Diarion Privacy Policy
In short
Diarion has no accounts, no servers and no sync. Your diary is stored on your device and is not sent to the developer or to anyone else. We collect no usage statistics, show no ads, and bundle no analytics or advertising SDKs.
What the app stores
All of the following lives only in the app's storage on your device:
- diary entries, mood, reflections, notes and tags;
- habits, tasks and planner events, wishlist, good deeds, happy moments;
- financial transactions, accounts, budgets;
- cycle tracker data and its symptoms;
- sleep times and how you felt, exactly as you typed them;
- settings: theme, language, currency, PIN, quick-menu order.
The database is encrypted on disk. The encryption key is generated on your device and held in the system keystore (Keychain on iOS, Keystore on Android); the developer does not have it and cannot obtain it. The PIN is stored as a hash, not as a number.
Where data can go — and only if you send it
- Backup. You create it. The file is encrypted with a key derived from your passphrase via PBKDF2 — not with the device key — and handed to the system share sheet, where you pick the destination. The app never stores the passphrase: lose it and nobody can open the backup, the developer included.
- Export. JSON, CSV and Markdown are produced locally and handed to you the same way.
- Crash report. If the app crashed, the last exception is written to a local file and the Data tab offers to send or delete it. Nothing is sent automatically.
Health
The app connects to neither Apple Health nor Google Health Connect and reads nothing from either. Sleep times, how you felt and any symptoms are what you typed yourself, and they stay in your local database.
Network
The app reaches the network in exactly one case: downloading AI model files from HuggingFace, and only when you start that download yourself in settings. It is a download: none of your entries, no diary text and no identifier are transmitted. Text is processed by the model on the device.
There are no other network calls: no telemetry, no update checks, no ads.
What there isn't
- No accounts, no registration.
- No Diarion servers — data cannot be sent anywhere because there is nowhere to send it.
- No analytics, crash analytics, A/B tests or advertising identifiers.
- No sharing with or selling to third parties.
- No cross-app tracking (App Tracking Transparency is not used, because there is nothing to track).
Your rights
The data is in your hands, so the rights are exercised in the app rather than by writing to the developer: to view it, open the app; to obtain a copy, use Export or Backup; to delete it, delete the app (its storage goes with it), tap “Delete all my data” in settings, or delete the individual entry. On Android, cloud backup is disabled in the manifest, so your diary does not end up in a Google backup.
Children
The app is not directed at children and collects no data, therefore it collects none from children.
Changes
A new version is published at this same URL with a new effective date. If a change involves sending data off the device, the app will ask for separate consent before the first such transmission.