Privacy Policy
Last updated October 11, 2026
CapsulePad is built to run entirely on your own devices — Mac, iPhone, and iPad. It has no backend of its own — there is no server of ours receiving, relaying, or logging the notes you write. This policy explains what that means for your data.
The short version
- CapsulePad has no account system and no server of ours in the request path for your notes.
- Every note is stored on-device first, in a local SwiftData store, and works fully offline.
- Sync across your devices happens only through your own private iCloud database (Apple's CloudKit), using Apple's infrastructure — not ours.
- A note you lock is encrypted on-device; the key lives in your own iCloud Keychain, never on a server of ours.
- CapsulePad contains no analytics SDKs, no advertising SDKs, and no third-party trackers of any kind.
Information we collect
None. We do not operate any servers that receive, log, or process your notes or your usage of the app. The app does not ask for your name, email address, or any account credentials of ours.
Where your notes are stored
Your notes live in a local SwiftData (SQLite) store on each device — your Mac's Application Support folder, or the equivalent app container on iPhone/iPad. This is the primary copy CapsulePad reads and writes, and the app works fully offline with iCloud sync turned off.
iCloud sync (CloudKit)
If you turn on "Sync with iCloud" in Settings, CapsulePad uses SwiftData's native CloudKit integration to mirror your notes into your own private CloudKit database — the same iCloud account you're already signed into, not a database we run or can read. Changes on one device typically reach your other devices within seconds. Toggling this setting takes effect the next time you launch the app, not instantly, since the sync database is fixed for the life of that launch. This data is governed by Apple's own privacy policy; CapsulePad has no separate copy of it and no server-side access to it.
Locked notes
Locking a note encrypts its body on-device (AES-GCM) before it's ever saved or synced — the title stays visible so you can still find the note, but the body is unreadable without unlocking it again with Face ID, Touch ID, or your device passcode. There's no persistent "unlocked" session: CapsulePad asks again every time you open a locked note. The decryption key lives in your iCloud Keychain, not on a server of ours, which is what lets a note locked on one device be unlocked on your other signed-in devices too. Exporting a locked note (see below) never includes its real body in a plain-text format — only the full-fidelity CapsulePad archive keeps the encrypted bytes, still unreadable without your key.
Export & import
You can export all of your notes at any time as Markdown, plain text, or a full-fidelity CapsulePad archive file, and import that archive back in later — entirely on-device, using the system's own file picker. We never see these files; they go directly from your device to wherever you choose to save them.
Information stored on your device
Your notes, app preferences (dock placement on Mac, default note color, appearance, sync and lock settings), and, if enabled, your CloudKit sync data are stored locally on each device. None of it is transmitted to us, because CapsulePad has nowhere of ours to send it.
Third parties
CapsulePad does not integrate with any analytics, advertising, or crash-reporting service of our own. It makes no network requests to servers of ours at all — the only network activity is Apple's own iCloud/CloudKit sync, if you have it enabled.
Children's privacy
CapsulePad is a general-purpose productivity utility and is not directed at children. It does not knowingly collect information from anyone, of any age, because it operates no server that collects information at all.
Deleting your data
Deleting a note permanently in the app removes it locally and propagates that deletion to your other devices the next time they sync, if iCloud sync is enabled. Uninstalling CapsulePad removes the app and its local data from that device; your CloudKit data remains in your own iCloud account until you remove it there or delete it from another synced device.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Since CapsulePad doesn't collect contact information, we're not able to notify you directly — check back here if you'd like to stay current.
Contact
Questions about this policy? Visit the Support page.