Legal
Last updated: August 3, 2026
PrivaLog is a personal, encrypted journal for iPhone, iPad, Mac, and the web. This privacy policy explains which personal data PrivaLog processes, why it is needed, and which rights you have.
PrivaLog / NextDevStudio is responsible for the processing of personal data within PrivaLog.
For questions about privacy or the use of your personal data, contact:
To create and use a PrivaLog account, we process:
Account registration and authentication are provided through Supabase Auth.
Your account password is separate from your journal passphrase.
Your journal content is encrypted on your device before it is sent to the server for synchronization.
As a result, the server does not receive readable:
The server stores the encrypted content and limited metadata needed for PrivaLog and synchronization to work, such as:
This metadata is not encrypted.
When you use PrivaLog, PrivaLog and its technical service providers may process limited technical data, such as:
This data is used to keep PrivaLog available and secure and to investigate errors, misuse, and unauthorized access.
It is not used to create advertising profiles.
PrivaLog may offer a trial period, a free plan, and a Pro subscription.
When you use Pro, we process data needed to determine whether you are entitled to Pro features. This may include:
Purchases and payments are handled by Apple. PrivaLog does not receive your full payment card or bank details.
RevenueCat is used to verify and manage your Pro status. The relevant Pro status is also stored in Supabase.
When you contact us, we process your email address and the content of your message so that we can respond.
Do not include readable journal content unless it is necessary for your question. Content that you include in an email is not protected by PrivaLog’s journal encryption.
Searching for a place and adding weather to an entry are optional. Nothing happens until you choose those actions on your device.
If you search for a place, your device may send search text or location information to a geocoding service. On the web, that is OpenStreetMap’s Nominatim service. On iPhone, iPad, and Mac, PrivaLog may use Apple MapKit and, with your permission, device location (When In Use) to suggest places or use your current location.
If you add weather, your device fetches current conditions from Open-Meteo using coordinates from the first place on the entry that has them.
PrivaLog’s servers do not receive these search queries or third-party requests directly. Place names and weather you save are stored in your encrypted journal content like other entry text.
We process personal data to:
The processing of account, synchronization, and subscription data is necessary to provide PrivaLog to you. The legal basis is the performance of our agreement with you.
We process technical and security data on the basis of our legitimate interest in keeping PrivaLog secure, reliable, and available.
In certain situations, we may process data when necessary to comply with a legal obligation.
The readable content of your journal is encrypted on your device before it is uploaded to the server.
Your journal passphrase is not sent to the server in readable form. PrivaLog cannot:
If you forget your passphrase and no longer have access to an unlocked device, PrivaLog cannot recover your journal.
Encryption does not protect against someone who has access to an unlocked device, an open journal, or a readable export.
The PrivaLog apps may store an encrypted local copy of your journal. This allows you to write offline and synchronize later.
On supported Apple devices, you may optionally use Face ID, Touch ID, or your device passcode to unlock PrivaLog. A device-bound key may be stored in Apple Keychain for this purpose.
The biometric check is performed by your device’s operating system. PrivaLog does not receive your face scan, fingerprint, or other biometric data.
During a trial period, Pro features may be temporarily available.
After the trial ends, you can continue using PrivaLog on the free plan.
On the Free plan, you can continue writing journal entries locally in the native apps. Uploading new or updated journal data to the cloud is blocked.
Without Pro, the web version is largely read-only.
With Pro, cloud storage, synchronization, and other Pro features are available. Your Pro status is determined through Apple and RevenueCat and linked to your PrivaLog account.
PrivaLog may offer two types of exports.
An encrypted JSON export contains ciphertext and is not a readable copy of your journal.
This export cannot be restored into a new account, even if you use the same email address, account password, and journal passphrase.
A readable JSON export contains your journal content as plain text.
Treat this file as a sensitive emergency copy and store it in a secure location.
You choose where an export is saved, for example on your device, in iCloud Drive, or with another storage provider.
PrivaLog does not automatically delete these files when you:
You are responsible for securely storing and deleting your export files.
We do not sell or rent your personal data.
PrivaLog does not use advertising or third-party analytics trackers for marketing or advertising profiling.
To operate PrivaLog, we use the following service providers:
These service providers receive only the data needed to perform their services.
Supabase, Vercel, and RevenueCat do not receive readable journal content through PrivaLog.
Apple processes App Store purchases and payments under its own privacy policy.
When you optionally use place search or weather, your device contacts third-party services directly from the app or website. Those requests are not routed through PrivaLog’s servers. See section 2 for details.
We may disclose data when required by law or when necessary to investigate fraud, misuse, or a serious security incident.
Because PrivaLog cannot decrypt your journal content, we cannot provide readable journal content that is stored on the server only in encrypted form.
Some service providers may process or store data in countries outside the European Economic Area.
Where this happens, appropriate legal and technical safeguards are used. These may include:
Client-side encryption ensures that service providers do not receive readable journal content. They may still process limited account data, metadata, subscription data, or technical logs.
You can request more information about the safeguards used by contacting privacy@nextdevstudio.com.
Your account data, Pro status, metadata, and encrypted journal data are kept for as long as your account remains active.
When you delete your account, the associated data is removed from PrivaLog’s active systems.
Deleted data may remain temporarily in secure technical backups until those backups are overwritten as part of the normal backup cycle.
Technical and security logs are kept only for as long as needed for security, troubleshooting, and preventing misuse.
Support messages are kept for as long as reasonably necessary to handle your question, any follow-up questions, or a dispute.
Data may be kept for longer where necessary to comply with a legal obligation, investigate a security incident, or establish, exercise, or defend a legal claim.
Export files created by you are not deleted automatically. You must delete them yourself.
You can permanently delete your PrivaLog account through the account settings in PrivaLog.
When you delete your account:
An encrypted export cannot be restored into a new account.
Deleting your PrivaLog account does not automatically cancel an active Apple subscription. You can manage your subscription separately through your Apple account subscription settings.
Where the GDPR applies, you may have the right to:
You can exercise these rights by contacting privacy@nextdevstudio.com.
We may ask you to confirm that the request relates to your account. We normally respond within one month.
Because PrivaLog cannot decrypt your journal content, the readable content cannot be viewed or corrected on your behalf. You can view, edit, delete, and export your journal content yourself after unlocking your journal.
If you are not satisfied with how your personal data has been handled, you may lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. You do not need to contact PrivaLog first.
PrivaLog is not intended for children under the age of 16.
If you believe that a child under 16 is using an account without valid permission, contact privacy@nextdevstudio.com.
We will investigate the report and delete data where appropriate.
We take appropriate technical and organizational measures to protect personal data.
These measures include:
No digital service can guarantee absolute security.
You should also use a strong device passcode, secure your email account, and store your journal passphrase and exports safely.
This privacy policy may be updated when PrivaLog, its service providers, or the applicable rules change.
The date at the top shows when the policy was last updated.
Where reasonably possible, we will inform users about significant changes through the app, website, or email.
For questions, privacy requests, or complaints, contact: