Privacy Policy
Last updated: June 27, 2026
1. Introduction & Scope
Capself ("Capself," "we," "us," or "our") is operated by BlindspotLab, based in Nigeria. We provide services at https://capself.co and https://auth.capself.co (collectively, the "Service").
This Privacy Policy explains what personal data we collect, why we use it, who we share it with, how long we keep it, and what choices and rights you may have. Capself is offered to a global audience; different countries impose different privacy rules. We aim to handle personal data responsibly and to honour rights that apply to you under the laws of your country or region, to the extent those laws apply to BlindspotLab and this Service.
We do not sell your personal information. We do not use your data for cross-context behavioural advertising.
2. Who Is Responsible for Your Data
Data controller: BlindspotLab (operator of Capself)
Privacy contact: privacy@capself.co
Website: https://capself.co
For privacy questions, requests, or complaints, contact us at the address above. We will respond in good faith and within timeframes required by applicable law where those timeframes apply to us.
3. What Data We Collect
Account information
Name, email address, profile image (if you use Google sign-in), authentication identifiers, session data, subscription tier and status.
Development & journal content
Goals, habits, journal entries, reflections, life-domain notes, values, beliefs, motivations, milestones, behavioural patterns, faith-track preferences, and related content you choose to store in Capself.
Sensitive or special-category information
Because Capself is a personal development tool, content you voluntarily submit may reveal information about your health, wellbeing, religious beliefs, or other sensitive topics. Faith-track selection is optional. We process this information only to provide the Service you request, not for unrelated marketing. Where local law treats this data as sensitive or special-category data, we rely on your voluntary submission and use of the Service, and on consent or another lawful basis permitted by applicable law.
AI conversations
Messages you send to Capself AI, responses, conversation metadata, and stored insights linked to your account. Unauthenticated preview chats at /chat are limited to three questions and are not tied to a long-term account unless you register.
Payment information
We do not store full payment card numbers. Paystack processes payments and recurring subscription renewals. We receive transaction references, subscription identifiers, payment status, plan codes, billing period end dates, and limited payment-method metadata (such as card brand and last four digits) needed to manage access, send billing-related notifications, and respond to support requests.
Recurring billing & failed payments
Founding Member and Yearly plans renew automatically through Paystack unless you cancel before the next billing date. If a renewal fails, we record that your subscription is past due and may notify you by email and in-app message so you can update your payment method. Paid access continues for 5 daysafter the failed charge while Paystack retries billing; if payment still has not succeeded after that grace period, we downgrade your account to the Free tier. We do not operate a separate payment-retry system beyond Paystack's own process.
Technical data
IP address, browser and device information, essential cookies, security logs, and audit logs for authentication, abuse prevention, and service operation.
4. Why We Use Data & Lawful Bases
We process personal data to:
- Provide, operate, and maintain the Service
- Personalise your experience and knowledge graph
- Generate AI-assisted reflections and guidance you request
- Process payments and manage plan access
- Send service-related communications you reasonably expect
- Protect the Service, users, and BlindspotLab from abuse or fraud
- Meet legal, regulatory, and accounting obligations
Depending on your location, our lawful bases may include:
- Performance of a contract: to deliver the Service you signed up for
- Consent: where you opt in or where law requires consent (you may withdraw consent where applicable without affecting processing already lawfully completed)
- Legitimate interests: security, fraud prevention, and service reliability, balanced against your rights
- Legal obligation: where we must retain or disclose data by law
We do not use solely automated decision-making that produces legal or similarly significant effects about you. AI features provide guidance you may accept or ignore; you remain responsible for your choices.
5. Third Parties & AI Processing
We use service providers ("processors") who process data on our instructions to run Capself. These may include:
- OpenRouter: routes AI API requests
- AI model providers (via OpenRouter): such as Nvidia, Google, Anthropic, OpenAI, and xAI, depending on your plan and the feature used
- Paystack: payment processing
- Resend: transactional email
- Google: OAuth sign-in, if you choose it
- Supabase: database hosting
How Capself uses AI data: We send prompts and relevant context to these providers so they can return a response for your request. On our side, we do not use your content to train machine learning models, and we do not share your private development data with other Capself users.
Third-party practices: Each provider has its own terms and privacy policy. We choose API/inference routes for service delivery, but we cannot guarantee how every upstream provider handles logs, retention, or abuse monitoring. If you need more information about a specific provider, contact us.
We require processors to handle data only for our documented purposes and to apply appropriate security measures under their agreements with us, to the extent those agreements exist.
6. Security
We use reasonable technical and organisational measures designed to protect personal data, including HTTPS for data in transit, access-controlled infrastructure, application-level per-user data isolation, and logging for security events. No method of transmission or storage is completely secure; we cannot promise absolute security.
You are responsible for keeping your sign-in method secure and for not sharing access to your account.
7. Retention
We keep personal data for as long as your account is active and as needed to provide the Service. If you delete your account, we aim to delete or anonymise personal development content within 30 days, except where we must keep certain records longer, for example payment, tax, fraud-prevention, dispute, or legal compliance purposes.
