Skip to content
Capsula
How it worksSecurityDownload
EN
  • ENEnglish
  • ESEspañol
  • PTPortuguês
Get the app
How it worksSecurityDownloadGet the app
Legal

Privacy Policy

This policy explains what personal data Capsula processes, why it is used, who receives it, and the choices and rights available to you.

Last updated: September 10, 2026

Privacy PolicyTerms of UsePurchases & Refunds PolicyAccount Deletion

On this page

  1. 1. Who is responsible for your data
  2. 2. Scope and the local-content boundary
  3. 3. Data we process
  4. 4. Purposes and legal bases
  5. 5. Encryption and key custody
  6. 6. Service providers and other recipients
  7. 7. International transfers
  8. 8. Retention
  9. 9. Your privacy rights
  10. 10. Children and teenagers
  11. 11. Security
  12. 12. Account deletion
  13. 13. Changes and contact

1. Who is responsible for your data

Capsula is operated by Lesound App SAS, established in Colombia, with a service address at CR 48 46 54, Itagüí, Colombia. This operator is the controller of the personal data described in this policy unless a third-party service acts as an independent controller.

Privacy questions and requests may be sent to laitelabs@gmail.com.

2. Scope and the local-content boundary

This policy covers the Capsula mobile app, the gocapsula.com website, the backend key-custody service and related support interactions.

Capsula is designed so that capsule files, photos, videos, audio, notes, capsule names, descriptions, filenames and the plaintext data-encryption key remain on your device or in storage you choose. They are not uploaded to the Capsula backend. A cloud-storage provider you choose processes those files under its own terms.

3. Data we process

  • Account data: Firebase user ID, sign-in provider, email address, display name, profile photo URL, account currency and account timestamps received through Google or Apple sign-in.
  • Capsule and key-custody data: capsule UUID, account ID, active status, scheduled unlock time, encrypted (KMS-wrapped) 32-byte data-encryption key, KMS version, client cipher label, Argon2id hash of the unlock secret, opening timestamps and related audit timestamps. Capsula does not store the plaintext key or unlock secret.
  • Purchase and credit data: store, product identifier, quantity, transaction identifier, purchase and refund times, environment, credits granted and consumed, refund status and the complete RevenueCat webhook event used for reconciliation. Apple or Google processes payment-card details; Capsula does not receive them.
  • Usage analytics in production release builds: Firebase user ID, screen names, authentication method, purchase outcome, item kinds and counts, group counts, days until unlock, boolean feature states, onboarding progress, review prompts and app-lifecycle events. Content, filenames and exact unlock dates are not intentionally sent as analytics parameters.
  • Crash and diagnostics data: Firebase user ID, app/device diagnostics, exception and stack information, stable error reason, breadcrumbs and custom diagnostic keys. An exception may contain incidental technical context.
  • Security and service logs: account ID, request path, status, duration, resource identifiers and, for some security events, IP address and user-agent. Upstash may process a pseudonymous account ID and counters for user rate limiting; short-lived global IP limits are held in instance memory.
  • Website data: technical data processed when Google Fonts, the Google Ads tag (gtag.js), Vercel Analytics and Vercel Speed Insights load, including connection data, pages viewed, referrer, advertising cookies and online identifiers.

4. Purposes and legal bases

Production release builds send product analytics to Firebase Analytics and Amplitude. Capsula does not currently show an in-app consent or opt-out control for that analytics; the login authorization is not analytics consent. If Capsula later serves users in the EU/EEA, ePrivacy/GDPR requirements may apply separately.

The website loads Google Ads (gtag.js) to measure campaigns, attribute visits after ad clicks and remarket to visitors.

  • Contract: authenticate you, create and maintain the account, display and reconcile the key balance, custody a wrapped key, enforce the unlock time and secret checks, and release a key when both checks pass.
  • Authorization under Colombian Law 1581 of 2012, and equivalent permission where you live: when you create an account you check an in-app authorization box that links to this policy and the Terms of Service. Capsula records the date and policy version of that authorization.
  • Legal obligations: keep records required for accounting, tax, refunds, chargebacks, consumer protection and lawful requests.
  • Operating the service: security, abuse and fraud prevention, failure diagnosis, reliability and product analytics in production release builds. Where GDPR, LGPD or similar laws apply, those activities are pursued as legitimate interests where that basis is permitted.

5. Encryption and key custody

Capsule content is encrypted locally with a client-generated key. The backend receives that key for wrapping with Google Cloud KMS and stores only the wrapped result. The separate unlock secret is stored only as an Argon2id hash.

This is split custody, not zero-knowledge or mathematically guaranteed time-lock encryption. The backend and KMS are technically involved in unwrapping a key after server-side checks. Service availability, database state, the server clock and KMS availability can affect when a key is released.

