Legal

PrivaLog Privacy Policy

Last updated: August 3, 2026

PrivaLog is a personal, encrypted journal for iPhone, iPad, Mac, and the web. This privacy policy explains which personal data PrivaLog processes, why it is needed, and which rights you have.

1. Who is responsible?

PrivaLog / NextDevStudio is responsible for the processing of personal data within PrivaLog.

For questions about privacy or the use of your personal data, contact:

privacy@nextdevstudio.com

2. What data does PrivaLog process?

Account data

To create and use a PrivaLog account, we process:

  • your email address;
  • an internal account ID;
  • data needed to sign you in and secure your session.

Account registration and authentication are provided through Supabase Auth.

Your account password is separate from your journal passphrase.

Encrypted journal data

Your journal content is encrypted on your device before it is sent to the server for synchronization.

As a result, the server does not receive readable:

  • titles;
  • journal entries;
  • moods;
  • tags;
  • favorites.

The server stores the encrypted content and limited metadata needed for PrivaLog and synchronization to work, such as:

  • the date of a journal entry;
  • the time an entry was created or updated;
  • technical identifiers;
  • information about the encryption version used.

This metadata is not encrypted.

Technical data

When you use PrivaLog, PrivaLog and its technical service providers may process limited technical data, such as:

  • your IP address;
  • the date and time of a request;
  • browser, device, or operating system information;
  • session, server, and security logs;
  • technical error information.

This data is used to keep PrivaLog available and secure and to investigate errors, misuse, and unauthorized access.

It is not used to create advertising profiles.

Subscription data

PrivaLog may offer a trial period, a free plan, and a Pro subscription.

When you use Pro, we process data needed to determine whether you are entitled to Pro features. This may include:

  • an internal user identifier;
  • the App Store product you purchased;
  • the status of your trial or subscription;
  • your current Pro status.

Purchases and payments are handled by Apple. PrivaLog does not receive your full payment card or bank details.

RevenueCat is used to verify and manage your Pro status. The relevant Pro status is also stored in Supabase.

Contact data

When you contact us, we process your email address and the content of your message so that we can respond.

Do not include readable journal content unless it is necessary for your question. Content that you include in an email is not protected by PrivaLog’s journal encryption.

Optional place and weather features

Searching for a place and adding weather to an entry are optional. Nothing happens until you choose those actions on your device.

If you search for a place, your device may send search text or location information to a geocoding service. On the web, that is OpenStreetMap’s Nominatim service. On iPhone, iPad, and Mac, PrivaLog may use Apple MapKit and, with your permission, device location (When In Use) to suggest places or use your current location.

If you add weather, your device fetches current conditions from Open-Meteo using coordinates from the first place on the entry that has them.

PrivaLog’s servers do not receive these search queries or third-party requests directly. Place names and weather you save are stored in your encrypted journal content like other entry text.

3. Why do we process this data?

We process personal data to:

  • create and manage your account;
  • sign you in securely;
  • store and synchronize encrypted journal data;
  • provide Free, trial, and Pro functionality;
  • verify purchases and subscription entitlements;
  • resolve technical problems;
  • protect accounts and systems;
  • prevent misuse and unauthorized access;
  • respond to questions and privacy requests.

The processing of account, synchronization, and subscription data is necessary to provide PrivaLog to you. The legal basis is the performance of our agreement with you.

We process technical and security data on the basis of our legitimate interest in keeping PrivaLog secure, reliable, and available.

In certain situations, we may process data when necessary to comply with a legal obligation.

4. How does PrivaLog protect your journal?

The readable content of your journal is encrypted on your device before it is uploaded to the server.

Your journal passphrase is not sent to the server in readable form. PrivaLog cannot:

  • read your journal content;
  • view your journal passphrase;
  • reset your passphrase;
  • decrypt or recover your encrypted journal for you.

If you forget your passphrase and no longer have access to an unlocked device, PrivaLog cannot recover your journal.

Encryption does not protect against someone who has access to an unlocked device, an open journal, or a readable export.

5. Local storage and biometric unlocking

The PrivaLog apps may store an encrypted local copy of your journal. This allows you to write offline and synchronize later.

On supported Apple devices, you may optionally use Face ID, Touch ID, or your device passcode to unlock PrivaLog. A device-bound key may be stored in Apple Keychain for this purpose.

The biometric check is performed by your device’s operating system. PrivaLog does not receive your face scan, fingerprint, or other biometric data.

6. Free, trial, and Pro

During a trial period, Pro features may be temporarily available.

After the trial ends, you can continue using PrivaLog on the free plan.

On the Free plan, you can continue writing journal entries locally in the native apps. Uploading new or updated journal data to the cloud is blocked.

Without Pro, the web version is largely read-only.

With Pro, cloud storage, synchronization, and other Pro features are available. Your Pro status is determined through Apple and RevenueCat and linked to your PrivaLog account.

