.chat.