Diurnal Privacy Policy
Version: 1.0
Effective date: September 8, 2026
Last updated: September 11, 2026
Diurnal is built around a simple principle: your journal belongs to you. The Diurnal Android application stores journal content on your device by default. If you choose cloud features, Diurnal sends that content directly to an application-specific area of your Google Drive. Shylder LLC does not operate a journal-content server and does not receive journal content through ordinary journaling or Drive sync. Information you choose to send to support is handled separately below.
This Privacy Policy explains how Shylder LLC (“Shylder,” “we,” “us,” or “our”) handles information when you use the Diurnal Android application and its related Android features (collectively, “Diurnal” or the “Services”).
Privacy at a Glance
This summary is for convenience. The full policy below controls.
- Your journal is private by design. Ordinary journaling and Drive sync do not send journal content to Shylder. You control content you separately send to support.
- Diurnal is local-first. The Android journal database and pending widget entries are encrypted on your device.
- Google Drive is optional. If enabled, entries, media, and drafts go directly between Diurnal and your private Google Drive app-data area. Current Drive backups are not additionally encrypted by Diurnal.
- The Android app does not show advertising. Diurnal does not request ads, and no advertising SDK collects information about your use of the app.
- Feedback and crash reports are optional. They are sent only when you choose to send them and are scheduled for deletion after 180 days.
- We do not sell your journal or use it for advertising, profiling, or training artificial-intelligence models.
- Diurnal does not monitor your writing. It is not an emergency, medical, or crisis-monitoring service.
1. Who We Are and What This Policy Covers
Shylder LLC is a New Mexico limited liability company based in Albuquerque, New Mexico, United States. Shylder is responsible for the information it collects through Diurnal, such as feedback, crash reports, and support communications.
This policy covers Diurnal only. It does not control the independent privacy practices of Google, your Android device manufacturer, your mobile carrier, or other third-party services you choose to use with Diurnal.
Diurnal does not require you to create an account with Shylder. Connecting a Google account for backup or sync does not create a Shylder-hosted account.
2. Information That Stays on Your Android Device
The following information is stored locally by default and is not transmitted to Shylder:
- journal titles and entry text;
- photos, videos, audio recordings, PDFs, drawings, and other attachments;
- dates, times, moods, tags, favorites, notebooks, statistics, and search information;
- precise coordinates and place names you choose to save;
- drafts, hidden-entry settings, time-lock dates, and time-lock messages;
- your local profile name or profile image;
- app preferences, language, notification settings, security settings, and sync metadata;
- your app passcode record and database encryption material protected through Android security facilities; and
- quick notes captured by the Android home-screen widget while they are waiting to be imported into your journal.
The main journal database is encrypted at rest on your Android device, and its key is protected using Android's secure keystore facilities. Pending widget notes are encrypted separately on your device. Attachments, previews, temporary files, and local crash records are stored outside the journal database and rely on Android app isolation and device protections; they are not all encrypted using the journal database key.
Android biometric information, such as a fingerprint or face template, is handled by Android and your device's biometric system. Diurnal receives only the result of the authentication attempt; Shylder does not receive or store your biometric template.
Diurnal does not track your location in the background and does not automatically upload journal content or sensor information to Shylder.
3. Information Stored in Your Google Drive
Google Drive backup and sync are optional. If you enable them, Diurnal requests access to the hidden appDataFolder area of your Google Drive. This permission is designed to let Diurnal create and manage only its own application data; it does not give Diurnal general access to your ordinary Google Drive documents.
Depending on the features you use, the Diurnal app-data area may contain:
- journal entries, notebooks, timestamps, deletion markers, and attachment metadata;
- supported photos, video, audio, PDFs, thumbnails, and other synced media;
- device and synchronization identifiers needed to coordinate backups across devices.
The Android app communicates directly with Google Drive. Shylder does not receive a copy of these files, does not possess your Drive access token, and cannot browse or retrieve your journal content from its own systems.
Drive encryption
The Android database is encrypted on your device, but Diurnal's current Google Drive backup files are not additionally encrypted by Diurnal. They are protected by your Google account and Google's security controls. Keep your Google account secure and use an independent export or backup if appropriate for you.
Google API Limited Use
Diurnal uses Google user data only to provide user-visible sign-in, backup, synchronization, and recovery features. Diurnal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google API data is not used for advertising, credit decisions, data brokerage, surveillance, or training generalized artificial-intelligence or machine-learning models.
