AI Diary (“we”, “us”, “our”, or “the app”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, why we process it, who helps us provide the service, how long we keep it, and the choices available to you when you use AI Diary on Android or iOS. Using the app means you acknowledge this notice; this notice is not a substitute for any consent required by law.
Account Information: We collect your email address when you provide one and a Supabase user identifier. Continuing as a guest creates an anonymous Supabase account identifier. You may also choose to add a display name, age, and profile photo. We may retain a legacy gender value if you supplied one in an earlier app version. If you choose Google or Apple sign-in, that provider sends Supabase the identifiers needed to authenticate you according to your provider settings.
Voice Recordings & Microphone Access: Microphone access is used only when you actively record a voice journal entry or voice follow-up. The recording is sent to Google Gemini for the requested transcription and analysis, and a copy is retained in Cloudflare R2 so you can play it again. A processed recording waiting for you to save or discard the result may remain unclaimed for up to 24 hours before it is queued for deletion.
Journal Content: We store journal entries and derived data such as transcripts, AI-generated summaries, mood/emotion data, sentiment scores, tags, memories, semantic embeddings, habits, reminders, and timestamps. Authentication and database row-level security keep this content unavailable to other users. Limited privileged access is used only where needed to operate, secure, or support the service.
Camera, Photo Library & Uploaded Photos: You may choose a photo from your library or take one with the camera to attach to an entry, use as your profile photo, or submit through Photo Journal to read a handwritten diary page. Entry photos and profile photos are resized and compressed on your device, with EXIF/GPS metadata removed, before Cloudflare R2 storage. Regular entry attachments and profile photos are not sent to Gemini. Only a photo you explicitly submit through Photo Journal is sent to Gemini for the requested handwriting and mood analysis. Current builds sanitize that analysis copy first; an older app version may send metadata present in the file returned by the camera picker. Camera and photo-library access can be revoked in your device settings.
Mood & Emotion Data: Our AI analyzes your voice tone and words to detect emotions and mood patterns. This includes emotion scores, sentiment analysis, and mood classifications. This data is stored with your journal entries to provide mood tracking and insights.
Physical Activity & Step Counts: If you enable the step-count habit, the app reads your daily step count through Android physical-activity sensors or Apple Motion & Fitness. The daily value is stored with your private habit progress so it can sync across sessions and appear in your insights. AI Diary does not collect precise location from step tracking.
Subscriptions & Purchase History: To provide and restore paid features, we store the subscription product, entitlement state, renewal or expiration status, and store transaction identifiers linked to your account through RevenueCat. We do not receive your full payment-card details.
Device, Notification & Technical Information: We collect basic device information including device type, operating system version, timezone, and app version for functionality and debugging. The app may create and store a Firebase registration token linked to a signed-in or anonymous guest installation before notification display permission is granted. Push-delivery logs can include the notification title/body, routing identifiers, Firebase message ID or delivery error, and sent time. A notification may contain a habit name, progress, diary-derived follow-up question, or support subject/reply excerpt, and may be visible on your lock screen.
Diagnostics & Support: We collect crash, error, and sampled performance diagnostics through Sentry to keep the app stable and fix bugs; Sentry's default personal-information collection is disabled. First-party production error reports store an error category, context, code, screen, app version, platform, user ID, and guest status in Supabase. The first occurrence in a short alert window may be sent to the operator through a private Telegram chat with a shortened user ID. If you submit an authenticated support request, the ticket also includes app/build version, device model and configuration, locale, timezone, subscription state, streak, and entry/follow-up counts. It does not automatically attach your diary text, recordings, or photos. We do not use a third-party product-analytics or behavioral-tracking SDK; first-party activity, rate-limit, notification, subscription, and journal-derived data is used for functionality, personalization, security, and diagnostics.
We use your information solely to provide and improve the app's functionality:
The app requests the following device permissions:
User-facing runtime permissions are requested when the related feature needs them. Technical permissions such as internet access do not show a runtime prompt. You can revoke optional camera, photo-library, microphone, notification, or biometric access through your device settings. AI Diary does not receive your fingerprint or face template; your device only returns whether biometric authentication succeeded.
