Privacy policy

What we keep, and what we never touch.

Effective
12 August 2026
Version
4
Covers
trycapsule.app, the guest camera and the film app

A privacy policy is usually written to be survived rather than read. This one is a promise you can check: the photographs of your night reach the people who were there and nobody else.

The short of it — a host gives us an email address. A guest gives us almost nothing, because a guest is not an account. We hold the photographs, we hand them back, and in between we do not look at them, learn from them, or show them to anyone.

Version 4 replaces the policy of 3 March 2026. What changed: we named every processor we use, and cut log retention from ninety days to thirty.

Capsule is made by Capsule Camera Ltd, registered in England and Wales (14892207) at 4 Ravey Street, London EC2A 4QP. Eleven of us, in London and Lisbon. Under the UK GDPR we are the controller: if something goes wrong with your data, we are the ones who answer for it. ICO registration ZB612904.

This covers the site you are reading, the camera a guest opens from a film link, and the app a host uses to run a film. It stops where your download begins.

A host is the only person with an account, and it is deliberately thin. No password, because we would rather not hold one — you sign in with a link we email you.

Your email address
The account is the address. Sign-in links, seal and develop notices, receipts. Nothing else without asking.
The films you make
Name, seal time, develop time, shots per guest, film stock. They live as long as the film does.
The guests you invited, if we sent the invitations
Deleted fourteen days after the film develops. Send the link yourself, as most hosts do, and we never learn who you sent it to.
What you paid
Stripe takes the card; we never see the number. We keep the last four digits, the amount and the date for six years — tax law.
Ordinary server logs
IP address, browser, page, time. Thirty days, then gone. For faults and abuse, nothing else.

Lawful basis: our contract with you, except the logs, which are legitimate interests — namely keeping the thing running.

Almost nothing, and that is the design rather than an oversight. No sign-up, no password, no phone number, no address book, no location. A guest taps a link and has a camera.

The photographs they take
The point of the whole thing. They have a clause of their own below.
A seat in the film
The link carries a random token saying which seat a shot belongs to, so the counter works and you can pull your own photo back. Not a name.
A name, only if they type one
Leave the box empty and you are Guest 7 for the life of the film. Plenty of people do.
An address, only to receive the roll
One email address, used for that film and deleted thirty days after it develops.

We do not know a guest’s name, we cannot reach their phone, and we could not tell you which other films they have been in.

A photograph is the most personal thing anyone hands us. It uploads over an encrypted connection and is encrypted again at rest, with AES-256, on storage in Dublin. A backup goes to Frankfurt every hour.

The pixels are untouched: the film look is a second copy, so the file your camera made is the one in your download. We remove exactly one thing: the location tag. GPS coordinates are stripped on upload, before the file is stored. A photograph should not be able to tell a stranger which house you were in.

While a film is sealed, nobody sees it. Not the guests, not the host, not us: sealed films do not open in any internal tool we have.

Free films
Deleted thirty days after the film develops. We warn you twice first.
Paid films
Kept until you delete them. That is what you paid for.
A film you delete
Originals within a day, backups within thirty. Then nobody can get it back, including us.
A frame someone asks us to pull
Gone from every copy we hold within a day. We cannot reach a download somebody already made, and we will not pretend otherwise.

Two engineers can open a stored file. It takes a written reason and a second person’s approval, it is logged, and if we open a frame in your film we tell you.

Everything above is what we do. This is the part we would have to break the company to change, set down in the same document as the boring ones.

We do not run data centres and we do not send our own email. Five companies process data on our behalf, each contracted to our instructions only. This is the whole list.

Processor What they do Where
Amazon Web Services Storage — where the films live Dublin
Cloudflare The network in front of everything Global edge
Stripe Payments. We never see the card Dublin
Postmark Sign-in links and film notices United States
Plausible Visit counts, without cookies Frankfurt

Add one or drop one and this table changes the same day, and the version at the top goes up.

One cookie. capsule_session holds a signed session identifier and nothing else, so a host does not have to sign in again on every page. It expires when you close the browser, or after thirty days if you ticked keep me signed in.

That is the whole cookie policy. No banner, because there is nothing to consent to: no ad cookies, no third-party pixels, no session recording, no heatmaps.

Guests get no cookie at all. The shot counter lives in your own browser’s storage, on your own phone.

We count visits with Plausible, which measures pages without cookies. We can tell you this page was read four thousand times last month. We cannot tell you one thing about who read it.

Films, databases and backups sit in the European Union — Dublin, backed up to Frankfurt — and that is where they stay.

Two things cross a border, and we will name both. Developed images go over Cloudflare’s network, so a cached copy can rest on a server near whoever is looking at it, anywhere, for up to twenty-four hours. And Postmark, who send our email, are in the United States; all that reaches them is an email address and a film name.

Both run on the UK International Data Transfer Addendum and the EU standard contractual clauses, with a risk assessment for each. Ask and we will send you the actual documents.

You have to be eighteen to start a film, because starting one is a purchase. Guests must be sixteen. We do not knowingly hold an account belonging to a child, and if we find one we close it.

The honest part: children are at parties, and children end up in photographs. No policy solves that. What we can do is this — a parent or guardian can ask us to pull any frame a child appears in, from any film. We do not ask for proof and we do not ask why. It goes within a day.

You can ask for a copy of everything we hold about you, ask us to correct it, delete it, hand it over in a portable file, object to a use, or withdraw consent. Rights, not favours, and free.

Email privacy@trycapsule.app and say what you want in your own words. No form, no portal, no reference number. If it is about one film, name the film.

We answer within thirty days and usually within three. If the request touches a film we may ask you to confirm you control the address the link went to — the only way to tell you from someone else asking for your photographs.

If we get it wrong, complain to the Information Commissioner’s Office. You do not have to come to us first. We would prefer it. Your call.

It will change, because the company will. The version goes up, the date changes, and old versions stay — ask and we will send you any of them.

If a change is material — a new processor, a longer retention period, a new use of anything — we email every host before it takes effect. Not after.

Ines Duarte looks after privacy at Capsule. She reads privacy@trycapsule.app and answers it herself. If you would rather write, the address below is a real office.

Capsule Camera Ltd 4 Ravey Street London EC2A 4QP United Kingdom

Company 14892207 · ICO ZB612904. Everything that is not a privacy question — support, events, press — is on the contact page.

That is all of it. Now put the phone down and have the night.