Privacy Policy
Last updated: September 8, 2026
This policy explains what personal data URLCapsule collects on the website and in the iOS app, why, and your rights. We are the data controller. We keep data collection to the minimum needed to run the Service and we never sell your data.
1. Who we are
URLCapsule is operated by Digital Nafta Portal FZCO, a company licensed by the International Free Zone Authority (IFZA) of Dubai under licence number 78656, with its registered address at Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates ("we"). We are the data controller for the personal data described in this policy. For any privacy request, contact support@urlcapsule.com.
We process personal data in line with the data protection law of the United Arab Emirates, Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (PDPL). If you are in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR) also applies to our processing of your data under its Article 3(2), because we offer the Service to you there. Where this policy refers to GDPR rights or safeguards, they apply to you as a user in the EEA.
2. What we store
- Account data: your email address, a securely hashed password, plan status, a save token used by the Apple Shortcut, and the version and date of your optional AI permission.
- Your saved links: the URLs you save, plus the title, description, favicon, a screenshot of each page, extracted text, and, with your AI permission, AI-generated categories and summaries.
- Billing data: if you subscribe on the web, Stripe processes your payment and we store a Stripe customer and subscription identifier and your plan status. If you subscribe in the iOS app, Apple processes your payment through the App Store and we store an Apple transaction identifier and your plan status. We do not store your full card number in either case.
- Technical data: limited logs (IP address, timestamps, error data, rate-limit counters) needed for security and to operate the Service.
If you use the iOS app, the app adds product analytics and diagnostics on top of this. Section 5 and section 6 describe exactly what the app collects and how to switch the analytics off.
3. Why we process it (legal bases)
- To provide the Service (contract): store, capture and search your links, run your account.
- To take payment (contract): manage your subscription through Stripe (web) or the App Store (iOS in-app purchase).
- Optional AI features (consent): sharing the content needed for categorization, summaries, semantic search, answers, content research and audio with OpenAI and Google Gemini. Permission is off by default and applies to your account across devices. Basic saving, screenshots and regular search work without it.
- Optional website analytics (consent): product interaction events and technical browser information, only after you enable usage sharing in Settings.
- Security and abuse prevention (legitimate interest): logs, rate limiting.
- Product analytics and diagnostics in the iOS app (legitimate interest, with an opt out): understanding which screens people use and where the app fails, so we can improve it. You can turn this off at any time from Settings inside the app, as described in section 6.
- Legal compliance (legal obligation): tax and accounting records where required.
4. Subprocessors
We share the minimum data necessary with trusted providers who process it on our behalf:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payments and subscriptions (web) | Email, billing details, subscription status |
| Apple | Payments and subscriptions (iOS in-app purchase) | Apple transaction identifier, subscription status |
| OpenAI | Optional categorization, summaries, semantic search, suggestions and answers | Saved URLs and domains, titles, descriptions, category names, extracted page text, search queries, questions, language and collection counts |
| Google Gemini | Optional content research, PDF and image understanding, audio script generation and speech synthesis | Saved URLs and domains, titles, extracted content, images or PDF files, generated scripts, and language and voice choices |
| Hetzner | Screenshot and capture engine hosting | The URLs being captured |
| Banahosting | Application and database hosting | Account data and saved links |
| Google LLC (Firebase Analytics, Crashlytics, Performance Monitoring and Google Analytics) | Product analytics for the app and optional website analytics | Device, browser and installation identifiers, approximate location derived from IP, product interactions, purchase events, crash information, timing and technical diagnostics. Product analytics events exclude saved URLs, titles, search text and link content |
We are established in the United Arab Emirates and our providers operate from the European Union, the United States and other countries. Where personal data of users in the EEA is transferred outside the EEA, including to us, the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses. Transfers of personal data outside the United Arab Emirates are made in line with the PDPL.
Your AI choice: before enabling AI, you can review the providers and data listed above and choose Allow AI with OpenAI and Gemini or Continue without AI. You can withdraw permission from AI permission in Settings. This stops new AI requests and later stages of queued work. It cannot recall requests already sent to a provider or remove existing results. Your saved links and earlier results remain available.
5. The URLCapsule iOS App
URLCapsule is also available as an iOS app, URLCapsule: Visual Bookmarks (bundle identifier com.digitalnafta.urlcapsule). The app signs you in to the same account and uses the same servers as the website, so sections 1 to 4 apply to it too. This section covers what is specific to the app.
- Account email, linked to your identity: we use the email address of your account to authenticate you and to keep your library attached to you. Signing in is required because your links are stored on our servers so they follow you across devices.
- Saved links and their screenshots, linked to your identity: the URLs you save from the app, together with the title, description, favicon, the screenshot of the page, extracted text and the AI categories and summaries described in section 2. This is the core function of the app.
- Diagnostics: crash reports, operation timing, fixed error codes and technical device information help us find failures and delays. Diagnostics can be associated with Analytics identifiers and subscription events, so we treat them as data linked to you.
- Widget and Share Extension: the home screen widget and the share sheet extension exchange data with the app locally on your device through a shared App Group container (group.com.digitalnafta.urlcapsule). They send nothing beyond what the app itself sends.
