Privacy
Your journal is not our dataset.
DayJar clearly separates the local journal app from this public website. This page explains how personal data is processed in both areas.
1. Controller
Alexander Stolte
Mansfelder Straße 1, 06108 Halle (Saale)
Privacy contact: privacy@mode1090.com
2. Journal content and people in the app
Journal text, photos stored in DayJar, and voice memos are kept locally on your device. DayJar does not require an account or operate a cloud for journal content. The controller therefore does not receive this content.
People, aliases, and their links to entries are also stored locally. If you open Apple's single-contact picker and choose a contact, DayJar imports only the selected name, an available contact image, and an opaque contact identifier. Phone numbers and email addresses are not imported. This data is not sent to DayJar servers.
Your iPhone and iCloud Backup settings can affect how app data is handled as part of a device backup. Apple and your system settings control that backup, not a DayJar account.
3. Photos, system permissions, and maps
DayJar can only see photos that iOS makes available to the app. A photo location remains optional and can be removed in DayJar. Camera, microphone, photo selection, notifications, and optional system intelligence are used only after your choice and with the relevant iOS permission.
When you open a map, the operating system loads map data from Apple. This processing is necessary to provide the feature you requested. The legal basis is Article 6(1)(b) GDPR. Apple's own privacy terms also apply. Apple Privacy.
4. DayJar Premium and purchases
When you view, buy, or restore DayJar Premium, the app uses Apple's in-app purchase system and RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA. The purpose is to show offers, validate purchases, unlock Premium status, and restore purchases. The legal basis is Article 6(1)(b) GDPR. Apple processes the payment.
As a processor, RevenueCat processes a randomly generated anonymous App User ID, purchase history, and necessary store and connection data. DayJar does not send journal content, an email address, its own account ID, or an advertising ID. Transfers to the United States are safeguarded by the EU Standard Contractual Clauses under the RevenueCat Data Processing Addendum.
RevenueCat processes the data for the term of the service agreement and afterwards only where legal duties or the enforcement of claims require it. You can send deletion requests to the privacy contact. RevenueCat DPA.
5. Visiting this website
This website runs on self-managed Appwrite infrastructure. When you visit, the server and necessary network providers process the IP address, time, requested path, transferred data volume, referrer, and browser and operating system information. The purpose is delivery, stability, error analysis, and protection against attacks. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is secure and reliable website operation.
Technical logs are kept only as long as needed for operation and investigation of a security incident. They are then deleted or anonymized unless a legal retention duty or preservation of evidence in an individual case applies. Providing connection data is technically required to access the website.
The public website does not set analytics or marketing cookies. Your light or dark appearance choice is stored only in the browser. There is no tracking or automated decision-making.
6. Protected editorial area
Only approved editorial accounts can sign in. The process uses the email address, Appwrite account and session data, and a technically required HttpOnly session cookie. Abuse protection uses short-lived HMAC hashes derived from the email address and the IP address confirmed by Appwrite, without storing the raw values in the rate-limit table. The purpose and legitimate interest are access control and protection against login attacks under Article 6(1)(f) GDPR.
The session ends on sign-out or expiry. Rate-limit records expire after about 30 minutes and are cleaned up on a later sign-in attempt.
7. Contact
If you contact us by email, we process the sender address, content, and technical metadata to handle your request. Depending on the request, the legal basis is Article 6(1)(b) or (f) GDPR. Messages are deleted when the request is complete and no legal retention duty or legitimate need for evidence remains.
8. Your rights
Where the legal requirements are met, you have the following rights:
- Access to and a copy of your personal data
- Rectification of inaccurate data
- Erasure or restriction of processing
- Data portability for processing where this right applies
- Objection to processing based on legitimate interests
- Withdrawal of consent for the future where processing is based on consent
To exercise a right, contact privacy@mode1090.com.
9. Right to complain
You may lodge a complaint with a data protection supervisory authority. For the controller's location, the competent authority is the State Commissioner for Data Protection of Saxony-Anhalt: Otto-von-Guericke-Straße 34a, 39104 Magdeburg, Germany, phone +49 391 81803-0. Supervisory authority contact.
10. Version and changes
Last updated: August 27, 2026. We update this notice when features, recipients, or legal bases change materially.