DEAREST

Dearest — Privacy Policy

Effective date: 19 July 2026 Version: 1.1

The Hungarian version (Adatkezelési Tájékoztató) prevails for consumers in Hungary.

Controller: Story Beat Pictures Kft., 2094 Nagykovácsi, Szent Lóránt utca 6., Hungary, company reg. no. 13-09-118220 — hello@dearestjournal.com

Dearest is a private diary for two. This policy is written to be read: it lists everything we process, why, for how long, and what we deliberately do not do. It applies worldwide; region-specific addenda (US, UK, Canada, Australia/NZ) add rights where local law grants them.


1. What we process, and why

| Data | Source | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Email address, password hash | You, at sign-up | Account, sign-in, service messages | Art. 6(1)(b) contract |
| Name, partner link, "together since" date, chapter names, timezone | You | Operating your shared journal; delivering letters on the right calendar day in your timezone | Art. 6(1)(b) |
| Journal content: memories, letters, prompts answers, dreams, milestones, photos, voice notes | You and your partner | Storing and displaying your journal to the two of you; exports you request | Art. 6(1)(b) |
| Sealed-mode ciphertext | Your device | Storing letters we cannot read (end-to-end encrypted) | Art. 6(1)(b) |
| Precise coordinates and optional place name | Your device, only if you grant the permission and enable sharing | Showing distance and whether you are together; the latest location can be updated in the background only if you separately grant "Always" access | Art. 6(1)(a) consent, revocable in the App and iOS Settings |
| Push notification token | Your device, if you allow notifications | Delivering letter-arrival and partner-activity notifications | Art. 6(1)(a) consent |
| Purchase entitlement (subscription or one-time "Forever" status, pseudonymous user ID) | Apple / RevenueCat | Unlocking paid features for both partners; fraud prevention | Art. 6(1)(b), 6(1)(f) |
| Diagnostics (crash reports) | Your device, only if you opt in (off by default) | Fixing crashes | Art. 6(1)(a) consent |
| Anonymous product events (for example: onboarding completed, feature used, export format, or purchase step; random device identifier and basic app/device metadata) | Your device, only if you opt in (off by default) | Understanding whether the product works and improving onboarding and paid features | Art. 6(1)(a) consent |
| Basic server logs (IP address, timestamps) | Your device | Security, abuse prevention | Art. 6(1)(f) legitimate interest |

Sensitive content. A diary about a relationship can reveal intimate details of your life. We treat all journal content as confidential: we do not read it, analyse it, index it for ourselves, use it for advertising, or train AI on it. Row-level security ensures that only the two linked accounts can retrieve a couple's data through the App. Ordinary journal content is not end-to-end encrypted and is technically accessible to a restricted number of authorised infrastructure administrators when strictly necessary for security, maintenance, legal compliance, or a support request you initiate. For letters, you can additionally enable Sealed mode, after which the content is end-to-end encrypted and technically unreadable to us — we hold neither the key nor any way to recover it.

2. What we deliberately do not do

No advertising, ad tech, or cross-app tracking.

No sale or sharing of personal data for anyone's marketing.

No analytics by default. Anonymous product analytics and diagnostics are

separate choices and run only after opt-in.

No AI training on your content.

No routine reading of your journal. Support never asks you to send

content unless it is necessary to resolve a request you initiated.

3. Processors and recipients

We use a small number of processors bound by data-processing agreements:

| Processor | Role | Location / transfer safeguard |
|---|---|---|
| Supabase | Database, file storage, authentication | EU — AWS eu-west-1 (Ireland); SCCs where applicable |
| Apple | Payment processing, push delivery (APNs) | Apple's own terms |
| RevenueCat | Subscription entitlement management (pseudonymous ID, receipt data — never your journal) | USA; EU–US Data Privacy Framework / SCCs |
| Expo (EAS) | Push notification relay (token, message envelope) | USA; SCCs |
| Sentry — only if it is configured and you opt in to Diagnostics | Crash reports tagged with a pseudonymous account ID; no journal content by design | Region selected in the Sentry project; SCCs where applicable |
| PostHog — only if you opt in to Anonymous product analytics | Content-free product events using a random device identifier; no person profile | EU Cloud (Frankfurt); IP capture disabled |

We disclose personal data to authorities only where a legally binding order compels us, and we challenge over-broad requests. Sealed-mode content cannot be disclosed in readable form by us to anyone, because we cannot decrypt it.

4. Retention

Journal content: until you delete it, or until account deletion.

Account: until you delete it (Profile → Delete account, or email

us). Deletion erases your authored content — including from your partner's view — your profile, location rows, push tokens, and your authentication record. Storage blobs (photos, voice) are removed in the same operation. Where provider backups exist, deleted database records are overwritten under the active backup cycle and within 30 days; deleted Storage objects are not included in database backups.

Purchase records: as required by tax and accounting law (in

Hungary, 8 years — Számv. tv. 169. §), limited to invoice/transaction data, never journal content.

Server and security logs: according to the hosting plan's rolling

retention period. We do not create a separate long-term copy.

Anonymous product events: PostHog EU Cloud's standard event retention,

currently up to 7 years. Withdrawing consent stops future events and resets the device identifier; earlier anonymous events cannot be tied back to your account because we never send an account, couple, name, or email identifier.

If your partner deletes their account, their authored content disappears; yours remains yours.

5. Your rights

Under the GDPR you may: access your data (Art. 15), rectify it (Art. 16), erase it (Art. 17), restrict processing (Art. 18), receive a portable copy (Art. 20 — the App's export produces your journal in open formats), object to legitimate-interest processing (Art. 21), and withdraw any consent at any time without affecting past processing (Art. 7(3)). Location and notification consents are revocable directly in iOS Settings; Diagnostics and Anonymous product analytics in the App's Privacy screen.

We answer within one month. Write to hello@dearestjournal.com. We will verify that a request about a couple's shared journal comes from an account holder of that journal, and we honour each partner's rights over their own authored content.

Complaints: you may complain to your local supervisory authority. Our lead authority is the Hungarian NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság, 1055 Budapest, Falk Miksa u. 9–11., ugyfelszolgalat@naih.hu, +36 1 391 1400, naih.hu).

6. Children

The Service is not directed to children and requires a minimum age of 16. We do not knowingly process children's data; if you believe a child uses the Service, contact us and we will delete the account.

7. Security

Transport encryption (TLS) everywhere; encryption at rest in our infrastructure; row-level security isolating each couple's data; server-managed entitlements; optional device unlock (Face ID) for the App; optional end-to-end encryption for letters, with keys that never leave your devices. No system is perfectly secure: if a breach is likely to result in a high risk to you, we will notify you and the authority as Articles 33–34 GDPR require. Report vulnerabilities per our [Vulnerability Disclosure Policy](/juli-and-me/security).

8. International use

We are established in Hungary and serve users worldwide. Where data leaves the EEA (see Section 3), we rely on adequacy decisions, the EU–US Data Privacy Framework, or Standard Contractual Clauses with supplementary measures. Additional mandatory rights under the law of your habitual residence apply regardless of whether they are repeated in this policy.

9. Changes

We will announce material changes at least 30 days in advance by email or in-App, with a dated changelog on this page. We will never reduce the protections applying to already-collected data without your consent.

10. Contact

Story Beat Pictures Kft. — hello@dearestjournal.com — 2094 Nagykovácsi, Szent Lóránt utca 6., Hungary. Data protection contact: the controller's management.