_deardiary

Dear Diary Privacy Policy

Effective date: September 25, 2026

Dear Diary is a journal published by Black and Blue. Its core journal works offline and contains no advertising, behavioral analytics, or third-party crash reporting. In the current Android closed-testing build, paid sync and Student Developer Support checkout are unavailable.

Journal entries, encrypted drafts, tags, moods, settings, encrypted photos, exports, and encrypted backups stay on your device or in a destination you choose. The developer cannot read local journal content or recover a lost vault or backup passphrase. Readable Markdown and JSON exports are not encrypted after export.

The Android build may connect to RevenueCat when it starts, even if you do not open a purchase screen. Google Play and RevenueCat may process a randomly generated app-user identifier, limited app and device technical information, product and purchase status, and transaction history to support billing and restore purchases. RevenueCat may use purchase history for anonymous subscription analytics. Dear Diary does not send your name, email, advertising identifier, journal content, photos, vault keys, or passphrases to RevenueCat.

If optional Pro encrypted sync becomes available and you choose it, the app encrypts journal records and attachments before sending them to the Dear Diary relay. The relay would receive ciphertext plus minimal opaque identifiers, versions, and timestamps needed for synchronization, but not the key needed to read journal content. This service is unavailable in the current closed-testing build.

The app may use device authentication, network access for optional purchases and encrypted sync, and system pickers when you choose a file or photo. It does not request an advertising ID, precise location, contacts, microphone, or broad photo-library access. Android cloud backup is disabled.

Children

Dear Diary is not directed to children. It does not transmit journal content to the developer, but Google Play and RevenueCat may process billing data as described above. Store and device-level age and purchase controls remain available to families.

Security and retention

Journal content is encrypted in app-managed storage on your device. Network billing connections use encrypted transport. No security measure can guarantee that device data or an exported file is unrecoverable after deletion. Local data remains until you delete it or remove the app. Google Play and RevenueCat retain purchase records according to their platform, legal, fraud-prevention, and accounting requirements.

Data deletion

You control local data from inside the app:

  1. Delete individual entries or attachments from the journal.
  2. If encrypted sync becomes available and you opt in, use its deletion control to remove the relay copy. This does not cancel a store subscription or delete your local journal.
  3. Clear app storage or uninstall Dear Diary to remove remaining local app data.
  4. Delete exported Markdown, JSON, or backup files from the destination where you saved them.

For access, correction, or deletion requests concerning any data held by Black and Blue or its billing provider, email developer@blackandblue.co.in. Include the anonymous support identifier shown in Dear Diary settings if available; never send a purchase token, order ID, vault key, passphrase, journal text, or photo. Subscription cancellation is managed separately in Google Play.

Google Play and RevenueCat may retain purchase records where required for platform operations, accounting, fraud prevention, or law.

Contact

developer@blackandblue.co.in

Black and Blue may update this policy when the app or its service providers change. The effective date above will be updated with material revisions.