Privacy Policy for diarello

Effective Date: May 2, 2026

diarello ("we," "us," or "our") is an AI-powered journaling app that helps you reflect on your life through daily entries, goals, AI-generated recaps, and conversations with an AI about your writing. Because journaling is deeply personal, we've written this Privacy Policy in plain English so you know exactly what we collect, why we collect it, and how we protect it.

This policy applies to the diarello iOS app and the diarello.com website.

What Data We Collect

We collect only what we need to make diarello work for you:

  • Email address — used to create your account, sign you in, send support replies, and (with your consent) marketing emails. Linked to your account, never used for tracking across other apps or websites.
  • Journal entries, goals, and AI chat messages — the content you create inside the app. Linked to your account, never used for tracking.
  • User ID — an internal identifier we generate to associate your data with your account. Used for app functionality and analytics.
  • Purchase history — records of subscriptions and in-app purchases. Used for app functionality and analytics.
  • Product interaction data — anonymous usage signals such as which features you use and how often. Used for analytics so we can improve the app.
  • Crash and performance data — diagnostic information that helps us fix bugs and keep the app stable. Not linked to your identity.

We do not sell your data. We do not use your journal entries, goals, or chat messages for advertising or for any kind of cross-app tracking.

How AI Processing Works

diarello uses third-party AI models to power features like weekly, monthly, and yearly recaps, insights, and the AI chat about your entries. We may change AI providers from time to time to give you the best experience; the rules below apply to whichever provider we use.

When you use an AI feature, the relevant content (for example, the entries being summarized or the messages in your chat) is sent over an encrypted HTTPS connection to the AI provider currently powering that feature. The provider acts as our service provider — it processes the content solely to generate the response we request and does not retain your content for training its models. We only work with providers whose commercial-API terms include this no-training-retention guarantee. Once the response is returned, the content is not used for any other purpose.

We send only the content needed for the specific feature you trigger. We never send your entries to any AI provider on a schedule or in the background without an action from you.

Service Providers We Use

We rely on a small number of trusted service providers to operate diarello. Each receives only the data necessary to perform its function and is contractually required to protect it.

  • AI model providers — process journal content, goals, and chat messages to generate AI responses, as described above. We may switch between providers from time to time; the provider currently in use can be obtained on request to privacy@diarello.com.
  • RevenueCat — manages subscriptions and in-app purchases. RevenueCat receives your user ID and purchase information so we can verify your subscription status across devices.
  • Resend — sends transactional emails (such as account confirmations and support replies) and, where you have opted in, marketing emails. Resend receives your email address and the content of the messages we send you.
  • Apple — processes payments for App Store subscriptions and provides crash and performance reporting.

Account Deletion

You can permanently delete your diarello account at any time, directly inside the app:

Settings → Account → Delete Account

When you delete your account, we remove your journal entries, goals, AI chat messages, email address, user ID, and other personal data from our systems within 30 days. Some records may be retained longer only when required by law (for example, billing records for tax purposes), and any such records are kept in restricted storage and not used for any other purpose.

If you would prefer to delete your account by email instead, write to privacy@diarello.com and we will handle it for you.

Your Rights

Wherever you live, you have the following rights over your data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to fix anything that is inaccurate.
  • Deletion — delete your account and your data (see above).
  • Export — request a portable copy of your journal entries and other content.

To exercise any of these rights, email privacy@diarello.com. We will respond within 30 days.

Depending on your location (for example, the EU, UK, or California), you may also have additional rights such as the right to object to processing, the right to restrict processing, or the right to lodge a complaint with your local data protection authority.

Data Retention

We keep your data for as long as your account is active. If you delete your account, your data is removed within 30 days as described above. Crash and performance data is retained for up to 90 days for debugging purposes. Billing and tax records may be retained for up to 7 years where required by law.

Security

Your data is transmitted using standard iOS HTTPS encryption (TLS) between the app, our backend, and our service providers. We do not use any custom or non-standard cryptography. While no system can be guaranteed 100% secure, we apply industry-standard safeguards to protect your data and limit access to it.

Children's Privacy

diarello is not directed at children under the age of 13, and we do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal information, please contact privacy@diarello.com and we will delete it promptly.

International Data Transfers

diarello is operated from, and our service providers may be located in, countries outside your own — including the United States. By using diarello, you understand that your data may be transferred to and processed in countries whose data protection laws may differ from those of your home country. Where required (for example, for users in the EU or UK), we rely on appropriate safeguards such as Standard Contractual Clauses to protect your data during these transfers.

Changes to This Policy

If we make material changes to this Privacy Policy, we will notify you in the app or by email before the changes take effect, and we will update the "Effective Date" at the top of this page. Continued use of diarello after the changes take effect means you accept the updated policy.

Contact Us

If you have any questions about this Privacy Policy or how your data is handled, email us at:

privacy@diarello.com