Effective date: September 25, 2026
Dear Diary is a journal published by Black and Blue. Its core journal works offline and contains no advertising, behavioral analytics, or third-party crash reporting. In the current Android closed-testing build, paid sync and Student Developer Support checkout are unavailable.
Journal entries, encrypted drafts, tags, moods, settings, encrypted photos, exports, and encrypted backups stay on your device or in a destination you choose. The developer cannot read local journal content or recover a lost vault or backup passphrase. Readable Markdown and JSON exports are not encrypted after export.
The Android build may connect to RevenueCat when it starts, even if you do not open a purchase screen. Google Play and RevenueCat may process a randomly generated app-user identifier, limited app and device technical information, product and purchase status, and transaction history to support billing and restore purchases. RevenueCat may use purchase history for anonymous subscription analytics. Dear Diary does not send your name, email, advertising identifier, journal content, photos, vault keys, or passphrases to RevenueCat.
If optional Pro encrypted sync becomes available and you choose it, the app encrypts journal records and attachments before sending them to the Dear Diary relay. The relay would receive ciphertext plus minimal opaque identifiers, versions, and timestamps needed for synchronization, but not the key needed to read journal content. This service is unavailable in the current closed-testing build.
The app may use device authentication, network access for optional purchases and encrypted sync, and system pickers when you choose a file or photo. It does not request an advertising ID, precise location, contacts, microphone, or broad photo-library access. Android cloud backup is disabled.
Dear Diary is not directed to children. It does not transmit journal content to the developer, but Google Play and RevenueCat may process billing data as described above. Store and device-level age and purchase controls remain available to families.
Journal content is encrypted in app-managed storage on your device. Network billing connections use encrypted transport. No security measure can guarantee that device data or an exported file is unrecoverable after deletion. Local data remains until you delete it or remove the app. Google Play and RevenueCat retain purchase records according to their platform, legal, fraud-prevention, and accounting requirements.
You control local data from inside the app:
For access, correction, or deletion requests concerning any data held by Black and Blue or its billing provider, email developer@blackandblue.co.in. Include the anonymous support identifier shown in Dear Diary settings if available; never send a purchase token, order ID, vault key, passphrase, journal text, or photo. Subscription cancellation is managed separately in Google Play.
Google Play and RevenueCat may retain purchase records where required for platform operations, accounting, fraud prevention, or law.
Black and Blue may update this policy when the app or its service providers change. The effective date above will be updated with material revisions.