4. Google Account Information and Authentication
When you connect Google Drive in the Android app, Diurnal may receive your Google account identifier, email address, display name, and profile image from Google. This information is stored locally on your device so Diurnal can show the connected account, prevent accidental account mixing, and associate sync data with the correct Google account. Disconnecting removes the displayed Google profile and signs out the device, but retains the last synced Google account identifier to prevent mixing journals with another account. Existing journal and sync records may also contain that identifier. Clearing the relevant local app data removes those local records. Disconnecting does not revoke account-wide Google authorization or delete Drive backups; use Google Account access controls and cloud-deletion controls separately.
5. Scope of This Android Policy
This policy describes the Android app. Separate writing utilities and websites are not a browser version of Diurnal and are not covered here. Review the privacy notice supplied with any separate service you use.
6. Location Information
Location features are optional and operate only after you use a location action or enable the relevant user-controlled setting.
The Android app may request coarse or precise location permission to obtain your current coordinates. Coordinates and the resulting place name are saved locally with the journal entry and, if you enable sync, in your Google Drive backup. Diurnal may pass coordinates or a place-search query to Android's native geocoding provider to obtain a readable place name. Google Maps may receive your IP address, device or app information, map requests, map area, and interactions under Google's policies. Shylder does not receive this location information through these features. Google Maps features and content are subject to the Google Maps End User Additional Terms of Service and Google Privacy Policy.
7. Camera, Files, Microphone, Speech, Notifications, and Other Permissions
Diurnal may request Android permissions only when needed for a feature:
- Camera and media: to capture or select photos and videos you choose to attach.
- Microphone for voice notes: to record audio after you start recording.
- Microphone and speech recognition: to convert speech to text after you start dictation. Android's configured speech-recognition provider may receive temporary audio and related technical data. Shylder does not receive that audio.
- Files and storage: to import files you select, store attachments, create exports, or restore backups.
- Notifications: to schedule journaling reminders and time-lock notifications locally on your device.
- Location: as described in Section 6.
- Biometrics or device credentials: to ask Android to authenticate you before opening protected parts of Diurnal.
- Network and foreground-service access: to complete user-requested backup, restore, import, export, map, purchase, reporting, and other network operations reliably.
You can manage these permissions in Android settings. Disabling a permission may prevent the associated feature from working.
8. Google Play Purchases
Diurnal Subscription purchases are processed by Google Play. Google, not Shylder, collects and processes your payment method and full billing details. Diurnal receives or reads purchase-product information, localized price information, and subscription-entitlement or receipt status needed to start a purchase, restore a purchase, and unlock subscription features. Diurnal stores subscription status and the last successful verification time locally. It also performs local installation and release-signature checks to protect access to paid features.
Google handles purchase information under the Google Privacy Policy and Google Play terms. Shylder may receive transaction and payout records from Google as necessary for accounting, fraud prevention, refunds, tax, and legal compliance.
9. Optional Feedback, Crash Reports, and Support
Diurnal does not use Google Analytics, Firebase Analytics, Facebook SDKs, or similar third-party marketing analytics to monitor your journaling activity.
Feedback and crash reports are sent to Shylder only after you choose Send. Reports include an eight-character portion of a randomly generated Diurnal installation identifier to help group reports from the same installation. This is not your advertising ID or a hardware serial number. Diurnal does not deliberately add your name, email, Google account profile, or journal files. Feedback can contain information you type, and diagnostics may contain incidental information, so we do not promise every report is anonymous.
Feedback reports
Feedback reports contain:
- the server-recorded receipt time;
- the category and message you enter;
- operating system;
- app version;
- truncated eight-character device identifier; and
- language.
Crash reports
Crash reports may contain:
- the server-recorded receipt time and client-recorded crash time;
- whether the report concerns a JavaScript or native crash;
- the crash category;
- error message and a length-limited stack trace;
- current app path or an indication that the crash occurred in a previous session;
- operating system, app version, language, and user-agent string; and
- truncated eight-character device identifier.
Diurnal does not intentionally attach journal entries or media to reports. Error text, stack traces, and app paths may contain incidental information. Crash reports have no free-text message field. Avoid adding personal information or journal content to the separate feedback form. Native crash information may be recorded locally before the next launch; sending remains optional. The pending record is cleared after dismissal or successful sending and may be replaced by a later crash. The server retention period below does not set an expiry for a pending local record.
Reports are sent through Google-hosted reporting infrastructure and stored in Google Drive for troubleshooting and support. We restrict access to authorized personnel and providers who need it for those purposes. Sending a report does not give Shylder access to your device journal or Drive journal backup.
Report rows are scheduled for deletion after 180 days based on the server-recorded receipt time. An automated time-driven process performs deletion, so removal may occur later if that process is delayed or fails. Limited residual copies may also remain temporarily in provider backups or where retention is required for security, legal, or dispute purposes.
