Privacy Policy
Last updated: March 22, 2026
1. Introduction
Capsule Backup ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our cloud backup service.
We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller is Capsule Backup. For any privacy-related inquiries or to exercise your data protection rights, contact our Data Protection Officer at support@capsulebackup.com.
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
- Email address
- Billing address
- Payment information (processed by Stripe — we do not store card details)
3.2 Backup Data
Your Time Machine backup data is stored on our servers in your selected region. We do not access, read, or analyze the content of your backups. If you enable Time Machine encryption, your backup data is encrypted with a key only you possess.
3.3 Technical Data
We collect minimal technical data necessary to provide the Service:
- IP addresses used to connect to the Service
- Connection timestamps
- Storage usage metrics
3.4 Website Analytics
Our website may use privacy-respecting analytics to understand traffic patterns. We do not use invasive tracking or sell data to third parties.
4. How We Use Your Data
We use your data solely to:
- Provide and maintain the backup service
- Process payments and manage your subscription
- Send storage usage alerts (at 80%, 90%, 95%, 100% capacity)
- Communicate important service updates
- Respond to support requests
5. Data Storage and Location
Your backup data is stored exclusively in the region you select:
- Germany — EU, GDPR jurisdiction
- Finland — EU, GDPR jurisdiction
- United States
Your data never leaves your selected region. Account data (email, billing) may be processed by our payment provider Stripe in accordance with their privacy policy.
6. Data Retention
We retain your data for the duration of your subscription. Upon cancellation:
- Backup data is destroyed at the end of the billing period using DoD 5220.22-M compliant 3-pass wipe
- Account data is retained for up to 12 months for legal and accounting purposes
- Payment records are retained as required by applicable tax law
7. Third-Party Services
We use the following third-party services:
- Stripe — Payment processing and customer billing portal
- BetterUptime — Service status monitoring
We do not sell, trade, or otherwise share your personal data with third parties for marketing purposes.
8. Security Measures
We implement the following security measures:
- SMB3 encrypted transport (mandatory)
- Time Machine native encryption support
- IP whitelisting (beta)
- VPN access (WireGuard, OpenVPN)
- DoD 5220.22-M data destruction on account termination
9. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access — Request a copy of your personal data
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your personal data
- Portability — Request your data in a portable format
- Restriction — Request limitation of processing
- Objection — Object to processing of your data
To exercise these rights, contact support@capsulebackup.com. We will respond within 30 days.
10. Cookies
Our website uses only essential cookies required for basic functionality. We do not use tracking cookies or third-party advertising cookies.
11. Children's Privacy
Our Service is not directed at children under 16. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email. The "Last updated" date at the top indicates the most recent revision.
13. Apple Disclaimer
Capsule Backup is not affiliated with, endorsed by, or sponsored by Apple Inc.
14. Contact
For privacy inquiries: support@capsulebackup.com