Privacy Policy

Last updated: July 2026

Dear Diary is a personal journaling app. Your private thoughts deserve real privacy — not marketing speak. This policy explains plainly what we collect, why, and what we never do with it.

What we collect

  • Account information — your name, email address, and profile photo when you sign up.
  • Journal entries — the text, images, mood, and dates you write in the app.
  • Device token — a push notification token if you enable reminders (optional).
  • Circle memberships — the email addresses you invite to your circles, and the circles you have been invited to.
  • Safety reports — if you report content or block someone, we record what was reported, why, and by whom, so we can review it.

How we use your data

We use your data only to provide the Dear Diary service to you. Specifically:

  • To display your journal entries to you.
  • To run the AI pipeline that turns your draft into a polished entry (processed transiently — not stored by the AI provider beyond the request).
  • To generate your “Story So Far” summary and mood insights.
  • To send you daily reminders if you opt in.
  • To share the entries you choose to share, with the specific circle members you choose — and no one else.
  • To screen images you upload and entries you publish or share, so the platform stays free of adult, violent, and abusive content.

Encryption at rest

Every journal entry you write is encrypted before it is saved to our database. We use AES-256-GCM — the same standard used by banks and governments — so that even if our database were ever accessed without authorisation, your entries would be unreadable without the encryption key.

  • Your entry text is encrypted on our servers the moment you save, and decrypted only when you read it back.
  • The encryption key is stored separately from the database, in Google Cloud Secret Manager, and is never written to disk alongside your content.
  • Images are stored in Google Cloud Storage with server-side encryption enabled by default.
  • All data in transit is protected by TLS (HTTPS).

We do not sell your data

We do not sell, rent, trade, or share your personal data or journal content with any third party for commercial purposes. Your diary is yours. We will never use your entries to train AI models, build advertising profiles, or provide data to data brokers.

What you choose to share

Every entry is private by default. Nothing leaves your account unless you explicitly choose an audience for it:

  • Private — visible only to you, encrypted at rest.
  • Circles — visible only to the specific people you invited to the circles you selected. Removing someone, or deleting the circle, revokes their access immediately.
  • Public — visible to anyone on Dear Diary, in the community Feed.

Entries you share to a circle or publish publicly are automatically checked for policy violations before they go live. Your private entries are never checked, shared, or shown to anyone.

AI disclosure

Dear Diary uses artificial intelligence (Google Gemini) to help turn your rough notes, chats, and photos into a polished journal entry, and to generate features like Reflections, Chronos, and Memory Books. Here's what that means in practice:

  • AI-generated content can be inaccurate. Before an AI-assisted entry is saved, you're shown the draft and asked to review and edit it — the app does not publish AI output without your review.
  • No human reviews AI output before you see it. Content moderation screening (for policy violations, not accuracy) only applies if you choose to share an entry publicly or to a Circle.
  • What the AI sees. To generate an entry, the AI processes the draft, images, and chat history you provide for that entry. It does not have access to your other private entries unless a feature (like Reflections) explicitly says it looks back across your journal.
  • Your content is not used to train AI models. Under our API agreement with Google, requests sent to Gemini are not retained or used to improve their models.
  • AI use is optional. You can write and save entries entirely yourself, with no AI involvement, at any time.

Third-party services

We use a small set of trusted third-party services to operate the app:

  • Google Cloud — database hosting and image storage.
  • Google Gemini — AI processing of your draft to generate polished entries. Requests are not used to train Google's models under our API agreement.
  • Expo / EAS — mobile app delivery and push notifications.
  • Resend — transactional email (OTP codes, password resets).
  • Google Cloud Vision — automated screening of uploaded images for adult or violent content. Images are checked at upload time and not retained by the service.
  • RevenueCat — subscription and purchase management. It receives your account identifier and purchase status, never your journal content.

Each of these providers is contractually bound to handle data securely and not use it for their own purposes.

Your rights

  • Access — you can view all your journal entries and profile data in the app at any time.
  • Delete — you can delete any individual entry from within the app. You can also permanently delete your entire account from Profile → Account settings: this immediately and irreversibly removes your entries, photos, diary buddy conversations, profile, memory books, and reflections from our systems. We keep only an anonymous record that an account was deleted — with no name, email, or identifier linking it back to you.
  • Export — if you'd like a copy of all your data, contact us and we'll prepare an export.
  • Opt out — you can turn off push notification reminders at any time in the app settings.

Contact

Questions or requests about your data? Email us at hello@deardiary.world. We aim to respond within 48 hours.