Daily Capsule
Privacy Terms

EN|DE

Privacy Policy

Last updated: May 2026

This Privacy Policy describes how Daily Capsule ("the app", "we") handles personal data when you use our mobile application. We take your privacy seriously — the app is built around anonymity by default, and we collect only what is strictly necessary to run the service.

1. Who we are

Controller:
Power of Life Labs GmbH
Oberdorfweg 9, 8704 Herrliberg, Switzerland
UID: CHE-495.719.617
Contact: hello@daily-capsule.com

Daily Capsule is operated by Power of Life Labs GmbH. This policy applies to the mobile app only, not to our website.

2. What data we collect

Daily Capsule is designed so that you can use the entire service without revealing who you are. Here is every piece of data we collect, why, and on what legal basis.

2.1 Automatically on first launch

  • Anonymous user ID (a random UUID assigned by our authentication provider). This is not linked to your device, Apple ID, phone number, or email unless you explicitly choose to link a sign-in later.
  • App preferences you choose during onboarding: display language, daily reminder time, translation consent.

Legal basis: Contract performance (Art. 6(1)(b) GDPR / Art. 31 revDSG) — necessary to provide the service.

2.2 Content you create

  • Alias — a pseudonymous nickname you choose or generate. Visible to other users only on reflections you explicitly share.
  • Reflections — the text you write in response to daily prompts. Reflections are private by default. Only you can see them, unless you tap "Release It" to share one anonymously.
  • Shared reflections — if you share a reflection, the text is displayed to other users under your alias.
  • Reactions — when you tap a reaction (touched / felt that / holding / thank you) on another user's reflection, we store the reflection ID, your user ID, and the reaction type.

Legal basis: Contract performance + your explicit action (choosing to share or react).

2.3 Optional: linked sign-in identity

If you choose to use Sign in with Apple, Continue with Google, or Email magic link from the onboarding backup step (or later from settings), we store the identifier returned by that provider (e.g., your Apple relay email, your Google sub, or the email you typed). This allows you to recover your account on a new device.

Legal basis: Your consent (Art. 6(1)(a) GDPR / Art. 31 revDSG) — you can skip this step entirely. If you do link an identity, you can delete your account at any time to remove it.

2.4 Moderation data

Before a reflection is shared publicly, its text is sent to our AI moderation service (see §4) to check for hate speech, threats, sexual content involving minors, doxxing, spam, or crisis signals. The moderation result (safe / block / crisis) is used to decide whether to share the reflection or offer crisis support. We do not store the moderation result against you.

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — keeping the community safe.

2.5 Optional: voice dictation

If you tap the microphone icon while writing a reflection, the app asks for permission to use the microphone and the system speech recognizer. Audio is captured only while you are dictating, and transcription happens on your device through Apple's built-in speech recognition. Audio is never recorded, stored, or sent to our servers. Only the resulting text — the same text you would have typed — is saved as your reflection. You can revoke microphone permission any time in your device settings.

Legal basis: Your consent (Art. 6(1)(a) GDPR / Art. 31 revDSG) — you can write reflections with the keyboard instead.

2.6 What we do NOT collect

  • No IP addresses beyond what Supabase logs briefly for abuse prevention
  • No device identifiers, advertising IDs, or fingerprints
  • No location data
  • No photos, contacts, or any background microphone access
  • No analytics or tracking cookies
  • No ads, no ad networks

3. Why we use your data

  • To provide the daily ritual (fetch today's prompt, save your reflection, display the shared feed).
  • To fulfil your chosen preferences (send your daily reminder at the time you set, display the app in your language).
  • To keep the community safe (AI content moderation before shared reflections go public).
  • To enable account recovery only if you opt in to a sign-in.

4. Sharing data with third parties

We only share data with the processors strictly needed to operate the app. Each is bound by a data processing agreement.

ProcessorPurposeLocationSafeguard
Supabase Inc.Database, authentication, storageUnited States (AWS us-east-1)Standard Contractual Clauses
Anthropic PBCAI translation of shared reflections + AI content moderationUnited StatesStandard Contractual Clauses
Apple Inc.Sign in with Apple (only if you choose)United StatesApple's own terms
Google LLCSign in with Google (only if you choose)United StatesStandard Contractual Clauses

We do not sell, rent, or share your data with advertisers or data brokers. Ever.

5. International data transfer

Your data is primarily stored in the United States (Supabase's AWS region). Switzerland has recognised the adequacy of certain US data transfer frameworks, and our processors have additional Standard Contractual Clauses (SCCs) in place to protect EU/EEA users' data under GDPR.

6. How long we keep your data

  • Reflections, reactions, profile, translations: kept for as long as your account is active. Deleting your account removes everything within 30 days.
  • Server logs: kept for up to 14 days for abuse detection, then automatically purged.
  • Email sign-in tokens: expire automatically after 1 hour.

7. Your rights

Under the Swiss Federal Act on Data Protection (revDSG) and the EU General Data Protection Regulation (GDPR), you have the following rights:

  • Right to access — ask us what data we hold about you.
  • Right to rectification — correct inaccurate data (e.g., change your alias in Settings).
  • Right to erasure — delete your account and all associated data in-app (Settings → Delete my account) or by emailing us. Deletion is final and cannot be undone.
  • Right to data portability — ask us to send you a copy of your reflections as a structured file. Email us to request.
  • Right to object — object to processing based on legitimate interest (e.g., content moderation).
  • Right to withdraw consent — turn off translation consent in Settings, or delete your account.
  • Right to lodge a complaint — with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EU, with your local supervisory authority.

To exercise any of these rights, email hello@daily-capsule.com.

8. AI moderation — what you should know

When you share a reflection publicly, its text is sent to Anthropic's Claude Haiku API and evaluated against a safety prompt we author. The result is one of three verdicts — safe, block, or crisis:

  • Safe: the reflection shares as normal.
  • Block: the reflection cannot be shared publicly (it is kept private in your archive). We do not tell you why, to make the filter harder to game.
  • Crisis: we show you a supportive sheet with hotline resources. You may still choose to share or keep the reflection private.

The moderation system is not perfect. It may sometimes misclassify content. If you believe your reflection was blocked unfairly, you can email us.

9. No cookies, no trackers

The Daily Capsule mobile app does not use cookies, advertising identifiers, analytics SDKs, or third-party trackers.

10. Children

Daily Capsule is not intended for users under the age of 16. If you are in the EU/EEA, this is the minimum age of consent under Art. 8 GDPR. We do not knowingly collect data from minors. If you believe a child has created an account, please contact us and we will delete the data.

11. Security

  • All data in transit uses TLS encryption.
  • All data at rest in our database is encrypted at disk level.
  • Anonymous sign-in means most of our user base has no personally identifying data stored.
  • Access to production systems is restricted to the company's managing directors.

Despite these measures, no internet service is 100% secure. If a breach affects your data, we will notify affected users within 72 hours as required under GDPR.

12. Changes to this policy

We may update this policy as the app evolves. Material changes will be announced in-app before they take effect. The "Last updated" date at the top of this page always reflects the current version.

13. Contact

Questions or concerns? Email hello@daily-capsule.com.

Daily Capsule

A daily reflection app by Power of Life Labs GmbH.
Oberdorfweg 9, 8704 Herrliberg, Switzerland · CHE-495.719.617

© 2026 Power of Life Labs GmbH Privacy · Terms · Contact