Privacy Policy of PicDiary

Introduction

With this privacy policy, we inform you about the types of personal data (hereinafter referred to as "data") we process, for what purposes, and to what extent in the context of providing our application PicDiary.

The terms used are not gender-specific.

Effective Date: June 5, 2026

Data Controller

Benedikt Kehl-Waas
Email: privacy@picdiary.app

Our Commitment

Your satisfaction and well-being are our top priorities. Given that PicDiary handles highly personal and sensitive data, protecting your information is crucial to us. We appreciate the trust you place in us by providing your data for processing and commit to respecting your rights and privacy. Our principles include:

  • Data protection is paramount, especially for personal and sensitive information.
  • Your personal data (photos, texts, voice recordings, etc.) are initially stored exclusively on your device.
  • If you create and use an account, your data is stored on servers in the European Union (EU) for backup and synchronization purposes only, and is encrypted in transit and at rest. We do not sell your data, and we share it only with the service providers (processors) that act on our behalf, as described under "Third-Party Services" below.
  • If you delete your account, all associated data will be deleted from the server.
  • If you delete the app, all your data will be deleted from your device.

Overview of Processing

This overview summarizes the types of data processed, the purposes of their processing, and the categories of affected persons.

Types of Data Processed

  • Inventory data (e.g., names, addresses).
  • Contact data (e.g., email addresses, phone numbers).
  • Content data (e.g., photos, texts).
  • Usage data (e.g., features used, interaction with content, access times).
  • Meta, communication, and procedural data (e.g., IP addresses).

Categories of Affected Persons

  • Communication partners.
  • Users.

Purposes of Processing

  • Provision of contractual services and customer support.
  • Handling contact requests and communication.
  • Implementing security measures.
  • Measuring reach and user interaction.
  • Analysis of app usage for service improvement.
  • Managing and responding to inquiries.
  • Collecting feedback.
  • Maintaining our information technology infrastructure.

Legal Bases for Processing

We process personal data based on the following legal bases of the GDPR:

  • Consent (Art. 6 para. 1 lit. a GDPR): The data subject has given their consent to the processing of their personal data for one or more specific purposes.
  • Contract performance and pre-contractual inquiries (Art. 6 para. 1 lit. b GDPR): Processing is necessary for the performance of a contract or for pre-contractual measures.
  • Legitimate interests (Art. 6 para. 1 lit. f GDPR): Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, unless overridden by the data subject's interests or fundamental rights and freedoms.

In addition to GDPR, national data protection regulations in Austria, such as the Data Protection Act (DSG), apply. These include specific provisions on rights to information, correction, or deletion, and data transfer to third countries.

Special Categories of Personal Data

A diary may contain special categories of personal data within the meaning of Art. 9 GDPR (for example information about your health, religious or philosophical beliefs, political opinions, or sexual orientation). You decide entirely on your own initiative which content you store in PicDiary. Where such data is processed (for example synchronized to your account or, at your request, transcribed), this is done on the basis of your explicit consent pursuant to Art. 9 para. 2 lit. a GDPR. You can withdraw this consent at any time, for example by deleting the respective content or your account.

Security Measures

We implement technical and organizational measures to ensure data protection, including controlling access to data, maintaining data integrity and availability, and implementing privacy-friendly default settings.

Transfer and Disclosure of Data

We transfer data only within the scope of legal requirements and contractual obligations, particularly adhering to GDPR when processing data in third countries.

In-App Purchases

We collect and process personal data necessary for in-app purchases, including inventory and contact data. Payment data is handled securely and in compliance with applicable laws, often involving third-party payment service providers with their own privacy policies.

Data Retention and Deletion

We retain personal data only as long as necessary for the purposes described in this policy or as required by law. In particular:

  • Account data (diary content stored in Google Firestore and Google Storage): retained until you delete the respective entry or your account. After account deletion, the associated data is removed within 7 days.
  • Crash data (Google Crashlytics): automatically deleted by Google after 90 days.
  • Analytics data (Matomo): IP addresses are anonymized; analytics data is automatically deleted after 180 days.
  • Feedback (EmailJS): retained only as long as necessary to process and respond to your request.

