MonDiary Privacy Policy
Last Updated: November 21, 2025
Effective Date: November 21, 2025
Your Privacy Matters: MonDiary is designed to be your private, personal diary. Your journal entries are stored locally on your device and are never accessed or read by us. Any cloud synchronization is optional and under your full control.
1. Introduction
Welcome to MonDiary ("App," "we," "us," or "our"). MonDiary is a personal diary and journaling application developed and operated by UKGADGETS LTD, a company registered in the United Kingdom.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application available on iOS, Android, and macOS platforms. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.
We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.
2.1 Information You Provide Directly
The following information is stored locally on your device and is under your complete control:
- Diary Entries: Text content, titles, dates, and timestamps of your journal entries
- Mood Data: Mood selections and emotional tracking information you record
- Media Files: Photos, videos, and audio recordings you attach to entries
- Tags and Categories: Custom tags you create to organize your entries
- Stickers and Annotations: Visual elements you add to your entries
- App Preferences: Theme settings, reminder times, and other customizations
2.2 Optional Information
- Email Address: Only if you choose to set up account recovery, your email is stored securely and encrypted
- Security Credentials: PIN codes and security question answers are stored in encrypted form using industry-standard encryption (Argon2 hashing)
2.3 Automatically Collected Information
When you use certain features of the App, we may automatically collect:
- Device Information: Device model, operating system version, and unique device identifiers
- App Usage Data: Features used, subscription status, and purchase history (processed by RevenueCat)
- Technical Data: IP address (collected automatically when connecting to third-party services)
- Analytics Data: Session duration, app launches, engagement metrics, and subscription purchase events (via Firebase Analytics integrated with RevenueCat)
- Crash Reports: Error logs and crash data to diagnose and fix app issues (via Firebase Crashlytics, release builds only)
- Firebase Installation ID: Anonymous identifier for analytics, crash reporting, and advertising attribution
- Firebase App Instance ID: Unique identifier linking RevenueCat purchase data with Firebase Analytics for Google Ads targeting
2.4 Biometric Data
If you enable Face ID or fingerprint authentication, this biometric data is processed entirely by your device's operating system. We never receive, store, or have access to your biometric data.
2.5 Sentiment Analysis
MonDiary includes optional sentiment analysis and psychological insights features. All analysis is performed locally on your device. Your diary content is never sent to external servers for analysis.
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose |
Description |
| App Functionality |
To provide core diary features including entry creation, mood tracking, and media attachment |
| Cloud Backup |
To enable optional backup and sync via Google Drive or iCloud (user-initiated only) |
| Account Recovery |
To help you recover access to your diary if you forget your PIN |
| Subscription Management |
To process and manage premium subscriptions and in-app purchases |
| Notifications |
To send you daily reminders and journaling prompts (if enabled) |
| Analytics |
To measure and improve app performance (via RevenueCat aggregated analytics) |
| Advertising Attribution |
To measure the effectiveness of our advertising campaigns |
| App Diagnostics & Improvement |
To detect, diagnose, and fix crashes and errors via Firebase Crashlytics |
| Usage Analytics |
To understand app usage patterns and improve features via Firebase Analytics |
| Google Ads Optimization |
To measure ad campaign effectiveness and optimize targeting using Firebase Analytics data and RevenueCat purchase events |
4. Data Storage and Security
4.1 Local Storage
Your diary entries and media files are stored locally on your device in the following locations:
- Database: SQLite database stored in the app's private documents directory
- Media: Photos, videos, and audio files stored in the app's documents directory
- Preferences: App settings stored in platform-specific secure storage
4.2 Encrypted Storage
Sensitive information is protected using industry-standard encryption:
- iOS: Keychain Services with first-unlock accessibility
- Android: EncryptedSharedPreferences with AES-256 encryption
- macOS: Encrypted preferences storage
PIN codes and security credentials are hashed using Argon2, a modern password-hashing algorithm designed for security.
