With this privacy policy, we inform you about the types of personal data (hereinafter referred to as "data") we process, for what purposes, and to what extent in the context of providing our application PicDiary.
The terms used are not gender-specific.
Effective Date: June 5, 2026
Benedikt Kehl-Waas
Email: privacy@picdiary.app
Your satisfaction and well-being are our top priorities. Given that PicDiary handles highly personal and sensitive data, protecting your information is crucial to us. We appreciate the trust you place in us by providing your data for processing and commit to respecting your rights and privacy. Our principles include:
This overview summarizes the types of data processed, the purposes of their processing, and the categories of affected persons.
We process personal data based on the following legal bases of the GDPR:
In addition to GDPR, national data protection regulations in Austria, such as the Data Protection Act (DSG), apply. These include specific provisions on rights to information, correction, or deletion, and data transfer to third countries.
A diary may contain special categories of personal data within the meaning of Art. 9 GDPR (for example information about your health, religious or philosophical beliefs, political opinions, or sexual orientation). You decide entirely on your own initiative which content you store in PicDiary. Where such data is processed (for example synchronized to your account or, at your request, transcribed), this is done on the basis of your explicit consent pursuant to Art. 9 para. 2 lit. a GDPR. You can withdraw this consent at any time, for example by deleting the respective content or your account.
We implement technical and organizational measures to ensure data protection, including controlling access to data, maintaining data integrity and availability, and implementing privacy-friendly default settings.
We transfer data only within the scope of legal requirements and contractual obligations, particularly adhering to GDPR when processing data in third countries.
We collect and process personal data necessary for in-app purchases, including inventory and contact data. Payment data is handled securely and in compliance with applicable laws, often involving third-party payment service providers with their own privacy policies.
We retain personal data only as long as necessary for the purposes described in this policy or as required by law. In particular:
Data stored locally on your device remains there until you delete the respective content or uninstall the app.
Our app is not intended for children under 14. We do not knowingly collect personal data from children under 14. If we become aware of such data collection, we will delete the information immediately. Parents or guardians should contact us if they believe their child has provided us with personal data.
To exercise these rights, contact us using the details provided above. We may require identity verification before processing requests. You also have the right to lodge a complaint with the competent supervisory authority — in Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, www.dsb.gv.at).
We may employ third-party companies and individuals due to the following reasons:
These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
We use Matomo, an open-source analytics platform, to monitor and analyze the use of our app. Matomo is self-hosted on our own servers in Germany, and all data is stored securely and in compliance with the GDPR. No personal data is shared with third parties. For more information about Matomo, please visit: https://matomo.org/privacy-policy/
We use Google Crashlytics to monitor and report application crashes. This helps us improve the stability and performance of our app. For more information on Google's privacy practices, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy
If you create an account, your data will be stored in Google Firestore and Google Storage. This allows us to back up and synchronize your data. For more information on Google's privacy practices, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy
PicDiary lets you attach voice notes — actual audio recordings — to your diary entries. These recordings are stored on your device. If you use an account, they are included in the same secure backup and synchronization as your other content (see "Google Firestore and Google Storage" above). Voice notes are not automatically sent to Deepgram or OpenAI.
For each voice note you can optionally request a transcript. Only when you actively request this is your data sent — via our own Cloud Functions hosted in Germany — to the following services:
These services are used solely to perform the transcription or improvement you request. They do not store or use your data beyond the completion of these tasks.
We use EmailJS to send user feedback. This service helps us manage and respond to your feedback effectively. For more information on EmailJS's privacy practices, please visit the EmailJS Privacy Policy web page: https://www.emailjs.com/legal/privacy-policy/
We use RevenueCat to manage in-app purchases and subscriptions. RevenueCat processes data such as a pseudonymous app user ID, your purchase and subscription history, and device information in order to validate, restore, and manage your purchases. The payments themselves are processed by Apple (App Store) or Google (Google Play) under their own privacy policies; we do not receive your full payment details. For more information on RevenueCat's privacy practices, please visit: https://www.revenuecat.com/privacy/
Some of the processors we use are located outside the EU, in particular in the United States (e.g., Deepgram and OpenAI for the optional transcription features, and RevenueCat for purchase management). Where data is transferred to such third countries, the transfer is based on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework, in order to ensure an adequate level of data protection. Transfers by Google in connection with Crashlytics are likewise governed by appropriate safeguards as described in Google's privacy policy. We take appropriate measures to protect your data in accordance with this policy and applicable law.
We may modify this privacy policy to reflect legal changes or updates to our services and data processing practices. Significant changes will be communicated directly or via the app.
For inquiries or support requests, providing your name and contact details (email or phone number) is necessary. This information is used solely to address your request. If you have any questions about these Terms and Conditions, You can contact us by email: privacy@picdiary.app