Data stored locally on your device remains there until you delete the respective content or uninstall the app.

Children's Privacy

Our app is not intended for children under 14. We do not knowingly collect personal data from children under 14. If we become aware of such data collection, we will delete the information immediately. Parents or guardians should contact us if they believe their child has provided us with personal data.

Your Rights

  • Right to confirmation.
  • Right to information.
  • Right to correction.
  • Right to deletion (right to be forgotten).
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing (Art. 21 GDPR).
  • Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7 (3) GDPR).
  • Right to complain to a supervisory authority.

To exercise these rights, contact us using the details provided above. We may require identity verification before processing requests. You also have the right to lodge a complaint with the competent supervisory authority — in Austria, this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, www.dsb.gv.at).

Third-Party Services

We may employ third-party companies and individuals due to the following reasons:

  • To facilitate our service;
  • To provide the service on our behalf;
  • To perform service-related services; or
  • To assist us in analyzing how our service is used.

These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

App Analytics

We use Matomo, an open-source analytics platform, to monitor and analyze the use of our app. Matomo is self-hosted on our own servers in Germany, and all data is stored securely and in compliance with the GDPR. No personal data is shared with third parties. For more information about Matomo, please visit: https://matomo.org/privacy-policy/

Google Crashlytics

We use Google Crashlytics to monitor and report application crashes. This helps us improve the stability and performance of our app. For more information on Google's privacy practices, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy

Google Firestore and Google Storage

If you create an account, your data will be stored in Google Firestore and Google Storage. This allows us to back up and synchronize your data. For more information on Google's privacy practices, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy

Voice Notes (Deepgram and OpenAI)

PicDiary lets you attach voice notes — actual audio recordings — to your diary entries. These recordings are stored on your device. If you use an account, they are included in the same secure backup and synchronization as your other content (see "Google Firestore and Google Storage" above). Voice notes are not automatically sent to Deepgram or OpenAI.

For each voice note you can optionally request a transcript. Only when you actively request this is your data sent — via our own Cloud Functions hosted in Germany — to the following services:

  • Transcript (Deepgram): the audio of the selected voice note is sent to Deepgram to convert your speech into text, which is then inserted into your entry. For more information, please visit their https://deepgram.com/data-security.
  • Improved transcript (Deepgram + OpenAI): the audio is first transcribed by Deepgram as above, and the resulting text — together with the relevant existing entry — is then sent to OpenAI to structure, improve, and where applicable merge it into your diary entry. For more information, please visit their https://openai.com/policies/row-privacy-policy/.

These services are used solely to perform the transcription or improvement you request. They do not store or use your data beyond the completion of these tasks.

EmailJS

We use EmailJS to send user feedback. This service helps us manage and respond to your feedback effectively. For more information on EmailJS's privacy practices, please visit the EmailJS Privacy Policy web page: https://www.emailjs.com/legal/privacy-policy/

RevenueCat and App Store Payments

We use RevenueCat to manage in-app purchases and subscriptions. RevenueCat processes data such as a pseudonymous app user ID, your purchase and subscription history, and device information in order to validate, restore, and manage your purchases. The payments themselves are processed by Apple (App Store) or Google (Google Play) under their own privacy policies; we do not receive your full payment details. For more information on RevenueCat's privacy practices, please visit: https://www.revenuecat.com/privacy/

International Data Transfers

Some of the processors we use are located outside the EU, in particular in the United States (e.g., Deepgram and OpenAI for the optional transcription features, and RevenueCat for purchase management). Where data is transferred to such third countries, the transfer is based on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework, in order to ensure an adequate level of data protection. Transfers by Google in connection with Crashlytics are likewise governed by appropriate safeguards as described in Google's privacy policy. We take appropriate measures to protect your data in accordance with this policy and applicable law.

Changes and Updates to the Privacy Policy

We may modify this privacy policy to reflect legal changes or updates to our services and data processing practices. Significant changes will be communicated directly or via the app.

Contacting Us

For inquiries or support requests, providing your name and contact details (email or phone number) is necessary. This information is used solely to address your request. If you have any questions about these Terms and Conditions, You can contact us by email: privacy@picdiary.app