7. Exports

PrivaLog may offer two types of exports.

Encrypted export

An encrypted JSON export contains ciphertext and is not a readable copy of your journal.

This export cannot be restored into a new account, even if you use the same email address, account password, and journal passphrase.

Readable export

A readable JSON export contains your journal content as plain text.

Treat this file as a sensitive emergency copy and store it in a secure location.

You choose where an export is saved, for example on your device, in iCloud Drive, or with another storage provider.

PrivaLog does not automatically delete these files when you:

  • sign out;
  • delete the app;
  • delete your account.

You are responsible for securely storing and deleting your export files.

8. Who is data shared with?

We do not sell or rent your personal data.

PrivaLog does not use advertising or third-party analytics trackers for marketing or advertising profiling.

To operate PrivaLog, we use the following service providers:

  • Supabase for accounts, authentication, database storage, and synchronization;
  • Vercel for hosting the website and web app;
  • RevenueCat for verifying and managing Pro entitlements;
  • Apple for App Store purchases, payments, and subscription management.

These service providers receive only the data needed to perform their services.

Supabase, Vercel, and RevenueCat do not receive readable journal content through PrivaLog.

Apple processes App Store purchases and payments under its own privacy policy.

When you optionally use place search or weather, your device contacts third-party services directly from the app or website. Those requests are not routed through PrivaLog’s servers. See section 2 for details.

We may disclose data when required by law or when necessary to investigate fraud, misuse, or a serious security incident.

Because PrivaLog cannot decrypt your journal content, we cannot provide readable journal content that is stored on the server only in encrypted form.

9. Processing outside the European Economic Area

Some service providers may process or store data in countries outside the European Economic Area.

Where this happens, appropriate legal and technical safeguards are used. These may include:

  • an adequacy decision by the European Commission;
  • the EU–US Data Privacy Framework, where the relevant US organization is validly certified;
  • the European Commission’s Standard Contractual Clauses.

Client-side encryption ensures that service providers do not receive readable journal content. They may still process limited account data, metadata, subscription data, or technical logs.

You can request more information about the safeguards used by contacting privacy@nextdevstudio.com.

10. How long do we keep data?

Your account data, Pro status, metadata, and encrypted journal data are kept for as long as your account remains active.

When you delete your account, the associated data is removed from PrivaLog’s active systems.

Deleted data may remain temporarily in secure technical backups until those backups are overwritten as part of the normal backup cycle.

Technical and security logs are kept only for as long as needed for security, troubleshooting, and preventing misuse.

Support messages are kept for as long as reasonably necessary to handle your question, any follow-up questions, or a dispute.

Data may be kept for longer where necessary to comply with a legal obligation, investigate a security incident, or establish, exercise, or defend a legal claim.

Export files created by you are not deleted automatically. You must delete them yourself.

11. Deleting your account

You can permanently delete your PrivaLog account through the account settings in PrivaLog.

When you delete your account:

  • your account and related server data are deleted;
  • PrivaLog cannot restore your account or journal;
  • data may remain temporarily in secure technical backups;
  • local exports and other files saved by you remain until you delete them yourself.

An encrypted export cannot be restored into a new account.

Deleting your PrivaLog account does not automatically cancel an active Apple subscription. You can manage your subscription separately through your Apple account subscription settings.

12. Your privacy rights

Where the GDPR applies, you may have the right to:

  • access your personal data;
  • correct inaccurate personal data;
  • have personal data deleted;
  • restrict processing;
  • data portability;
  • object to processing based on a legitimate interest.

You can exercise these rights by contacting privacy@nextdevstudio.com.

We may ask you to confirm that the request relates to your account. We normally respond within one month.

Because PrivaLog cannot decrypt your journal content, the readable content cannot be viewed or corrected on your behalf. You can view, edit, delete, and export your journal content yourself after unlocking your journal.

If you are not satisfied with how your personal data has been handled, you may lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. You do not need to contact PrivaLog first.

13. Children

PrivaLog is not intended for children under the age of 16.

If you believe that a child under 16 is using an account without valid permission, contact privacy@nextdevstudio.com.

We will investigate the report and delete data where appropriate.

14. Security

We take appropriate technical and organizational measures to protect personal data.

These measures include:

  • client-side encryption of journal content;
  • secure network connections;
  • separation of data by user account;
  • secure authentication;
  • restricted access to technical systems;
  • secure local key storage.

No digital service can guarantee absolute security.

You should also use a strong device passcode, secure your email account, and store your journal passphrase and exports safely.

15. Changes to this policy

This privacy policy may be updated when PrivaLog, its service providers, or the applicable rules change.

The date at the top shows when the policy was last updated.

Where reasonably possible, we will inform users about significant changes through the app, website, or email.

16. Contact

For questions, privacy requests, or complaints, contact:

Back to sign in