Privacy policy
Last updated: 30 September 2026
Capacity lets two people share how much they have left today. Your check-ins are personal, so the app keeps as little as it can and shows it only to your partner.
Who is responsible
Capacity is made by João Carreiro, an independent developer based in Portugal, who is the data controller for the app. Questions or requests: joaocarreiro@gmail.com.
What Capacity stores
| Data | Why | How long |
|---|---|---|
| Account: your email address and a sign-in ID. If you sign in with Google, Google also passes your name and profile photo link to our sign-in provider; the app doesn’t use or show them. | To sign you in and keep you connected to your partner. | Until you delete your account. |
| Your name as you typed it in the app and, if you say you’re away, the last day you’ll be away. | Shown to your partner. | Your name until you delete your account; the away day until you’re back or check in. |
| Your latest check-in: Head, Heart and Body levels (1–5), what would feel good (if you chose something), your note for the day (if you wrote one and it's shared) and when you shared it. | Shown to your partner. | Your partner only ever sees the latest one; each new check-in replaces it. Removed from the shared space when you unpair or delete your account. |
| Your history, only while Keep my history is on (it is on by default): every check-in you share (levels, what would feel good, your note, date and time), with each day’s latest one as a summary. | To show you how you’ve been over the last weeks. Only you can see it; your partner never does. A note you keep private is stored only here and on your phone, never in the shared space. With history off, nothing is kept here: a private note then stays only on your phone, for that day. | Until you turn off Keep my history in Settings → Privacy, which deletes it straight away, or delete your account. |
| Pairing: which account you’re paired with, and your invite codes (stored scrambled, valid for 24 hours, usable once). | To connect the two of you. | Until you unpair or delete your account. |
| “Got it” and “Ask”: which of your partner’s check-ins you acknowledged, and when you last asked your partner for an update. | To tell your partner, and to limit asks to one every two hours. | Until you unpair or delete your account. |
| Notification token for each phone you use, and the time your last notification was sent. | To deliver notifications and avoid sending too many. | Until you sign out on that phone or delete your account. |
| Feedback you send from the app, with the app version and phone model. | To fix problems and improve the app. | Until you delete your account. |
| Anonymous usage counts: each day's totals of check-ins shared, the level chosen on each ring, the need chosen, the local hour, whether the rings differ or changed since the last share, and how many "Got it", asks, invites and new accounts there were; how the app is opened (icon, widget or notification), which widgets are placed, which settings are on, and each phone’s platform and language. The totals contain no account, name, email or device, and can't be traced back to a person. | To learn which parts of the app are used and improve it. | Kept as daily totals. |
| Crash reports: what went wrong in the code, phone model, Android or iOS version, app version, and a random ID for this installation. Never your check-ins, name or email. | To find and fix crashes. | 90 days. |
Your phone also keeps a copy of your and your partner’s latest check-ins, your settings and your reminder times, so the app and widgets work offline. This copy stays on your phone and is removed when you sign out or uninstall the app.
Capacity has no ads, no third-party analytics and no tracking. The usage counts above are computed on our own servers and never leave them. Capacity does not sell your data or share it with anyone for marketing.
Who can see it
- Your partner sees your name, your latest check-in, whether you acknowledged theirs, and until when you’re away, if you said so. They never see your email.
- Nobody else in the app. There are no public profiles and no groups.
- Service providers. Capacity runs on Google Firebase (sign-in, database, notifications, crash reports). Google processes this data on our behalf under its data processing terms, and stores it in the United States. Transfers from the EU rely on the EU–US Data Privacy Framework and Standard Contractual Clauses. Everything listed above is kept there, and nowhere else.
- Beta testing. While Capacity is in beta, the app is delivered through Apple TestFlight (iPhone) and Firebase App Distribution (Android). They only deliver the app and never receive your check-ins, notes or history. Apple and Google do handle your tester email, device and install details, crash reports and any feedback you send through them, under their own privacy policies.
- The developer can technically access the database, but only does so to fix a problem you reported or when required by law.
Notifications
By default, notifications only say that your partner updated; the details stay in the app. If you turn off Private notifications, they also show your partner’s levels, what would feel good and their note, including on the lock screen.
Your note for the day is free text you write. It goes to your partner with your check-in unless you turn off Share my note; then only you see it. Please don't write anything in it you wouldn't want your partner to read, and don't use it for health information.
Legal basis
Check-ins, your history, your account, pairing and notification data are needed to provide the app you use. You can stop at any time: turn history off, unpair, or delete your account. Crash reports, feedback and the anonymous usage counts rely on our legitimate interest in keeping the app working and improving it; the counts are taken from each check-in as it is shared and are never stored with who shared it.
Deleting your data
- Unpair (Settings → Account → Unpair) removes your check-in, acknowledgements and asks from the shared space.
- Keep my history off (Settings → Privacy) deletes your history straight away.
- Share my note off (Settings → Privacy) takes today's note back from your partner and keeps future notes private.
- Delete account (Settings → Account → Delete account) permanently deletes your account and everything listed above, straight away. You can also do it on the web without the app, or email us.
- Anonymous usage counts can’t be linked to you, so they stay as daily totals. Crash reports are deleted automatically after 90 days. Google may keep deleted data in its backups for a short time before it is overwritten.
Your rights
Under the GDPR you can ask to access, correct, delete or export your data, and object to or restrict how we use it. Email joaocarreiro@gmail.com and we’ll reply within a month. You can also complain to the Portuguese data protection authority, the CNPD, or to the authority where you live.
Security
Data travels encrypted and is stored encrypted by Google. Database rules only let you read your own data and your partner’s name and check-in, and invite codes are stored scrambled.
Age
Capacity is meant for adults in a relationship and is not directed at anyone under 18.
Changes
If this policy changes, we’ll update the date at the top. If a change affects what we store or who sees it, we’ll also tell you in the app.