Privacy Policy
Effective date: April 18, 2026 · Version 1.0
Self Capsule Pty Ltd (ABN 34 696 418 970), a company registered in New South Wales, Australia.
1. Introduction
SelfCapsule ("we", "our", or "us") is a local-first personal finance application. We built SelfCapsule with privacy as a core principle — your financial data is stored exclusively on your device and never transmitted to our servers.
This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. It applies to our website at selfcapsule.com and the SelfCapsule applications for macOS, iOS, and iPadOS.
2. Information the App Does Not Collect
SelfCapsule is designed so that your financial data never leaves your device. Specifically, the application:
- Does not transmit your transactions, budgets, account balances, or any financial data to any server
- Does not include analytics, telemetry, or usage-tracking code
- Does not require an account or login to use
- Stores all data locally in an AES-256 encrypted SQLite database on your device
- Processes AI-powered features entirely on your device using a local language model (Ollama) — no data is sent to external AI services
3. Network Connections Made by the App
The SelfCapsule application initiates only the following outbound network connections. Each is listed here so you can see the full surface at a glance.
a. License activation
When you activate or deactivate a SelfCapsule Pro license, the app contacts our license provider (Polar) to register or release your activation. No financial data, transactions, budgets, or settings are sent. Only your license key and a short device label are transmitted. The free tier never contacts Polar. Once activated, the app does not contact Polar again until you deactivate.
b. Update checks
When you click "Check for Updates" in Settings, the app fetches a small version manifest from our content delivery network to compare your installed version against the latest release. This check is manual only and never runs automatically or in the background. No personal information is sent.
c. Local AI inference
All AI features run entirely on your own device using a local language model. The app itself does not contact any remote AI service, and no prompt, transaction, or response ever leaves your machine. If you choose to download a new AI model from within the app, that download goes to the model provider under their own privacy policy.
No other network connections are initiated by the application. The app contains no analytics, telemetry, crash reporting, or automatic update checks.
4. Information We Do Collect
While the app itself collects no personal data, we do collect limited information through the purchase process and our website:
a. Purchase Information
When you purchase a SelfCapsule Pro license, our payment processor Polar (polar.sh) collects the information necessary to complete the transaction, including:
- Email address (for license key delivery)
- Payment details (processed securely by Polar via Stripe — we never see or store your full card number)
- Country of residence (for tax compliance)
b. License Validation
When you activate your Pro license, the app makes a one-time network request to validate your license key. After initial activation, the app functions fully offline.
c. Website Analytics
Our website uses server-side Google Analytics (via Google Tag Manager) to understand how visitors use the site. This collects:
- Pages viewed and referral source
- Device type and browser
- Anonymised IP address (truncated before storage — we never see your full IP)
- Ad conversion events (e.g., completed purchase)
We do not use third-party cookies for tracking. In regions that require consent (EU/EEA, UK, Brazil, South Africa), analytics are only activated after you grant permission via our consent banner. In California, analytics are active by default but you may opt out at any time.
d. Contact Form
When you submit our contact form, we collect:
- Name and email address
- Inquiry category, subject, and message content
- IP address and browser user agent (for spam prevention and rate limiting)
This information is sent via Resend (our email delivery provider) to our support team and is used solely to respond to your inquiry. You will also receive an automated confirmation email.
e. Conversion Tracking
When you arrive at our site from an advertisement, we may capture a click identifier from the URL (e.g., a Google or Meta click ID) and send it server-side with your purchase event to measure ad effectiveness. This data is processed server-side and subject to your consent preferences.
5. How We Use Your Information
The limited information we collect is used solely to:
- Deliver your license key via email
- Validate license activations
- Respond to your contact form inquiries and support requests
- Process refund requests
- Improve our website and understand how visitors find us (analytics)
- Measure the effectiveness of our advertising campaigns (conversion tracking)
- Comply with legal obligations (e.g., tax reporting, fraud prevention)
We do not sell, rent, or share your personal information with third parties for marketing purposes.
6. Third-Party Services
We use the following third-party services, each with their own privacy policies:
- Polar (polar.sh) — payment processing and license management
- Stripe — underlying payment infrastructure (via Polar)
- Google Analytics — aggregate website usage analytics (via server-side Google Tag Manager)
- Google Ads — conversion tracking for advertising campaigns
- Meta (Instagram/Facebook) — conversion tracking via Conversions API
- Resend — transactional email delivery for contact form submissions and automated confirmations
We encourage you to review their privacy policies. Analytics and advertising services are subject to your consent preferences.
7. Cookies and Tracking Technologies
Our website does not set third-party tracking cookies. We use server-side Google Tag Manager to process analytics and conversion data, which means tracking requests go through our server rather than directly from your browser to third parties.
Consent by Region
We use a geo-aware consent system to comply with local regulations:
- EU/EEA/UK (GDPR): Analytics and marketing tracking are disabled by default. We request your explicit consent before activating any tracking.
- California (CCPA/CPRA): Analytics are active by default. You may opt out at any time via the consent banner or the "Manage Preferences" link in our footer.
- Brazil (LGPD) and South Africa (POPIA): Same as GDPR — explicit opt-in consent required.
- Other regions: Analytics are active by default. You may manage your preferences at any time via the "Manage Preferences" link in our footer.
Managing Your Preferences
You can change your tracking preferences at any time by clicking "Manage Preferences" in the website footer. Your preference is stored locally in your browser (via localStorage, not a cookie) and respected on subsequent visits.
8. Data Retention
App data: Since your financial data is stored only on your device, you have full control over it. You can export or delete your data at any time through the app.
Purchase data: We retain your email address and purchase records for as long as necessary to provide license support and comply with tax and legal obligations.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding personal information we hold:
All Users
- Request access to the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information
- Withdraw consent for processing where consent is the legal basis
- Manage your analytics and marketing tracking preferences at any time via the "Manage Preferences" link in our website footer
European Economic Area (GDPR)
If you are in the EEA, our legal basis for processing your data is contract performance (license delivery) and legitimate interest (fraud prevention). You additionally have the right to data portability and the right to lodge a complaint with your local data protection authority.
California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.
Other Jurisdictions
We respect privacy rights under applicable local laws, including but not limited to the LGPD (Brazil), PIPEDA (Canada), POPIA (South Africa), and APPI (Japan). If your local law grants additional rights, we will honour them upon request.
To exercise any of these rights, contact us at privacy@selfcapsule.com. We will respond within 30 days (or sooner where required by law).
10. International Data Transfers
Your financial data remains on your device and is never transferred internationally. Purchase-related data processed by Polar and Stripe may be transferred to and stored in countries outside your own. These providers maintain appropriate safeguards, including Standard Contractual Clauses (SCCs) for transfers from the EEA.
11. Data Security
Within the app, your data is encrypted at rest using AES-256 encryption. For purchase transactions, all payment data is handled by PCI DSS-compliant processors (Stripe via Polar). We do not store payment card details on our systems.
12. Children's Privacy
SelfCapsule is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. We encourage you to review this page periodically.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: