Privacy policy

Draft · last updated October 07, 2026 · to be reviewed by a lawyer before publishing. Items in [brackets] must be completed or confirmed.

The short version. Your journal lives on your phone and we can't read your entries. An account is optional; if you create one we store only your email address and your AI usage counts. Only if you tap "Reflect" (and have agreed), a short text summary is sent through our server to an AI provider (Anthropic, USA) to write your reflection. We don't store that text.

1. Who is responsible

Your Full Name, Street 1, 12345 Berlin, Germany, support@datefolio.app ("we"). [Data protection officer: not appointed.]

2. What stays on your phone

Everything you enter: people (nicknames), dates, ratings, notes, photos, plans, check-ins, settings. It is stored in the app's private storage on your device. Your PIN is kept in your phone's secure keychain (iOS Keychain / Android Keystore). We do not receive this data. Entries can reveal sensitive information about your private life, including sexual orientation or sex life; this is why we keep them local by default. Deleting the app, or "Delete all my data" in Settings, removes them.

3. Optional account

You can use the app without an account. If you create one, you sign in with your email address and a one-time code (no password). We process your email address, an account ID, the time of sign-in, and technical sign-in records (including IP address and device information) held by our authentication provider Supabase. The purpose is to run your account and to count your AI reflections per account. Legal basis: performance of the service you asked for (Art. 6(1)(b) GDPR) and, for security and abuse prevention, our legitimate interest (Art. 6(1)(f)). Sign-in emails are sent through our email delivery provider [name: e.g. Resend / Brevo; confirm DPA and region] as our processor.

We keep this data until you delete your account. You can delete it yourself in the app (Settings → Delete account); this removes your email, account ID and usage counters from our server straight away. [Confirm retention of authentication logs at Supabase and the email provider, and state it here.] Your journal is not part of your account and stays on your phone; delete it with Settings → Delete all my data. You can also request deletion by email (see how to delete your account).

4. Optional AI reflections

When you tap "Reflect" and have given your consent, the app builds a short text summary on your phone (nickname, stage, your ratings, flags and notes for the person or the last two weeks) and sends it over an encrypted connection to our server function hosted with Supabase. The function forwards it to Anthropic, PBC (USA), which runs the Claude AI model, and returns the reply to you. We do not store or log the text or the reply. Photos, your name, contacts, location, birthdays and payments are never sent.

Anthropic processes the text on our behalf under its commercial terms. [LAWYER/YOU: confirm and state Anthropic's current retention period for API data and that it is not used to train models; link the DPA.]

Legal basis: your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), given in the app before the first use. You can withdraw it at any time in Settings → AI & support → AI reflections; this doesn't affect earlier processing. AI reflections are optional; the app works without them.

Your notes describe other people. Please use nicknames and avoid full names, phone numbers and addresses.

5. Usage limits (what the server keeps)

DataPurposeKept
Random install ID (not linked to your name) and number of reflections used this weekEnforce the free weekly limitup to 60 days
If you have an account: your account ID and the number of reflections used this weekEnforce the weekly limit per accountup to 60 days, or until you delete your account
Scrambled (HMAC-hashed) network address and a daily counterPrevent abuse and protect against cost attacksup to 7 days
Monthly total call count and estimated cost (no personal data)Spending capindefinitely

Legal basis: our legitimate interest in preventing abuse and controlling costs (Art. 6(1)(f) GDPR). You can object by emailing us.

6. Where data goes (recipients and transfers)

7. Email and support

If you write to us, we process your email address and message to answer you (Art. 6(1)(b)/(f) GDPR) and keep it for as long as needed, normally up to [12] months after the conversation ends. If you join the Plus waitlist by email, we keep your address to notify you about Plus, until you ask us to delete it (consent, Art. 6(1)(a)).

8. Crash and error data

[Fill after checking the final build: "The app does not send crash reports or analytics." or list the tool, data, and basis.]

9. Security

Local storage in the app sandbox, optional app lock (PIN / Face ID / Touch ID, with the PIN in secure keychain storage), encrypted connections (TLS) for AI requests and sign-in, passwordless sign-in (one-time email codes), the account session stored in the phone's secure keychain and excluded from device backups. Exports you create ("Export my data") are plain files you control; keep them safe. No system is perfectly secure; if there is a personal-data breach affecting you, we will inform you and the authority as the law requires.

10. Your rights

Under the GDPR you can request access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests and withdraw consent at any time. Because your journal isn't on our servers, access and deletion of journal data are done directly in the app (Export / Delete all my data). Your account can be deleted in the app (Settings → Delete account). For anything else we hold (account email, usage counters, support emails), write to support@datefolio.app. You may complain to a supervisory authority, for example [Berliner Beauftragte für Datenschutz und Informationsfreiheit, or the authority where you live].

11. Age

The app is for people aged 18 and over.

12. Changes

If we change this policy in a material way (for example when Plus adds cloud sync), we will tell you in the app and ask for consent again where required.