zDiary Privacy Policy
Local-first diary privacy for App Store Connect — effective September 30, 2026.
Effective date: September 30, 2026
App: zDiary (app.zdiary.ios)
Developer: Corey J. Mahler
This Privacy Policy describes how zDiary handles information when you use the iOS app (and related Apple Watch companion features). zDiary is designed to be local-first: your diary lives on your devices unless you choose to export a file or turn on optional encrypted backup (zSync).
This document is written for App Store Connect (including Beta App Review) and for people who use the app. It is not legal advice.
Summary
- We do not sell your personal data.
- We do not use your data for advertising or tracking across apps or websites.
- Apple’s App Privacy “nutrition label” for the app reports no tracking (
NSPrivacyTracking= false). - Location, motion, Health, photos (for journal), and Face ID are used on device to run the diary features you enable.
- Optional zSync uploads only client-encrypted backup envelopes to private cloud storage. The recovery key never leaves your devices. The backup service cannot read your diary.
Information the App Uses on Your Device
Depending on the permissions you grant in iOS Settings, zDiary may use:
Location
- What: Precise location and visit-related location data (including background location when you grant Always).
- Why: To record places you stay, geofences, optional Full detail tracks, and related diary features (including temporary Full tracking during commute-like motion when that feature is on).
- Where it stays: On your device. Tracks and visits are not uploaded to our servers unless you export a file yourself or enable zSync (see below). Background location is used only for diary functionality.
Motion / Fitness Activity
- What: Motion history such as walking, running, cycling, and automotive activity (
CMMotionActivity). - Why: To label time between stays without turning on continuous GPS for everyday parity tracking.
- Where it stays: On your device.
Apple Health (HealthKit)
- What (read): Sleep Analysis, workouts, mindfulness, and steps.
- Why: To complete the day (for example, sleep may replace overlapping night stationary time; workouts and mindfulness can override their intervals; steps are a measure of the day, not a place).
- What we do not do: zDiary does not write these types back to Health. zDiary does not use a Sleep Cycle (or similar) account. Health data is used only for app functionality on your device and is not used for advertising, sold, or used for tracking.
- Where it stays: Derived diary slices stay on your device (and in any export or encrypted backup you choose to make).
Photos
- What: Access to look up photos in a time window so you can attach them to a weekly journal.
- How stored by default: As on-device Photos library asset ids. Pixel data stays on your iPhone and is not uploaded unless a later backup opt-in explicitly includes it.
- Vision: Optional on-device suggestions are limited to things (for example food or drink). The app does not identify people or use Photos People.
Face ID / Device Authentication
- What: Face ID or other device owner authentication.
- Why: Optional journal lock when a weekly journal exists (and related lock settings).
- Where it stays: Authentication happens on device via Apple frameworks; we do not receive your biometrics.
Diary Content You Create
- Stays, places, activities, slices, journal entries, device tags, and related diary data stored in the app’s local store / App Group as needed for the iPhone and Watch glance features.
- You can export a
diary.v1archive (and CSV via the share sheet where available). Exports you share leave the device under your control.
Purchases (zSync)
- If you subscribe to zSync, Apple processes the purchase through StoreKit / App Store. We receive entitlement status needed to unlock backup/Join features. StoreKit does not name your diary person identity.
Apple Watch and App Groups
The Watch companion can show a phone-mediated glance and complications (current slice / journal preview) using data pushed from the paired iPhone (for example via WatchConnectivity and the App Group group.app.zdiary.ios). The Watch is not a separate cloud account and is not a first-class backup peer. Capture remains on the iPhone.
Optional Cloud Backup (zSync)
zSync is optional and paid. When enabled:
- Your device encodes the diary archive in memory.
- The device encrypts it with AES-256-GCM using a key kept in the iOS Keychain.
- Only a sealed envelope (
zdiary.backup.v1) is uploaded over HTTPS to our backup Worker and stored in a private object store (Cloudflare R2 bucketzdiary-backups). - The recovery key is never sent to the backup service. The service refuses plaintext diary bodies.
- Auth uses an account id and HMAC token you configure in Settings (channel credentials), separate from your diary person id / recovery key.
- Retention is roughly rolling 30 days of backup objects for that account.
- Join / restore merges into the destination diary; it does not silently overwrite like a one-phone cloud restore.
Operators of the backup infrastructure can see ciphertext, account identifiers used for auth, and operational metadata (timestamps, object keys). They cannot decrypt diary contents without your recovery key.
What We Do Not Do
- No sale of personal data.
- No third-party advertising SDKs in the app for serving ads.
- No cross-app or cross-site tracking as defined by Apple’s privacy nutrition label (
NSPrivacyTrackingis false). - No use of HealthKit data for advertising or marketing.
- No requirement to create a social login (no Facebook login).
- No live continuous GPS sync to our servers as a product feature.
Analytics and Crash Data
zDiary does not currently operate a first-party analytics product that profiles your diary. System-level diagnostics Apple may collect when you opt in (for example App Store / TestFlight crash reports) are governed by Apple’s policies.
Children
zDiary is not directed at children under 13. Do not use the app to submit children’s data if you are not permitted to do so.
Data Retention and Deletion
- On device: Delete the app (and related Watch app data) to remove local diary data from that device, subject to normal iOS backups you control (iCloud/computer backups of the device).
- Exports: Files you exported remain wherever you saved or sent them.
- zSync: You can delete individual backup objects through the app/API flows where available; older objects age out on the rolling retention schedule. Losing the recovery key means ciphertext cannot be recovered by us.
Your Choices
- Grant or revoke Location, Motion, Health, Photos, and Face ID permissions in iOS Settings.
- Keep backup off; use only on-device diary and optional file export/import.
- Turn zSync off; copy or secure your recovery key if you use Join/backup.
- Use journal lock settings when a journal exists.
International Users
Backup infrastructure may be operated on cloud providers that process data in the United States or other regions. Encrypted envelopes are still unreadable without your recovery key.
Changes
We may update this Privacy Policy as the product changes. The effective date at the top will change when we do. Material changes for App Store builds will be reflected at this URL before or when those builds ship.
Apple HealthKit Specific Statement
HealthKit data (Sleep Analysis, workouts, mindfulness, and steps) is read solely to provide diary functionality on your device. It is not sold, not used for advertising, and not used for data mining unrelated to improving health management or the diary features you enabled. zDiary does not write those HealthKit types back to Apple Health.