Skip to content

Privacy Policy

Daylum has no account and no server. Your journal stays in app-private storage on your device, and the developer collects nothing about you.

Applies to
The Daylum app for iOS and Android, version 1.0.0 and later (com.ronelabs.daylum), and this website.
Effective
Last updated

Who we are#

Daylum is an independent app made by one developer, trading as RONE Labs. RONE Labs is the data controller for this policy, and is the same entity that appears as the app’s publisher on the App Store and on Google Play.

There is no company behind the app and no Daylum server. Nobody is holding your journal on your behalf, because there is nowhere for it to be held. The one route to a human is ronelabs26@gmail.com.

No account, no login#

You do not sign up and you do not sign in.

Daylum never asks for an email address, a password, or a phone number, and there is no account to create. No login is a deliberate privacy choice, not a missing feature.

Because there is no account, there is no user record anywhere to look up, to hand over, or to breach. There is no “your Daylum profile” to request, because one was never created.

Where your journal lives#

Your journal is saved in app-private storage on your device, and it stays there.

Everything you put into Daylum is written to a local database and an app-private media folder on the device you are using:

Daylum works fully offline. It needs no network connection to write, read, or search your journal, and your journal is never uploaded to a server or synced to the cloud.

Photos are copied, not linked. When you attach a photo, Daylum writes its own copy into app-private storage instead of pointing at your photo library. That copy is not visible in your gallery and is not synced to any photo cloud service.

What “app-private” means. The storage belongs to the app alone: other apps on the device cannot read it, and removing Daylum removes it. It is the operating system’s own sandbox, not a Daylum invention.

A backup you export yourself is a different thing, and it leaves this protection behind. That is covered in the backups section below.

What Daylum collects: nothing#

The app gathers nothing about you and sends nothing off your device.

Concretely, Daylum ships with none of the following:

If diagnostic information is ever exported, it is something you start, and it excludes journal content by default.

There are two exceptions, and neither is the app reading your journal. Buying Daylum Plus is a transaction Apple or Google runs, under their policies. And this website is a web page, which means a web server receives the request that serves it to you. Neither one involves your entries.

Permissions the app asks for, and why#

Every permission Daylum asks for is used on your device, for the thing you just asked it to do.

Daylum asks for a permission at the moment the feature needs it, not on first launch, and declining one disables that feature rather than the app.

PermissionWhen it is askedWhat it is used for
NotificationsOnce, when you turn on your first reminder.Scheduling local reminder notifications on this device. No reminder data leaves the device.
Photo library (iOS)When you attach a photo to an entry.Choosing a photo for Daylum to copy into the entry. On Android this goes through the system photo picker, which needs no permission.
Save to photo libraryWhen you save an image the app generated.Writing that one image back to your library, at your request. On Android this is only needed on API 29 and lower.
Camera (iOS)When you take a photo for an entry.Capturing a photo to attach, which Daylum copies into app-private storage. Android uses the system camera activity and declares no camera permission.
Face ID and biometricsWhen you turn on app lock with biometric unlock.Unlocking the app on this device. The check is performed by the operating system, and Daylum never receives your biometric data.
Run at boot (Android)Never prompted. Granted at install.Re-arming your local reminders after the device restarts, so a reminder is not silently lost.
Vibration (Android)Never prompted.Haptic feedback on taps, which follows your Haptics setting.
Billing (Android)Never prompted.Letting Google Play process a Daylum Plus purchase. See the Daylum Plus section below.

App lock and on-device security#

App lock is optional, and it runs entirely on your device.

You can turn it on in Privacy & Security, set a PIN, choose whether to unlock with your biometrics or your PIN, and pick how soon the app relocks after you leave it.

Your PIN is not stored. Daylum keeps only a secured verifier in your device’s secure storage, never the PIN itself, and your unlock secret is never sent anywhere. A biometric check is performed by the operating system; Daylum receives the yes or no and never your biometric data.

Your journal database and photo copies are protected by the operating system’s app sandbox and by whatever device passcode or device encryption you have enabled. Daylum does not separately encrypt the database at rest.

Daylum Plus and purchase data#

Daylum is free to download. Daylum Plus is one optional one-time purchase, and the payment is handled entirely by Apple or Google.

There is no subscription, there are no ads, and there is still no Daylum account. Buying Plus does not create one.

