Privacy Policy
Last updated: August 11, 2026
This policy explains what personal data URLCapsule collects on the website and in the iOS app, why, and your rights. We are the data controller. We keep data collection to the minimum needed to run the Service and we never sell your data.
1. Who we are
URLCapsule is operated by Orion Sky Marketing Ltd ("we"). For any privacy request, contact support@urlcapsule.com. We process personal data in line with the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).
2. What we store
- Account data: your email address, a securely hashed password, plan status, and a save token used by the Apple Shortcut.
- Your saved links: the URLs you save, plus the title, description, favicon, a screenshot of each page, extracted text, and AI-generated categories and summaries.
- Billing data: if you subscribe on the web, Stripe processes your payment and we store a Stripe customer and subscription identifier and your plan status. If you subscribe in the iOS app, Apple processes your payment through the App Store and we store an Apple transaction identifier and your plan status. We do not store your full card number in either case.
- Technical data: limited logs (IP address, timestamps, error data, rate-limit counters) needed for security and to operate the Service.
If you use the iOS app, the app adds product analytics and diagnostics on top of this. Section 5 and section 6 describe exactly what the app collects and how to switch the analytics off.
3. Why we process it (legal bases)
- To provide the Service (contract): store, capture and search your links, run your account.
- To take payment (contract): manage your subscription through Stripe (web) or the App Store (iOS in-app purchase).
- Security and abuse prevention (legitimate interest): logs, rate limiting.
- Product analytics and diagnostics in the iOS app (legitimate interest, with an opt out): understanding which screens people use and where the app fails, so we can improve it. You can turn this off at any time from Settings inside the app, as described in section 6.
- Legal compliance (legal obligation): tax and accounting records where required.
4. Subprocessors
We share the minimum data necessary with trusted providers who process it on our behalf:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payments and subscriptions (web) | Email, billing details, subscription status |
| Apple | Payments and subscriptions (iOS in-app purchase) | Apple transaction identifier, subscription status |
| OpenAI | AI categorization, summaries, semantic search | Saved page text and titles (not sent for ads or model training) |
| Hetzner | Screenshot and capture engine hosting | The URLs being captured |
| Banahosting | Application and database hosting | Account data and saved links |
| Google LLC (Firebase Analytics) | Product analytics for the iOS app | Firebase device and installation identifiers, product interaction events. No email address, no saved URLs, no advertising identifier |
Where a provider is outside the EU, transfers are covered by appropriate safeguards such as Standard Contractual Clauses.
5. The URLCapsule iOS App
URLCapsule is also available as an iOS app, URLCapsule: Visual Bookmarks (bundle identifier com.digitalnafta.urlcapsule). The app signs you in to the same account and uses the same servers as the website, so sections 1 to 4 apply to it too. This section covers what is specific to the app.
- Account email, linked to your identity: we use the email address of your account to authenticate you and to keep your library attached to you. Signing in is required because your links are stored on our servers so they follow you across devices.
- Saved links and their screenshots, linked to your identity: the URLs you save from the app, together with the title, description, favicon, the screenshot of the page, extracted text and the AI categories and summaries described in section 2. This is the core function of the app.
- Diagnostics, not linked to your identity: crash and performance data used to find and fix failures. It is not tied to your account and we do not use it to profile you.
- Widget and Share Extension: the home screen widget and the share sheet extension exchange data with the app locally on your device through a shared App Group container (group.com.digitalnafta.urlcapsule). They send nothing beyond what the app itself sends.
- No advertising and no cross app tracking: the app shows no ads and contains no advertising SDK. It does not read the Advertising Identifier (IDFA) and therefore never asks for App Tracking Transparency permission. We do not track you across apps or websites owned by other companies, and we do not share your data with data brokers.
Deleting your data from the app: the Settings screen includes a Delete Account option that deletes your account, your saved links and their screenshots from our servers. Links you delete individually go to the Trash first and are permanently removed after 30 days, which gives you time to restore something deleted by mistake.
6. Analytics in the iOS App
The app measures how the product is used so we can see which screens matter and where people get stuck. There are two parts to it, and a single switch turns both off.
- Our own product analytics, not linked to your identity: the first time the app runs it generates a random installation identifier on your device and stores it in the iOS Keychain. It is not the Advertising Identifier (IDFA), it is not identifierForVendor, and it is not synced to iCloud. Together with it we record product usage events whose names are short fixed labels in snake_case, for example an event recording that a screen was opened. Those events carry no URLs, no page titles and no email address.
- Google Firebase Analytics, not linked to your identity: Google LLC processes product interaction events on our behalf as a subprocessor. We ship the variant of Firebase Analytics built without advertising identifier support (FirebaseAnalyticsWithoutAdIdSupport), so no advertising identifier is read and nothing is used for advertising. Firebase generates its own device and installation identifiers. Neither those identifiers nor the events are attached to your account identity, and none of it is used to track you across other companies' apps or websites.
How to turn it off: the Product analytics switch in the app Settings stops all of the above. Switching it off ends collection for both our own analytics and Firebase, and it also deletes any events still queued on your device waiting to be sent. Settings additionally lets you reset the installation identifier whenever you want, which breaks the link with anything measured before the reset.
In App Store terms, this is what the app collects:
| Data | Used for | Linked to your identity | Used for tracking |
|---|---|---|---|
| Email address | App functionality (account and sign in) | Yes | No |
| Saved URLs and their screenshots | App functionality (your bookmark library) | Yes | No |
| Product interaction events and installation identifier | Analytics, to improve the app | No | No |
| Crash and performance data | Diagnostics | No | No |
7. Retention
We keep your data while your account is active. If you delete a link it is removed, and if you delete your account we delete your personal data and saved content within a reasonable period, except where we must keep limited records (for example billing) to meet legal obligations.
Links deleted one by one in the iOS app stay in the Trash for 30 days before being permanently removed. Product analytics events are kept in aggregated form only for as long as they are useful to improve the product, and events still queued on your device are deleted as soon as you switch Product analytics off.
8. Your rights
Under GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to certain processing. You can export or delete your data from within the app, or email us. In the iOS app, Delete Account in Settings erases your account and saved content, and the Product analytics switch in Settings is how you object to analytics processing. You may withdraw consent at any time and lodge a complaint with the Spanish data protection authority (Agencia Española de Protección de Datos, aepd.es).
9. Cookies
We use a single essential session cookie to keep you logged in and a CSRF token to protect your account. We do not use advertising or third-party tracking cookies. The iOS app uses no advertising or tracking cookies either.
10. Security
Passwords are hashed, traffic is encrypted in transit (HTTPS), and access to your links is scoped strictly to your account. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
Questions about your privacy or a data request? Write to support@urlcapsule.com and we will respond within the timeframes set by GDPR.