4.3 Cloud Storage (Optional)
If you choose to enable cloud backup:
- Google Drive: Backups are stored in your personal Google Drive's hidden app data folder
- iCloud: Data syncs to your personal iCloud account
Cloud backups contain your diary entries and media files. These services are governed by Google's and Apple's respective privacy policies.
4.4 Data Transmission Security
All data transmitted from the App uses HTTPS encryption to protect your information in transit.
5. Third-Party Services
MonDiary uses the following third-party services that may collect information:
5.1 RevenueCat (Subscription Management)
We use RevenueCat to manage subscriptions and in-app purchases. RevenueCat collects:
- Device identifiers
- Purchase history and subscription status
- Platform information (iOS/Android)
- App Store or Play Store receipt data
For more information, see RevenueCat's Privacy Policy.
5.2 Google Services
If you choose to use Google Drive backup:
- We request access only to the app-specific data folder (not your entire Drive)
- Your Google account email is stored locally to display your signed-in status
- Authentication is handled securely via Google Sign-In
For more information, see Google's Privacy Policy.
5.3 Apple Services
If you use iCloud sync (iOS/macOS only):
- Data syncs to your personal iCloud account
- Apple manages the encryption and security of iCloud data
For more information, see Apple's Privacy Policy.
5.4 Email Service (Zepto Mail)
If you set up email-based account recovery, we use Zepto Mail to send recovery codes. This requires your email address, which is transmitted securely and used solely for sending recovery codes.
5.5 Firebase Services (Google)
We use Firebase, a platform provided by Google LLC, for app analytics and crash reporting:
Firebase Analytics:
- Automatically collects app usage data including:
- Session duration and frequency
- Device information (model, OS version, language, country)
- App version and install/update events
- First app open and basic engagement metrics
- Purchase and subscription events from RevenueCat (for Google Ads attribution)
- Integrated with RevenueCat via Firebase App Instance ID linkage
- Purchase data includes: subscription status, purchase events, revenue (anonymized per user)
- All personal data is anonymized and aggregated
- Used for app performance analytics and Google Ads campaign attribution
- Enables Google Ads conversion tracking and audience targeting
Firebase Crashlytics:
- Enabled only in release builds (disabled during development)
- Automatically collects when the app crashes:
- Crash reports and stack traces
- Device specifications (model, OS, RAM, storage, battery level)
- Session identifiers and crash timestamps
- Network connectivity status
- App configuration context (premium status, theme selection, backup provider)
- Custom error context to help diagnose issues
- Anonymous Firebase Installation ID (not linked to personal identity)
- Does NOT collect: diary content, passwords, email addresses, or personal notes
All Firebase data is transmitted securely via HTTPS and stored on Google's servers in the United States. For more information, see Google's Privacy Policy and Firebase Data Processing Terms.
6. Advertising Attribution and Tracking
6.1 Advertising Attribution
We use advertising attribution services to measure the effectiveness of our marketing campaigns and understand how users discover MonDiary. This helps us optimize our advertising spend and reach users who would benefit from our app.
Meta (Facebook) Attribution:
- Currently integrated via RevenueCat for subscription attribution
- Collects device identifiers for attribution purposes only
- Tracks conversion events (such as app installs and subscriptions)
- Facebook App Events SDK processes data
- Facebook Advertiser ID collection enabled on iOS (with your permission via App Tracking Transparency)
- For more information, see Meta's Privacy Policy
Google Ads Attribution (via Firebase Analytics):
- Currently integrated to measure campaign effectiveness and optimize ad targeting
- Uses Firebase Analytics data including:
- App install and usage events
- Subscription purchase events from RevenueCat
- User engagement metrics and session data
- Conversion tracking enabled through Firebase Analytics integration
- Collects advertising identifiers (IDFA on iOS with permission, AAID on Android)
- Purchase events automatically flow from RevenueCat → Firebase Analytics → Google Ads
- Used for:
- Measuring ad campaign ROI
- Creating lookalike audiences
- Targeting users likely to subscribe
- Optimizing ad spend
- For more information, see Google Ads Privacy Policy and Firebase Analytics Privacy
Important: We do NOT display any advertisements within the app. Attribution tracking is used solely to measure the effectiveness of external marketing campaigns that bring users to MonDiary. Your diary content and personal notes are never shared with advertising platforms.