If you contact [email protected], we receive the email address, message, attachments, and technical or account information you choose to provide. We use support communications to respond, troubleshoot, prevent abuse, improve Diurnal, and maintain reasonable business records.
10. Imports, Exports, Sharing, and Links
Diurnal processes imported files on your device. Shylder does not receive them. Imported files may contain personal information from another service, and you are responsible for having the right to import and use that information.
When you export or share an entry, backup, PDF, media file, or other content, you choose the destination. The receiving application, person, storage provider, or website handles that copy under its own privacy practices. Exported content may be unencrypted.
Some HTML export templates reference Google Fonts. If you open one of those exports while connected to the internet, your browser may request font files from Google and transmit information such as your IP address, browser information, and the requested font resource. The journal text itself is contained in the export and is not intentionally included in that font request.
Links you place in journal entries or open from Diurnal may take you to third-party sites. This policy does not cover those sites.
11. How We Use Information Shylder Receives
Shylder uses the limited information it actually receives to:
- respond to feedback, support requests, and privacy inquiries;
- diagnose crashes and improve performance, reliability, accessibility, and security;
- prevent spam, fraud, misuse, and security incidents;
- administer subscriptions, refunds, accounting, and tax records;
- enforce the Terms of Use and protect users, Shylder, and others; and
- comply with applicable law, valid legal process, and regulatory obligations.
Shylder does not use journal content for advertising, user profiling, data brokerage, surveillance, or training generalized artificial-intelligence models. Shylder cannot use or disclose journal content it does not possess.
12. Legal Bases for Processing
Where EU or UK data-protection law applies, the legal basis depends on the processing purpose, not simply on where a file is stored:
- Contract: processing necessary to provide journaling, requested backup and sync, paid access, and purchase-related assistance under our agreement with you.
- Consent: sending optional feedback or crash reports. Declining reports does not prevent journaling. Withdraw consent through the relevant control or by contacting us; withdrawal does not invalidate earlier lawful processing. Android permissions and Google authorization provide additional feature controls and are not automatically the legal basis for every use of information.
- Legitimate interests: responding to general support inquiries, protecting the app and reporting service from abuse, and maintaining necessary security and dispute records, after considering the effect on your rights. You may object to processing based on legitimate interests.
- Legal obligations: required accounting, tax, regulatory, and legal-process records.
Journal content can include sensitive information. Shylder does not routinely receive or analyze it. If you ask us to handle sensitive information for support, we will identify an applicable legal basis and any additional consent or condition required before using it. Google and other providers may act as independent controllers for their own services under their privacy notices.
13. When Information Is Disclosed
Shylder may disclose information it possesses only in these circumstances:
- Service providers: Google for feedback/crash storage and related infrastructure, email or support providers used to answer messages, and professional advisers or vendors needed to operate Shylder, subject to appropriate duties.
- At your direction: when you intentionally send, export, or share information.
- Legal and safety reasons: when Shylder reasonably believes disclosure is required by valid law, subpoena, court order, or other enforceable legal process, or is necessary to protect rights, security, and safety.
- Business transaction: in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this policy and applicable law.
- With consent: for another purpose you clearly authorize.
Google, Android service providers, and other third parties receive information directly as described in this policy. Their receipt is governed by their own terms and privacy policies.
Shylder does not exchange personal information for monetary payment. Some privacy laws define sale or sharing more broadly, including certain advertising disclosures without payment. Shylder does not disclose journal content to advertisers and does not knowingly sell or share personal information about anyone under 16 for cross-context behavioral advertising.
14. Retention and Deletion
Retention depends on where information is stored:
- Android journal data: remains on your device until you delete it, clear the app's storage, or uninstall Diurnal. Entries placed in Trash remain recoverable until permanently deleted. In the current version, permanent purge clears the entry title, body, attachment references, time-lock date and message, mood, location, tags, notebook assignment, and derived content fields; a non-recoverable deletion record can retain its identifiers, dates, status flags, and other metadata used for synchronization. Deleted notebook records do not retain their former names. These records can be included in later Drive backups. Ordinary deletion records become eligible for removal after 30 days and are removed on a subsequent database startup; the reserved welcome-entry marker is retained to prevent the sample from reappearing. These records are not recoverable entries in the app.
- Widget quick notes: remain in the encrypted on-device widget outbox until imported, individually removed after successful import, explicitly cleared in Settings, or erased with app data.
- Google account information on Android: the displayed profile is removed on disconnect; the account-boundary identifier and identifiers in existing journal or sync records remain until the relevant local app data is cleared, as explained in Section 4.
