Privacy Policy
Last updated: August 8, 2026
1. Introduction
SpeakDiary is a private journaling app for text, voice, and optional AI-assisted features.
Your journal is local-first. Cloud Sync is optional. Journal content is encrypted on your device before encrypted content is synced, and we cannot read that encrypted journal content.
Features such as transcription, Lumi calls, AI insights, support, notifications, subscriptions, and Drift require limited data to reach our backend or service providers so the requested feature can work.
2. Information we collect
Account data: email address and authentication identifiers handled by our authentication provider.
Journal content: text entries, voice entries, letters, goals, moods, and check-ins are stored locally by default. If you enable Cloud Sync, encrypted versions are stored remotely.
Voice-entry audio: stored on your device first. Audio you choose to transcribe or sync is sent for that purpose.
Lumi call data: our voice provider processes live call audio. SpeakDiary may retain the resulting transcript, summary, call status, duration, and rating. SpeakDiary does not offer saved Lumi call recordings or add call audio to your journal.
Diagnostics, device, and security data: app usage, crash data, device and OS details, language, push token, and short-lived network or request metadata. These are not joined to decrypted journal content.
Payment data: app stores and RevenueCat manage purchases and entitlements. We do not store complete payment credentials.
3. Permissions and device access
- Microphone: voice entries and Lumi calls.
- Photos or media: optional local avatar selection, where supported.
- Notifications: reminders, scheduled messages, and security alerts. Push tokens are stored for delivery.
- Biometrics: optional local unlock and security flows on supported devices.
- Location: SpeakDiary does not request GPS location permission.
4. Storage and sync
Local app storage and a local database hold your on-device data. If Cloud Sync is enabled, encrypted records are synced through our backend and Firestore.
Voice-entry audio you choose to sync may be stored in secure object storage and linked to your account for playback and cross-device sync. This does not apply to Lumi call recordings.
5. AI and voice processing
AI features are optional and process only the content needed for the feature you request. Voice entries may be sent for transcription; text may be sent for summaries, insights, prompts, categorisation, translation, or related outputs.
For Lumi calls, Retell processes live audio to conduct and transcribe the conversation. The transcript or summary—not a saved recording—can become a journal reflection.
When the app is unlocked in your real profile, a call may also receive a minimised on-device context containing up to three recent journal titles/categories and up to three active goal titles with numeric progress you entered. Journal bodies, encrypted entries, record IDs, and full history are excluded.
We do not use your journal content to train AI models or for advertising.
6. How we use information
- Provide journaling, calls, sync, AI features, and notifications you request.
- Maintain security, enforce entitlements, moderate public content, and prevent abuse.
- Improve performance and reliability. We do not sell personal data or use private journal entries for advertising.
7. Sharing and third parties
We share only what is needed with providers for authentication, encrypted sync, AI and transcription, voice calls, notifications, support email, subscriptions, hosting, app-store billing, analytics, crash reporting, and secure object storage. Current providers include Firebase/Google, OpenAI, Google Gemini, Retell, RevenueCat, Cloudflare R2, Inbound, Vercel, Apple, and Google Play.
We may also disclose information when legally required or as part of a business transfer subject to applicable safeguards.
Crisis-resource links open an external phone, messaging, or website service. That service’s own privacy and charging terms apply once you contact it.
8. Retention and deletion
Local data remains until you delete it or remove the app. Account-linked cloud data is retained while your account is active and is removed or anonymised within 30 days after account deletion unless security, fraud-prevention, or legal duties require otherwise.
Provider-side processing records may follow the provider retention settings and contractual terms described here. SpeakDiary does not promise that live call audio is deleted immediately by the voice provider.
9. Drift community feed
Drift is an optional public, anonymous feed. Reading and reacting are free; posting requires Pro. Posts have no public username, profile, or history.
We keep an irreversible account-derived author code for rate limits, blocking, and moderation. It never appears in API responses, logs, or analytics. Public responses also exclude internal hidden status and report counts.
A coarse origin is shared only when you turn on the composer option. It is derived from the device time zone, not GPS, and includes a region label plus coordinates rounded to one decimal place. Posting without an origin is supported.
Posts stop appearing after 24 hours. An hourly cleanup then permanently deletes expired posts and their translations, reactions, and reports, normally within one additional hour. You may delete your own post during its first four hours.
Crisis-language posts are not published or stored. A content-free safety event may be retained for up to 30 days. Reported posts may be hidden for moderator review. Do not include identifying information in public posts.
10. Your choices and rights
You can choose whether to enable Cloud Sync, notifications, AI features, coarse Drift origin, and other optional processing. You may access, correct, export, or delete eligible data in the app.
For privacy requests, email [email protected].