6.2 App Tracking Transparency (iOS)
On iOS devices, we request your permission through Apple's App Tracking Transparency framework before collecting the Identifier for Advertisers (IDFA). You can:
- Deny tracking when prompted
- Change your preference in iOS Settings > Privacy > Tracking
If you deny tracking, we will not collect your IDFA for advertising purposes.
6.3 No In-App Advertisements
MonDiary does not display banner ads, interstitial ads, or any other advertising within the app.
7. Your Privacy Rights
7.1 Rights for All Users
Regardless of your location, you have the right to:
- Access: View and export all your diary data at any time
- Delete: Delete any or all diary entries from the app
- Portability: Export your data in multiple formats (PDF, TXT, ZIP)
- Opt-out: Disable cloud backup, notifications, and tracking at any time
7.2 European Union Residents (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing:
• Contract: Processing diary data to provide the service you requested
• Consent: For optional features like email recovery and cloud backup
• Legitimate Interest: For analytics and improving our service
Your GDPR Rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of processing
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
Data Controller:
UKGADGETS LTD
Email: [email protected]
You also have the right to lodge a complaint with your local data protection authority.
7.3 California Residents (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information Collected:
- Identifiers (device ID, email if provided)
- Commercial information (purchase history)
- Internet or network activity (app usage data)
- Sensory data (photos, videos, audio you create)
Your CCPA Rights:
- Right to Know: Request disclosure of personal information collected
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt-out of the sale or sharing of personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
Do Not Sell or Share My Personal Information:
We do not sell your personal information. We share device identifiers with Meta for advertising attribution purposes. To opt-out, deny App Tracking Transparency permission on iOS or contact us to request opt-out.
To exercise your CCPA rights, contact us at [email protected].
7.4 UK Residents
If you are a UK resident, you have similar rights under the UK GDPR. You can contact the Information Commissioner's Office (ICO) if you have concerns about our data practices.
8. Data Retention and Deletion
8.1 Local Data
- Diary entries and media are retained until you delete them
- App preferences are retained until you uninstall the app
- Encrypted credentials are retained in secure storage until you reset them or uninstall the app
8.2 Cloud Data
- Google Drive backups are retained until you delete them from the app or directly from Google Drive
- iCloud data is retained until you delete it from the app or your iCloud account
8.3 Third-Party Data
- RevenueCat retains purchase and subscription data according to their retention policy
- Meta retains advertising data according to their data retention practices
- Firebase Analytics retains automatically collected data for 14 months (Google's default)
- Firebase Crashlytics retains crash reports for 90 days (non-fatal errors) and 1 year (fatal crashes)
- Firebase Authentication retains anonymous user IDs for the lifetime of the account
8.4 Account Deletion
To delete all your data:
- Delete all diary entries within the app
- Sign out of Google Drive and/or iCloud backup
- Delete cloud backups from Google Drive or iCloud
- Uninstall the app from your device
For assistance with complete data deletion, contact us at [email protected].
9. Children's Privacy
MonDiary is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children under these ages.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected]. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including:
- United States: Firebase services (Analytics, Crashlytics, Authentication), RevenueCat servers, and Meta advertising services
- Various locations: Google Cloud infrastructure (Firebase backend), Google Drive, Apple iCloud
These countries may have data protection laws different from those in your country. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Data Processing Agreements with our service providers
- Privacy Shield certification (where applicable)
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Updating the "Last Updated" date at the top of this policy
- Providing notice within the app for material changes
We encourage you to review this Privacy Policy periodically. Your continued use of the App after any changes indicates your acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
© 2025 UKGADGETS LTD. All rights reserved.
MonDiary Privacy Policy v1.0