DiaryNote(每日日记)隐私权政策
开发者:liuwen-org
DiaryNote 是一款本地优先的日记应用,无需注册开发者账号即可记录。本政策说明当前版本如何处理日记、应用设置及使用统计信息。记录、查看、编辑和搜索日记可离线使用,但应用包含联网的使用统计服务。
一、应用处理的数据及用途
- 日记数据:你主动输入的标题、正文、富文本、日期、天气、心情及所选图片,以及创建、修改和删除时间,用于保存、展示、编辑、搜索、排序、日历和回收站功能。天气和心情由你手动选择,不通过设备定位获取。
- 应用设置:主题、语言、排序、提醒、心情选项和应用锁等设置,用于保存偏好及本地访问控制。
- 密码信息:设置应用密码时,在设备本地保存加盐派生后的验证值,用于核验密码;不将应用密码发送给开发者或统计服务。
- 使用统计:通过 Google Analytics for Firebase 自动收集使用事件、应用和设备信息及标识符,用于了解使用情况和改进应用,详见第二节。
应用不要求提供姓名、邮箱、手机号或身份证号,也不请求精确定位、通讯录、通话记录、短信、相机或麦克风权限。你自行写入日记或选择的图片可能包含这些信息,其内容由你决定。
二、使用统计和网络访问
应用具有互联网访问权限,并接入 Google Analytics for Firebase。当前版本从应用启动时默认启用自动统计,不以应用内隐私提示的同意操作为启用条件,未提供应用内的统计关闭开关。联网时,SDK 会将自动收集的统计数据发送至 Google;统计不依赖于是否使用备份功能。
统计数据可能包括应用启动、会话及屏幕浏览等使用事件,应用版本、操作系统版本、设备型号、语言、应用实例标识符,以及在系统允许且可用时的 Android 广告标识符。Google 可在收集时根据 IP 地址推算大致地区,这不需要设备定位权限。
应用不会把日记标题、正文、图片、应用密码或备份密码作为统计事件或参数发送,也不将日记内容上传至开发者服务器。应用不包含广告 SDK,不出售日记数据。开发者可通过 Google 提供的统计报表了解应用使用情况。
统计由 Google 处理,保存期限取决于 Google Analytics 媒体资源的保留设置和适用服务规则。Google 可能在你所在国家或地区之外处理数据。有关 SDK 数据类别,请参阅 Firebase 数据收集说明;有关 Google 的处理规则,请参阅 Google 隐私政策。
三、图片、系统权限和设备验证
应用通过 Android 系统图片选择器读取你明确选择的图片,并将原始图片复制到应用私有目录以供日记使用;也可接收你从其他应用主动分享的文字或图片。应用不会扫描未选择的相册内容。原始图片可能保留拍摄时间或位置等内嵌元数据。
开启每日提醒时,应用使用通知权限显示本地提醒,并通过开机、时间和时区变化通知重新安排提醒。你可以在应用或系统设置中关闭提醒及通知权限。
启用指纹或设备解锁时,验证由 Android 系统完成,应用仅接收验证结果,不读取或保存指纹等生物特征数据。你可以在应用中关闭该解锁方式。
四、手动备份、导入与云同步状态
你可以主动导出带密码加密的备份文件,或选择已有备份进行导入。备份包含日记内容、关联图片和可迁移的应用偏好,不包含应用锁密码及锁定状态。文件保存到你通过系统文件选择器指定的位置;如果选择云盘或第三方文件服务,该服务会按其自身规则处理文件。请妥善保管备份文件和密码。
当前版本未向用户开放自动备份、Google Drive 云同步和日记导出入口(PDF、图片、Markdown、TXT 和 HTML),相关后台备份及同步任务也被禁用。应用目前不会通过这些功能自动将日记上传到 Google Drive。上述使用统计仍独立运行;未来开放这些功能时将相应更新政策。
五、Android 系统备份和设备迁移
应用允许 Android 系统备份。当前备份规则仅将日记数据库和应用保存的日记图片纳入备份或设备迁移,不包含应用偏好、密码验证信息、锁定状态及缓存。云备份要求系统具备相应的加密能力;是否实际备份或迁移由 Android 版本、设备厂商和你的系统设置决定。
系统备份由操作系统或备份服务提供商处理,不会将日记提供给开发者。你可以在系统设置中管理备份。日记文本加密使用设备上的 Android Keystore 密钥,该密钥不包含在上述备份中,因此系统备份或换机迁移不保证能恢复加密文本;需要迁移时,请使用应用的手动加密备份。
六、数据保存、删除及你的选择
日记和设置默认保存在设备本地。删除日记或“清空日记”会先将其移入回收站,可在 30 天内恢复;你可以在回收站永久删除或清空。超过 30 天的条目会在应用执行清理时删除,并清理不再被其他日记引用的图片。
你可以查看、更正和删除日记,通过清除应用数据或卸载应用移除本地数据,也可以在系统设置中管理通知、图片访问和备份。撤销图片来源访问不自动删除已经复制到应用内的图片。导出的备份和其他外部文件、系统云备份及其他设备上的副本需要在相应位置另行管理或删除。
删除日记、清除应用数据或卸载应用,不会自动删除此前发送给 Google 的统计数据。当前版本没有统计关闭开关;你可以停止使用并卸载应用以停止该安装后续的统计收集。如有数据访问、删除或其他隐私请求,请通过第十节的联系方式联系开发者。
七、安全措施
应用使用 Android 应用隔离保护私有数据,并使用 AES-GCM 和 Android Keystore 加密本地日记标题、正文及富文本内容。日期、天气、心情等数据库字段和原始图片不在此文本加密范围内,不能将其理解为整个数据库或所有文件均已加密。手动备份文件另行使用密码加密。
可选应用密码和系统验证用于控制应用访问。请妥善保管设备、系统解锁凭据、应用密码、备份密码和外部文件。任何安全措施都无法保证绝对安全。