Backup systems may retain deleted data for a short technical window before being overwritten.
8. International Transfers
Because Capself is global, your data may be stored or processed in Nigeria, the United States, the European Union, and other countries where our providers operate. Laws in those countries may differ from yours.
Where applicable law requires safeguards for cross-border transfers, we aim to use appropriate measures, such as processor contracts, standard contractual clauses where available, or other mechanisms recognised by relevant authorities, to the extent we are able and required to do so.
9. Cookies
We use essential cookies and similar technologies for authentication, session management, preview limits, and security. We do not use third-party advertising cookies. Where non-essential cookies are added in future, we will update this policy and, where required, ask for consent before using them.
10. Your Rights (All Users)
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Know what data we hold about you
- Access a copy of your data
- Correct inaccurate data
- Request deletion, subject to legal exceptions
- Request portability in a usable format, where applicable
- Object to or restrict certain processing, where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
How to exercise rights: email privacy@capself.co or delete your account in settings. We may need to verify your identity. We aim to respond within 30 days, or within any shorter period required by law that applies to your request.
We will not discriminate against you for exercising privacy rights where such protection is required by law.
11. Region-Specific Information
The sections below summarise additional rights or expectations that may apply in certain regions. They supplement, and do not limit, your rights under Section 10.
Nigeria (Nigeria Data Protection Act 2023: NDPA)
BlindspotLab is established in Nigeria. Under the NDPA, you may have rights to access, rectify, erase, restrict, or object to processing, and to data portability, where applicable. Processing of sensitive personal data requires an appropriate lawful basis under Nigerian law.
If you believe we have processed your data unlawfully, you may contact us first at privacy@capself.co. You may also have the right to complain to the Nigeria Data Protection Commission (NDPC).
If a personal data breach is likely to harm your rights, we will take steps required by applicable Nigerian law, which may include notifying you and the NDPC within legally required timeframes.
European Economic Area & United Kingdom (GDPR / UK GDPR)
If you are in the EEA or UK, BlindspotLab is your data controller for Capself. Our lawful bases are described in Section 4. You have GDPR rights including access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making where applicable.
You may lodge a complaint with your local supervisory authority (for example, the ICO in the UK or your EU member-state authority). We encourage you to contact us first so we can try to resolve your concern.
For international transfers from the EEA/UK, we rely on appropriate safeguards where required, as described in Section 8.
United States
We do not sell personal information as "sale" is defined under California and similar state privacy laws. We do not share personal information for cross-context behavioural advertising.
If you are a California resident, you may have rights to know, access, delete, and correct personal information, and to limit use of sensitive personal information, under the CCPA/CPRA and related regulations. Other US states (including Virginia, Colorado, Connecticut, Utah, Texas, and others with consumer privacy laws) may provide similar rights. Submit requests to privacy@capself.co. We will verify requests as permitted by law.
Canada (PIPEDA)
Canadian users are entitled to meaningful information about our privacy practices and to challenge our compliance with PIPEDA principles. Contact privacy@capself.co with concerns; you may also contact the Office of the Privacy Commissioner of Canada if unsatisfied with our response, where applicable.
Brazil (LGPD)
If you are in Brazil, you may have rights under the Lei Geral de Proteção de Dados, including confirmation of processing, access, correction, anonymisation, portability, deletion, and information about sharing. You may contact Brazil's Autoridade Nacional de Proteção de Dados (ANPD) where applicable.
Australia, South Africa, Kenya & other regions
If you are in Australia, you may have rights under the Privacy Act 1988 and may contact the Office of the Australian Information Commissioner (OAIC). If you are in South Africa, the Protection of Personal Information Act (POPIA) may apply and complaints may be directed to the Information Regulator. If you are in Kenya, the Data Protection Act 2019 may apply. Users in other countries may have local data protection laws. Contact us and we will address your request in good faith to the extent we are required or able to do so.
12. Children
Capself is not directed at children and is not intended for anyone under 16 years of age. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided data, contact privacy@capself.co and we will take reasonable steps to delete it. Some jurisdictions require parental consent for users under 13 or 16. You must meet the minimum age for your location.
13. Data Breaches
If we become aware of a personal data breach that is likely to pose a risk to your rights, we will investigate promptly and take reasonable steps to mitigate harm. Where applicable law requires us to notify you, regulators (such as the NDPC or an EU/UK supervisory authority), or both, we will do so within the timeframes that law requires.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email or in the Service where practicable before changes take effect. The "Last updated" date at the top shows the current version. Continued use after the effective date means you accept the updated policy, except where your local law requires a different form of consent.
15. Governing Framework
This policy is issued by BlindspotLab under Nigerian law as our home jurisdiction. That does not reduce rights you have under mandatory privacy laws in your country of residence. Where those laws conflict with this policy, mandatory local protections prevail to the extent required.
16. Contact
BlindspotLab (Capself)
Privacy: privacy@capself.co
Support: support@capself.co
Questions? Contact legal@capself.co