We take data security seriously and implement industry-standard measures:
AI Diary is not end-to-end encrypted because our service providers must process readable content to provide storage, transcription, and AI features. No method of electronic storage or transmission is 100% secure, so we cannot promise absolute security.
We use Google Gemini AI only when an AI-powered feature requires it, including transcription, mood analysis, summaries, memories, coaching, recaps, semantic search, and diary chat. Depending on the feature, we send the relevant audio, journal text, derived journal context, or question you submit.
AI Diary does not train its own models on your content. Google's handling depends on the Gemini service and project settings used for the request. Under Google's published terms, paid services do not use prompts or responses to improve Google products, although limited safety and abuse-prevention logging may apply; unpaid services may use prompts and responses for product improvement and may involve human review. Your data may be transferred to and processed in countries where our service providers operate.
We do not sell, trade, rent, or share your personal data with third parties for their marketing purposes.
Your journal entries, recordings, attached photos, and mood data are not intentionally published or made available to other users. We disclose data only to service providers needed to operate the requested features:
These providers handle data under their own privacy terms and, where applicable, our service agreements and instructions. We may also disclose information where required by applicable law or a valid legal process, or where necessary to protect users and the service.
Account and journal data are generally retained while your account is active or until you delete the relevant content. You have the following controls:
Deletion removes the relevant database rows and live account access immediately. Associated audio and image object keys are placed in a server-only durable deletion queue in the same database transaction, and a scheduled worker retries failed storage removals until each object is gone. While an account remains active, a minimal completed-job tombstone (account ID, object key, and timestamps) is retained to prevent a delayed request from reusing a deleted media key. After account deletion, this operational metadata is removed within seven days. Backups may retain deleted data for up to 30 days before being purged.
A voice recording processed before you save an entry may remain in R2 for up to 24 hours while waiting to be claimed; abandoned recordings are then queued for deletion. A failed recording upload may remain temporarily on your device until you retry or discard it.
Service providers may retain security, diagnostic, transaction, submitted-content, derived-notification, or legally required records under their own terms and project settings.
Privacy rights vary by location. Where applicable, you may have the following rights regarding your personal data:
AI Diary does not make solely automated decisions that produce legal or similarly significant effects. To exercise a right, contact us at mubarisfly@gmail.com. We may verify account ownership and will respond within the period required by applicable law, normally within 30 days. We will tell you if a permitted extension is needed.
With your permission, the app may send local notifications and Firebase Cloud Messaging push notifications for:
Available notification categories can be adjusted in AI Diary. Device notification settings are the reliable global off switch, including for support replies. AI Diary may register a signed-in or anonymous guest installation with Firebase before display permission is granted; the operating-system permission controls whether alerts are shown. Push titles, bodies, routing identifiers, message IDs or delivery errors, and send times may be logged for delivery and deduplication. Journal content is not used for third-party advertising.
AI Diary is intended only for people aged 18 or older and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us with personal data, contact us at mubarisfly@gmail.com so we can investigate and delete the data and associated account.
On Android, the free tier may display ads through Google AdMob. Pro and trial users see no ads, and the ads SDK is not included or initialized in the iOS app. Android ads are non-personalized:
The mobile app does not use cookies. Our website (landing page) may use essential cookies for basic functionality. We do not use tracking cookies or third-party analytics cookies on our website.
Your data may be transferred to and processed in countries other than your country of residence, including the United States, where our service providers operate. Where applicable law requires it, we rely on the transfer safeguards made available by those providers and our agreements with them.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
We encourage you to review this policy periodically.
AI Diary provides AI-generated mood analysis and summaries for personal journaling and self-reflection purposes only. This is not a medical device and should not be used as a substitute for professional mental health advice, diagnosis, or treatment. We make no warranties regarding the accuracy of mood detection or emotional analysis. Always seek the advice of a qualified healthcare provider for mental health concerns.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
AI Diary - Voice Mood Journal
Email: mubarisfly@gmail.com
We respond within the period required by applicable law and will notify you if a permitted extension is needed.