八、未成年人保护
应用不要求提供年龄或身份信息。未成年人应在监护人指导下使用,并避免在日记、图片或备份中记录和传播不必要的敏感个人信息。
九、政策更新
应用功能或数据处理方式变化时,本政策将相应更新。请在更新应用后查看本页面的日期、适用版本和内容。
十、联系我们
如对本政策有疑问、投诉或个人信息相关请求,请联系开发者:liuwen.yeah@gmail.com。请勿在邮件中发送日记全文、密码或其他不必要的敏感信息。你主动提供的邮箱和请求内容将用于处理及回复你的请求。
DiaryNote Privacy Policy
Developer: liuwen-org
DiaryNote is a local-first diary app. You can start writing without registering a developer account. This policy describes how the current version handles diaries, settings, and usage analytics. Writing, viewing, editing, and searching diaries work offline, while the app also includes an online analytics service.
1. Data handled and its purposes
- Diary data: titles, text, rich text, dates, weather, moods, selected images, and creation, modification, and deletion times, used for storage, display, editing, search, sorting, calendar, and recycle-bin features. You select weather and moods manually; they are not obtained using device location.
- Settings: theme, language, sorting, reminders, mood options, and app-lock settings, used for preferences and local access control.
- Password information: setting an app password stores a salted, derived verification value locally. The app password is not sent to the developer or analytics service.
- Usage analytics: Google Analytics for Firebase automatically collects usage events, app and device information, and identifiers to understand usage and improve the app, as described below.
The app does not require your name, email address, phone number, or government identifier, or request permissions for precise location, contacts, call logs, messages, camera, or microphone. Diaries and images you choose may contain such information; you decide their contents.
2. Usage analytics and network access
The app has Internet access and includes Google Analytics for Firebase. Automatic analytics is enabled by default from app startup, without waiting for acceptance of the in-app privacy prompt. This version has no in-app switch to disable it. When online, the SDK sends automatically collected analytics to Google, independently of backup usage.
Analytics may include app launches, sessions, screen views, app and operating-system versions, device model, language, an app-instance identifier, and the Android advertising identifier when permitted and available. Google may derive an approximate region from the IP address during collection; this does not require device location permission.
