Dearest — Privacy Policy
Effective date: 19 July 2026 Version: 1.1
The Hungarian version (Adatkezelési Tájékoztató) prevails for consumers in Hungary.
Controller: Story Beat Pictures Kft., 2094 Nagykovácsi, Szent Lóránt utca 6., Hungary, company reg. no. 13-09-118220 — hello@dearestjournal.com
Dearest is a private diary for two. This policy is written to be read: it lists everything we process, why, for how long, and what we deliberately do not do. It applies worldwide; region-specific addenda (US, UK, Canada, Australia/NZ) add rights where local law grants them.
1. What we process, and why
Sensitive content. A diary about a relationship can reveal intimate details of your life. We treat all journal content as confidential: we do not read it, analyse it, index it for ourselves, use it for advertising, or train AI on it. Row-level security ensures that only the two linked accounts can retrieve a couple's data through the App. Ordinary journal content is not end-to-end encrypted and is technically accessible to a restricted number of authorised infrastructure administrators when strictly necessary for security, maintenance, legal compliance, or a support request you initiate. For letters, you can additionally enable Sealed mode, after which the content is end-to-end encrypted and technically unreadable to us — we hold neither the key nor any way to recover it.
2. What we deliberately do not do
No advertising, ad tech, or cross-app tracking.
No sale or sharing of personal data for anyone's marketing.
No analytics by default. Anonymous product analytics and diagnostics are
separate choices and run only after opt-in.
No AI training on your content.
No routine reading of your journal. Support never asks you to send
content unless it is necessary to resolve a request you initiated.
3. Processors and recipients
We use a small number of processors bound by data-processing agreements:
We disclose personal data to authorities only where a legally binding order compels us, and we challenge over-broad requests. Sealed-mode content cannot be disclosed in readable form by us to anyone, because we cannot decrypt it.
4. Retention
Journal content: until you delete it, or until account deletion.
Account: until you delete it (Profile → Delete account, or email
us). Deletion erases your authored content — including from your partner's view — your profile, location rows, push tokens, and your authentication record. Storage blobs (photos, voice) are removed in the same operation. Where provider backups exist, deleted database records are overwritten under the active backup cycle and within 30 days; deleted Storage objects are not included in database backups.
Purchase records: as required by tax and accounting law (in
Hungary, 8 years — Számv. tv. 169. §), limited to invoice/transaction data, never journal content.
Server and security logs: according to the hosting plan's rolling
retention period. We do not create a separate long-term copy.
Anonymous product events: PostHog EU Cloud's standard event retention,
currently up to 7 years. Withdrawing consent stops future events and resets the device identifier; earlier anonymous events cannot be tied back to your account because we never send an account, couple, name, or email identifier.
If your partner deletes their account, their authored content disappears; yours remains yours.
5. Your rights
Under the GDPR you may: access your data (Art. 15), rectify it (Art. 16), erase it (Art. 17), restrict processing (Art. 18), receive a portable copy (Art. 20 — the App's export produces your journal in open formats), object to legitimate-interest processing (Art. 21), and withdraw any consent at any time without affecting past processing (Art. 7(3)). Location and notification consents are revocable directly in iOS Settings; Diagnostics and Anonymous product analytics in the App's Privacy screen.
We answer within one month. Write to hello@dearestjournal.com. We will verify that a request about a couple's shared journal comes from an account holder of that journal, and we honour each partner's rights over their own authored content.
Complaints: you may complain to your local supervisory authority. Our lead authority is the Hungarian NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság, 1055 Budapest, Falk Miksa u. 9–11., ugyfelszolgalat@naih.hu, +36 1 391 1400, naih.hu).
6. Children
The Service is not directed to children and requires a minimum age of 16. We do not knowingly process children's data; if you believe a child uses the Service, contact us and we will delete the account.
7. Security
Transport encryption (TLS) everywhere; encryption at rest in our infrastructure; row-level security isolating each couple's data; server-managed entitlements; optional device unlock (Face ID) for the App; optional end-to-end encryption for letters, with keys that never leave your devices. No system is perfectly secure: if a breach is likely to result in a high risk to you, we will notify you and the authority as Articles 33–34 GDPR require. Report vulnerabilities per our [Vulnerability Disclosure Policy](/juli-and-me/security).
8. International use
We are established in Hungary and serve users worldwide. Where data leaves the EEA (see Section 3), we rely on adequacy decisions, the EU–US Data Privacy Framework, or Standard Contractual Clauses with supplementary measures. Additional mandatory rights under the law of your habitual residence apply regardless of whether they are repeated in this policy.
9. Changes
We will announce material changes at least 30 days in advance by email or in-App, with a dated changelog on this page. We will never reduce the protections applying to already-collected data without your consent.
10. Contact
Story Beat Pictures Kft. — hello@dearestjournal.com — 2094 Nagykovácsi, Szent Lóránt utca 6., Hungary. Data protection contact: the controller's management.