CapsulaCapsula

Capsula — Privacy Policy

Effective date: June 27, 2026 Last updated: July 27, 2026

Data controller: Capsula ("we", "us", "our"). Contact: hello@usecapsula.app

Capsula is an iOS application for tracking dietary supplements and seeing their personal correlation with your self-reported wellbeing ("Track your supplements. See the effect."). This Privacy Policy explains what data we collect, why, who processes it on our behalf, and the choices and rights you have.

Capsula provides information about supplements and your own logged data. It is not a medical device, does not diagnose, treat, cure, or prevent any disease, and does not provide medical advice. See the Health Disclaimer below.


1. What data we collect and why

We collect only what we need to operate the app. The table below mirrors our Apple App Store privacy disclosures (PrivacyInfo.xcprivacy + App Store Connect data questionnaire).

Data Examples Why we collect it App Store classification
Email address Your sign-in email Account creation and authentication (Supabase); subscription management (RevenueCat) Linked to you
Name Full name from Apple Sign In (full_name), if you choose to share it Personalizing your account Linked to you
User ID Supabase user UUID; RevenueCat app user ID Authenticating you, syncing your data, managing your subscription Linked to you
Health & Fitness Supplement names, dosage, timing/schedule; wellbeing you enter (sleep, energy, mood and focus scores, sleep duration, free-text notes, and self-reported observation tags) Core app function: logging your stack and computing your personal correlation analysis Linked to you
Other user content Messages you send to the AI Coach / Nutrition Advisor; your free-text wellbeing notes and self-reported observation tags Generating AI responses to your questions and your personal AI summary Linked to you
Purchase history Subscription status and transactions Managing your Capsula Pro subscription and entitlements Linked to you
Device ID Anonymous installation identifier; Mixpanel distinct ID; Statsig stable ID. No IDFA, no cross-app/website tracking. Product analytics and feature experiments (consent-gated) Linked to you · Analytics
Product interaction In-app events (Mixpanel); experiment assignments (Statsig) Understanding and improving how the app is used; A/B testing (consent-gated) Linked to you · Analytics + Personalization
Crash data Crash reports (Sentry), with PII scrubbed Diagnosing and fixing crashes (consent-gated) Not linked to you
Other diagnostic data AI call traces (Langfuse, server-side); Sentry diagnostics — PII scrubbed Reliability and quality of the AI features and the app Not linked to you

We do not sell your personal information, and we do not use your data for cross-app advertising or third-party ad targeting.


2. Third-party processors

We use the following service providers ("processors") who handle data on our behalf, only for the purposes described. Each is bound by a data processing agreement (or equivalent terms).

Processor Purpose Data involved
Supabase Authentication, database, and cloud sync (Postgres) Email, name, user ID, health & fitness data, AI messages (stored), purchase status
Anthropic (Claude) AI Nutrition Advisor / AI Coach, and your personal AI summary in Insights. Data is sent (via our server-side Edge Function proxy) to Anthropic for AI processing Messages you send to the AI Coach, plus context automatically derived from your logged data to generate your AI summary: your free-text wellbeing notes, self-reported observation tags, and wellbeing dimension values (sleep, energy, mood, focus)
Mixpanel Product analytics (consent-gated) Anonymous device/distinct ID, bucketed product-interaction events
Statsig Feature flags and A/B testing (consent-gated) Anonymous stable ID, experiment assignments
Sentry Crash reporting (consent-gated; EU region ingestion) Crash diagnostics with PII scrubbed
RevenueCat Subscription management App user ID, email address, purchase/subscription status
Langfuse AI call observability (server-side only) AI request/response traces with PII scrubbed
Apple Apple Sign In Authentication token, optional name/email relay
Google Google Sign In Authentication token, email
Apple AdServices / Apple Search Ads (ASA) App install attribution, if applicable Attribution token (no IDFA-based tracking)

We do not knowingly send your raw health scores or message content to processors beyond what is described above.


3. Consent


4. Your rights

4.1 GDPR (EU/EEA — DE, ES, and others)

Subject to applicable law, you have the right to: access your data; rectify inaccurate data; erase your data (Art. 17); restrict or object to processing; data portability (Art. 20); and to withdraw consent at any time. You may also lodge a complaint with your supervisory authority. Our legal bases include performance of a contract, your consent (analytics, crash reporting, and processing of health data), and our legitimate interests.

4.2 CCPA / CPRA (California)

You have the right to know/access, delete, and correct your personal information, and to opt out of the sale or sharing of personal information. Capsula does not sell or share personal information as those terms are defined under the CPRA. We will not discriminate against you for exercising your rights.

4.3 KVKK (Türkiye)

Under Law No. 6698 (KVKK), you have rights including learning whether your data is processed, requesting information, requesting correction/erasure, and objecting to results of automated processing. An explicit-consent (açık rıza) and clarification (aydınlatma) flow is required and is planned before TR launch.

4.4 US state consumer health data (Washington, Nevada, Connecticut, and others)

Some US states regulate "consumer health data" separately from general privacy law. Your self-reported wellbeing scores and the supplements you log may qualify as consumer health data under laws such as the Washington My Health My Data Act (MHMDA), Nevada SB 370, and the Connecticut Data Privacy Act. Where these laws apply, you may have the right to confirm whether we collect, share, or sell your consumer health data, to access it, to withdraw consent, and to have it deleted. We do not sell your consumer health data, and we do not share it except with the processors described in Section 2 to provide the service. By creating an account and entering data, you consent to our collection of the consumer health data you choose to log; you can withdraw by deleting your data.

How to exercise rights: Most rights can be exercised directly in the app (account and data deletion). For other requests, contact hello@usecapsula.app. We will respond within the timeframes required by applicable law.


5. Data deletion

You can delete your account and data from within the app. Deletion is a cascade: it removes your cloud data (Supabase) and your on-device data, including supplements, dose logs, wellbeing scores, and AI messages. This is handled by our in-app account deletion flow (AccountDeletionService) together with our server-side delete-user function.

When you delete your account, we also stop analytics and crash collection associated with you. Some data held by independent processors may persist briefly in backups or be retained where required by law, then deleted on their standard schedules.


6. Data retention and location


7. About your health data


8. Health disclaimer

Capsula is not a medical device and does not provide medical, diagnostic, or treatment advice. The information, correlations, and AI responses in the app are for informational and educational purposes only.


9. Children

Capsula is intended for users aged 16 and older. The AI Coach includes an age gate. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact hello@usecapsula.app and we will delete it.


10. Data security

We use technical and organizational measures to protect your data, including: - Row-Level Security (RLS) in our database so users can access only their own data; - JWT-based authentication for API access; - Encryption in transit (TLS/HTTPS) for data sent between the app and our services; - Server-side AI proxy: AI provider API keys are never stored in the app; AI requests pass through our Edge Function; - PII scrubbing for crash and AI-observability diagnostics (e.g., Sentry sendDefaultPii=false plus additional scrubbing).

No method of transmission or storage is 100% secure, but we work to protect your data and respond to incidents as required by law.


11. Changes to this policy and contact

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where required, notify you in the app. Your continued use after changes take effect constitutes acceptance, to the extent permitted by law.

Questions or requests: hello@usecapsula.app Data controller: Capsula Governing law / jurisdiction: Türkiye (courts of İstanbul)