The app does not send diary titles, text, images, app passwords, or backup passwords as analytics events or parameters, or upload diary content to developer servers. It contains no advertising SDK and does not sell diary data. The developer can view usage reports provided by Google.
Google processes analytics, with retention governed by the Google Analytics property's retention settings and applicable service rules. Google may process data outside your country or region. See Firebase's data collection information for SDK data categories and Google's Privacy Policy for its processing practices.
3. Images, permissions, and device authentication
The app reads images you explicitly select using the Android system photo picker and copies the original images into private app storage. It can also receive text or images you deliberately share from another app. It does not scan unselected photos. Original images may retain embedded metadata such as capture time or location.
Daily reminders use notification permission for local notifications. Boot, time, and time-zone change notifications allow reminders to be rescheduled. You can disable reminders or notification permission in app or system settings.
When fingerprint or device unlock is enabled, Android performs authentication. The app receives only the result and does not read or store fingerprints or other biometric data. You can disable this unlock method in the app.
4. Manual backups, imports, and cloud-sync availability
You can manually export a password-encrypted backup or select an existing backup to import. Backups contain diaries, associated images, and portable preferences, excluding app-lock passwords and lockout state. Files are saved to the location you select through the system file picker. If you select cloud storage or a third-party file service, that service handles the file under its own rules. Protect backup files and passwords.
Automatic backup, Google Drive sync, and diary export (PDF, images, Markdown, TXT, and HTML) are not available through the current version's user interface, and the related background backup and sync tasks are disabled. The app currently does not automatically upload diaries to Google Drive through these features. Analytics still operates independently. This policy will be updated if these features become available.
5. Android system backups and device transfers
The app allows Android system backups. Current rules include only the diary database and app-managed diary images in backups or device transfers, excluding preferences, password verification information, lockout state, and caches. Cloud backups require appropriate system encryption capability. Actual backup and transfer behavior depends on Android, your device manufacturer, and system settings.
The operating system or backup provider handles these backups without providing diaries to the developer. You can manage backups in system settings. Diary text uses a device-local Android Keystore key that is not included in these backups, so recovery of encrypted text from system backups or device transfers is not guaranteed. Use the app's manual encrypted backup for migration.
6. Retention, deletion, and your choices
Diaries and settings are stored locally by default. Deleting diaries, including using “Clear diaries,” first moves them to the recycle bin, where they can be restored for 30 days. You can permanently delete entries or empty the bin. Entries older than 30 days are removed when app cleanup runs, along with images no longer referenced by other diaries.
You can view, correct, and delete diaries, clear app data or uninstall to remove local data, and manage notifications, image access, and backups in system settings. Revoking access to an image source does not delete copies already imported into the app. Exported backups and other external files, system cloud backups, and copies on other devices must be managed or deleted separately.
Deleting diaries, clearing app data, or uninstalling does not automatically delete analytics previously sent to Google. This version has no analytics switch; stopping use and uninstalling stops future analytics collection by that installation. Contact the developer using section 10 for access, deletion, or other privacy requests.
7. Security
Android app isolation protects private app data. AES-GCM with Android Keystore encrypts locally stored diary titles, text, and rich text. Other database fields, such as dates, weather, and moods, and original image files are outside this text-encryption scope; this does not mean the entire database or all files are encrypted. Manual backups are separately encrypted with a password.
An optional app password and system authentication control app access. Protect your device, system credentials, app password, backup passwords, and external files. No security measure can guarantee absolute protection.
8. Children
The app does not request age or identity information. Minors should use it with guidance from a parent or guardian and avoid recording or distributing unnecessary sensitive information in diaries, images, or backups.
9. Policy changes
This policy will be updated when app features or data-handling practices change. Review this page's date, applicable version, and content after app updates.
10. Contact
For questions, complaints, or personal-data requests, contact the developer at liuwen.yeah@gmail.com. Do not include complete diaries, passwords, or unnecessary sensitive information in emails. The email address and request you voluntarily provide will be used to handle and respond to your request.