The payment never happens inside Daylum. It happens in the App Store or Google Play sheet, under that store’s own payment terms and privacy policy. Daylum receives only the result: an entitlement saying this device owns Plus. It never receives and never stores your card number, your billing address, your Apple Account, or your Google Account.

What that entitlement is, and is not:

Restoring a purchase asks the App Store or Google Play whether your store account owns the product. It does not contact a Daylum server, because there is no Daylum server.

Refunds and receipts are handled by the store that took the payment, not by the developer. Apple documents its process at Apple Support, and Google at Google Play Help.

Backups, exports, and imports#

You can export a complete backup of your journal at any time, and restore from one later.

Both controls are in the Data section of Settings. The full backup, the restore, and a basic CSV export of your entries are free, and they stay free. Getting your data out of Daylum is never a paid feature.

Importing checks the file before it changes anything. Daylum reads and validates a backup, shows you what it contains, and only then writes. A malformed file is rejected rather than half restored.

Daylum Plus adds two conveniences here, and neither replaces the free path. You can produce a password-protected (encrypted) backup instead of a plain one, and you can schedule automatic backups to a folder you pick on your own device. Restoring an encrypted backup is free, so a file made with Plus is never a file you need Plus to read. There is no cloud and no server on either path.

Once a backup leaves the app, it is an ordinary file. It sits wherever you saved it or sent it, it is no longer protected by the app sandbox, and Daylum cannot reach it, protect it, or delete it for you. Keeping an exported backup somewhere you trust is your call, and it is the single most likely way a journal ends up somewhere you did not intend.

Deleting your data#

Delete everything is in Settings, under Data, and it is immediate.

It erases the journal content on the device and resets the app to its defaults. Uninstalling Daylum removes its app-private storage as well, including the database and the photo copies attached to your entries.

There is no server copy, so there is nothing to request the deletion of. There is no form to fill in and no waiting period, because there is nowhere else your journal has ever been.

What deletion does not reach: backups you have already exported and saved somewhere else. Those files are yours, and they are outside the app’s reach. Deleting them is something only you can do.

Your rights, and what they mean with no server#

There is no remote copy of your journal, so most data rights have nothing to be exercised against. Here is the local equivalent of each.

Legal basis. The developer does not collect or process personal data from app users. Where no personal data is processed, the usual lawful-basis analysis has nothing to attach to.

California residents. Daylum does not collect personal information from app users, does not sell or share personal information, and does not use it for cross-context behavioral advertising. There are no categories of personal information collected, sold, or shared to enumerate.

Complaints. Write to ronelabs26@gmail.com first. If you are in the EU or the UK, you may also complain to your local supervisory authority.

Nothing here asserts compliance with any particular regulation, and none of it is legal advice.

What this website loads#

This page loads nothing from any other site, and stores nothing in your browser.

Hosting. The site is hosted on Vercel. Like any web host, Vercel’s network receives the request needed to serve you a page, including your IP address and browser user agent, and may keep operational logs under its own policies. Vercel Web Analytics and Vercel Speed Insights are not enabled on this site.

If a page here ever loads something else from elsewhere, you will find it named here, with the origin it comes from, from the day it starts loading.

Children#

Daylum is not directed to children and is not designed as a children’s product.

Because the app collects no personal information from anyone, there is no children’s data held or processed by the developer.

If you are a parent or guardian with a question, write to ronelabs26@gmail.com.

If AI is ever added#

Daylum has no AI today.

If AI is ever added, it will be optional and off by default. You will see exactly what leaves your device, and you will have to agree first. Nothing is sent without your okay.

That paragraph describes what would happen if AI is added. It is not a description of anything Daylum does now.

Changes to this policy#

The effective date and last-updated date at the top of this page are the record.

If anything on this page stops being true, the page is updated to match. That is the same commitment the app makes on its in-app privacy screen, and it runs in both directions: when the app’s privacy behavior changes, this page changes with it, not later.

Because there is no account and no mailing list, there is no way to notify you individually. This page is where changes are announced, and the material ones are listed below with dates.

  1. The website section now names the content delivery network that serves the icons on the landing page, and the address details that reach it. Nothing about the app changed.
  2. First publication. This is the initial version of the hosted policy, derived from the privacy stance already shipping inside the app.

Contact#

Privacy questions, data questions, and complaints go to ronelabs26@gmail.com.

It is a real mailbox read by the developer, and it is the only contact route for anything in this policy. Nothing you write there is public.