- No advertising and no cross app tracking: the app shows no ads and contains no advertising SDK. It does not read the Advertising Identifier (IDFA) and therefore never asks for App Tracking Transparency permission. We do not track you across apps or websites owned by other companies, and we do not share your data with data brokers.
Deleting your data from the app: the Settings screen includes a Delete Account option that deletes your account, your saved links and their screenshots from our servers. Links you delete individually go to the Trash first and are permanently removed after 30 days, which gives you time to restore something deleted by mistake.
6. App analytics and diagnostics
The iPhone and iPad app measures product use through Firebase Analytics, Crashlytics and Performance Monitoring. Product analytics in the app can be disabled in Settings. Mac usage sharing is off by default and can be enabled separately in Settings.
- What the events describe: screens opened, time spent actively using a screen, actions and their outcomes, operation duration, fixed error categories, onboarding steps and subscription events. Subscription events include a transaction identifier, product, price and currency.
- Identifiers and attribution: the iOS app sends a random identifier also used as the app account token for App Store purchases. Firebase creates installation and app instance identifiers. These identifiers can connect product use, diagnostics and subscriptions. They are not your email address, but we treat this information as linked to you. Apple Ads campaign attribution, when available, is used to understand acquisition.
- Technical information: app and operating system versions, device information, crash reports and performance measurements. Google Analytics derives approximate location, such as country or city, from network information. We do not request precise location for analytics.
- Content excluded from product analytics: saved URLs, page titles, clipboard text and images, search terms, questions and page content. Our onboarding experiment also records a limited set of predefined steps and outcomes on our own server. Optional AI processing is separate and is described in section 4.
- No advertising tracking: our Firebase integration excludes IDFA support and denies advertising storage, advertising user data and advertising personalization. We do not use this data to track you across other companies' apps or websites.
Turning it off: the app's Product analytics switch stops new product analytics and diagnostic submissions and clears pending local analytics data. It does not erase reports already received by Google or delete your account and purchase records.
In App Store terms, the app collects the following categories. These categories are linked to you and are not used for tracking across other companies' apps or websites:
| Data | Purpose |
|---|---|
| Email address and account identifiers | Account and app functionality. Analytics identifiers also support product measurement |
| Saved links, page content, notes and uploaded images | App functionality and optional AI features |
| Searches and questions submitted for a response | App functionality and optional AI features |
| Product interactions, device identifiers, approximate location and acquisition attribution | Analytics |
| Purchase history | Subscription functionality and analytics |
| Crash, performance and other diagnostic data | App functionality and analytics |
Mac clipboard history
The Mac app can keep a recent history of copied text, URLs and images on your Mac. When automatic URL saving is enabled, detected URLs are sent to your URLCapsule account and marked From Mac. Other copied text and images stay in the local clipboard history and are not sent as analytics. You can pause capture, disable automatic saving and remove local history in Settings. Local clipboard history is separate from the links already saved to your account.
Website analytics
Website usage sharing is off by default. If you enable Share product usage data in Settings, Google Analytics receives fixed product event names, the screen or action involved, the result and duration, plus technical browser information and a browser identifier. It does not receive your saved URLs, page titles, search text, questions or link content from these events. The website sends a fixed location, https://urlcapsule.com/app, the title URLCapsule and an empty referrer. Enhanced measurement is disabled.
You can turn website usage sharing off in Settings. The browser stops sending usage events. This does not withdraw AI permission, which has a separate account setting, and it does not delete analytics already received by Google.
7. Retention
We keep your data while your account is active. If you delete a link it is removed, and if you delete your account we delete your personal data and saved content within a reasonable period, except where we must keep limited records (for example billing) to meet legal obligations.
Links deleted one by one in the iOS app stay in the Trash for 30 days before being permanently removed. Analytics already received by our providers follows the configured retention settings. Switching Product analytics off clears pending local analytics data and stops new submissions. It does not retroactively delete provider records. You can contact us to request access or deletion.
8. Your rights
Under the PDPL, and under GDPR if you are in the EEA, you have the right to access, rectify, erase, restrict, and port your data, and to object to certain processing. You can export or delete your data from within the app, or email us. In the iOS app, Delete Account in Settings erases your account and saved content, and the Product analytics switch in Settings is how you object to analytics processing. You may withdraw consent at any time.
If you are in the EEA, you also have the right to lodge a complaint with the data protection supervisory authority of the country where you live or work, or where the issue you are complaining about took place. If you are in the United Arab Emirates, you may raise a complaint with the competent data protection authority there (the UAE Data Office). We would appreciate the chance to address your concern first, so please write to us before contacting an authority.
9. Cookies
We use an essential session cookie to keep you logged in and a CSRF token to protect your account. If you opt in to website usage sharing, Google Analytics may store analytics cookies to recognize that browser. The website remembers your analytics choice, theme and filters in local browser storage. AI permission is stored with your account. We do not use advertising cookies.
10. Security
Passwords are hashed, traffic is encrypted in transit (HTTPS), and access to your links is scoped strictly to your account. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
Questions about your privacy or a data request? Write to support@urlcapsule.com and we will respond within the timeframes set by applicable data protection law (within one month under GDPR).