6. Service providers and other recipients

These providers may use subprocessors listed in their own documentation. They process data under their terms and, for Google, Supabase, RevenueCat and Amplitude, under the data-processing terms included in their service terms.

  • Google/Firebase: authentication, analytics, crash reporting, Cloud Run hosting, logging and Cloud KMS key wrapping.
  • Supabase: PostgreSQL database and backend data services.
  • Upstash: distributed per-account rate-limit counters.
  • RevenueCat: in-app purchase status, webhook delivery and purchase reconciliation.
  • Apple App Store and Google Play: sign-in and/or payment processing, refunds and store compliance; they may act as independent controllers under their own policies.
  • Amplitude: product analytics in production release builds.
  • Vercel: website hosting analytics and performance insights.
  • Google Ads: website conversion measurement, campaign reporting and remarketing cookies on gocapsula.com.
  • Google Fonts: remote delivery of website fonts and associated connection data.

7. International transfers

Cloud Run, Cloud KMS and the Supabase project are hosted in the United States (Cloud Run and Cloud KMS in us-central1). Other providers may also process data in the United States and in other countries where they or their subprocessors operate.

Where a restricted international transfer occurs, the intended safeguards are performance of the contract for transfers to the United States required to provide authentication, key custody, purchases, hosting, analytics and website advertising measurement, together with the data-processing terms included in the Google, Supabase, RevenueCat and Amplitude terms of service.

8. Retention

Account, capsule and wrapped-key records remain until a valid deletion request is completed or a lawful exception applies. Purchase, webhook, log and analytics periods above are the intended maximums.

  • Account, capsule and wrapped-key records: while needed to provide the account and scheduled key-custody service, then until a valid deletion request is completed or a lawful exception applies.
  • Normalized purchase/refund records: 10 years, where necessary for legal obligations and disputes.
  • Complete raw RevenueCat webhook events: 10 years.
  • Security and request logs: 30 days.
  • Firebase Analytics and Amplitude data: 14 months.
  • Google Ads website measurement: advertising cookies and identifiers processed by Google under its Ads policies. Capsula does not keep a separate copy of that data.

9. Your privacy rights

Depending on where you live, you may have rights to be informed; access, correct or delete data; restrict or object to processing; receive portable data; withdraw consent; opt out of legally defined sale or sharing; and complain to a data-protection or consumer authority. Mandatory rights are not limited by this policy.

Submit a request through laitelabs@gmail.com. We may verify that you control the account, but we will never ask for your unlock secret or plaintext encryption key.

The Capsula app does not include an advertising SDK, and Capsula does not sell your personal data. Firebase Analytics and Amplitude receive product-analytics events from the app to operate and improve Capsula, not to serve third-party ads. The gocapsula.com website loads a Google Ads tag that uses advertising cookies and online identifiers to measure campaigns, attribute visits after ad clicks and build remarketing audiences.

10. Children and teenagers

Capsula is intended only for people aged 18 or older. It is not directed at children. By creating an account you represent that you meet this age.

If we learn that an account belongs to someone under 18, we will delete the personal data we hold for that account as the law permits.

11. Security

Controls include local authenticated encryption, non-exportable KMS key-encryption keys, least-privilege runtime access, hashed unlock secrets, service-role database access, row-level database lockdown, authentication, rate limits and structured redaction of secret/key fields.

No security measure is absolute. Keep your device, chosen storage, account and unlock secret secure. Do not send the unlock secret or plaintext key to support.

12. Account deletion

Account deletion requests are submitted through the in-app account-deletion option, or by email to laitelabs@gmail.com and completed within 2 days.

Wrapped custodied keys are deleted when the account is deleted, which permanently prevents the corresponding capsules from being opened. See the Account Deletion page before making a request.

13. Changes and contact

We may update this policy when the service, providers or law changes. Material changes should be communicated through the app, website or account contact channel before they take effect where required.

Controller: Lesound App SAS. Privacy contact: laitelabs@gmail.com. Address: CR 48 46 54, Itagüí, Colombia.

Related legal documents

Terms of UsePurchases & Refunds PolicyAccount Deletion
Capsula

Encrypted digital time capsules you seal today and reopen in the future.

Language
EN
  • ENEnglish
  • ESEspañol
  • PTPortuguês

Product

  • How it works
  • Features
  • Pricing
  • Download
  • FAQ

Company

  • About
  • Contact
  • Security

Legal

  • Privacy
  • Terms
  • Purchases & refunds
  • Account deletion
© 2026 Capsula. All rights reserved.Made for memories · EN · ES · PT