- Google Drive data: remains in your Google account until Diurnal or you delete it, subject to Google's retention and backup practices. Uninstalling Diurnal does not delete Drive data. Use Diurnal's Clear Cloud Backup or Delete Everything feature, or manage connected-app data through your Google account.
- Feedback and crash reports: are scheduled for deletion after 180 days as described in Section 9.
- Support and business records: are kept only as long as reasonably necessary for support, security, accounting, tax, legal, or dispute purposes.
Deletion may not immediately remove limited copies held in provider backups, transaction records, security logs, or records we must retain by law.
15. Your Choices and Privacy Rights
Diurnal gives you direct control over most information because it is stored on your device or in your Google account:
- edit or delete entries and attachments in the app;
- export your journal in supported formats;
- clear pending widget notes;
- wipe local data;
- disconnect Google Drive;
- clear the cloud backup or delete local and cloud data through Settings → Delete Data;
- revoke Diurnal's Google access through your Google Account;
- decline or revoke Android permissions;
- cancel Diurnal Subscription through Google Play; and
- uninstall Diurnal to stop app operation and erase its local app data.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or a copy of personal information Shylder controls; to object to or opt out of certain processing; to withdraw consent; and to appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
Email requests to [email protected]. We may need information reasonably necessary to verify and locate the relevant record. Because Diurnal has no Shylder user account and Shylder cannot access your device or Drive journal, we generally cannot retrieve, correct, export, or delete that content for you. Use the app and Google controls described above. For a feedback or crash report, the truncated device identifier and approximate submission time may help locate a record, but they may not be sufficient to verify that a report belongs to you. We will explain if we cannot safely identify or act on a requested record.
An authorized agent may submit a request where applicable law permits. We may ask for proof of authority and identity. If you believe a request was improperly denied, reply to our decision and state that you wish to appeal.
Residents of the EEA, United Kingdom, or Switzerland may complain to their local data-protection authority. EEA authority contacts are available from the European Data Protection Board; UK residents may contact the Information Commissioner's Office; and Swiss residents may contact the Federal Data Protection and Information Commissioner.
16. Security
Diurnal uses safeguards appropriate to its local-first design, including encrypted journal and widget storage, Android-protected keys, encrypted connections for supported network requests, and limited Google Drive permissions. These safeguards do not make every separate file encrypted by Diurnal; see Sections 2 and 3.
No safeguard is perfect. Device compromise, weak device credentials, malicious software, exported files, Google-account compromise, provider incidents, user error, or software defects may expose or destroy information. Drive backups are not additionally encrypted by Diurnal. Keep Android and Diurnal updated, secure your Google account, protect recovery information, and maintain an independent export or backup appropriate to the importance of your journal.
17. Children's Privacy
Diurnal is not directed to children under 13, and children under 13 may not use it. We do not knowingly collect personal information from a child under 13. If you believe a child under 13 sent personal information to Shylder, contact [email protected], and we will take appropriate steps to delete it.
A higher minimum age applies where local law requires it. Permission to use the app, capacity to enter its terms, and capacity to consent to data processing can have different thresholds. Where legally required, a parent or guardian must authorize use or the relevant processing; accepting this policy alone does not supply that authorization. Parents and guardians should understand that Shylder cannot monitor or retrieve locally stored or Google Drive journal content.
18. International Processing
Shylder is located in the United States. Google and other providers may process information in the United States, the European Economic Area, the United Kingdom, and other countries where they or their service providers operate. Those countries may have different data-protection laws from your home country.
For transfers subject to EU or UK restrictions, we must use an applicable adequacy decision or appropriate safeguards, such as European Commission standard contractual clauses and the UK addendum or equivalent UK agreement, as applicable. Contact us for information about the safeguard applicable to information we hold about you or to request a copy, subject to necessary redactions. This policy is not consent to an otherwise restricted transfer. Journal content stored in your Google Drive is transferred and stored according to your relationship with Google and your Google-account settings.
19. Changes to This Policy
We may update this Privacy Policy to reflect changes in Diurnal, providers, or law. We will publish the revised policy at the location linked from Diurnal and update the “Last updated” date. Where reasonably practicable, we may also describe material changes in Google Play release notes, an app update, or a Diurnal webpage.
Because Diurnal does not maintain Shylder user accounts or a user email list, we may not be able to provide individualized notice. If applicable law requires advance notice or consent, a new use of information will not apply to you until we provide that notice or obtain consent through an available, legally sufficient method.
20. Contact Us
For privacy questions, requests, complaints, or security concerns, contact:
Shylder LLC
Albuquerque, New Mexico, United States
Email: [email protected]
Do not email journal entries, passcodes, recovery keys, security answers, government identification, health information, or other sensitive content unless it is necessary and we specifically request a secure method.