Privacy Policy for Dear Us Daily Journal

Effective Date: August 19, 2026

Dear Us Daily Journal ("Dear Us," "we," "us," or "our") is a private daily journal app for couples. This Privacy Policy explains what information is processed when you use Dear Us, how it is used, when it is shared, and the choices available to you.

Syncing Options

Dear Us offers two separate ways to pair and sync:

These are separate journals. Selecting one as your default does not delete or disconnect the other.

Information We Collect and Process

Google account information. If you choose cross-platform pairing, Google Sign-In and Firebase Authentication process your Google account identifier, email address, display name, profile photo URL if available, authentication tokens, IP address, and technical information such as user-agent data. We store your Firebase user ID, email address, display name, and profile photo URL in your Firebase profile to provide account and pairing features.

iCloud information. If you choose iCloud pairing, Apple iCloud and CloudKit process the identifiers and records needed to store your journal and connect it with your partner. Apple processes this information under its own privacy terms.

Journal content. Dear Us processes the text, dates, and photos you choose to add to your journal. In the Google/Firebase journal, note text and attached photos are encrypted on your device before being uploaded to Cloud Firestore. Firebase stores the encrypted content.

Journal metadata needed to operate the service—including entry identifiers, dates, update timestamps, journal membership, and author identifiers—is stored separately and is not contained inside the encrypted note payload.

Partner and invitation information. For Google/Firebase pairing, we store invitation records containing the sender's and intended recipient's email addresses, Firebase user identifiers, invitation status, shared journal identifier, and relevant timestamps. We also store the identifiers of the two journal members and encrypted journal-key envelopes.

Encryption and recovery information. Cross-platform journals use end-to-end encryption. A recovery key is displayed to you so that the journal can be restored on another device. Dear Us does not upload the recovery key itself. Firebase stores encrypted key envelopes that allow authorized devices to unlock the journal.

Anyone who obtains your recovery key may be able to access your encrypted journal, so you should keep it private.

Technical and service data. Apple, Google, and Firebase may process limited technical data required to provide authentication, networking, security, fraud prevention, diagnostics, and reliable service operation. This can include device and operating-system information, app and SDK versions, IP address, request logs, and performance or diagnostic information.

Dear Us does not use this information for advertising or cross-app tracking.

How We Use Information

We use information to:

Sharing of Information

Your journal content is shared with the partner connected to that journal. Do not connect with someone unless you intend for that person to receive the content you add to the shared journal.

We use Apple as a service provider for iCloud/CloudKit functionality and Google/Firebase as service providers for optional cross-platform authentication and synchronization. These providers process information according to their applicable terms and privacy practices.

We may disclose information if reasonably necessary to comply with law, enforce our rights, prevent fraud or abuse, or protect the safety and security of users and the service.

We do not sell personal information. We do not use journal content for advertising, and we do not track you across apps or websites owned by other companies for advertising purposes.

End-to-End Encryption

For Google/Firebase journals, note text and attached photos are encrypted on the sender's device and decrypted on authorized paired devices using the shared journal key.

Firebase also encrypts its services in transit and at rest, but this service-level encryption is separate from Dear Us's end-to-end encryption.

End-to-end encryption does not conceal all operational metadata. Firebase can process account, membership, invitation, entry-date, identifier, and request information needed to provide the service. No security measure can guarantee absolute protection.

Data Retention

We retain Firebase account and journal information while your account and pairing remain active or as needed to provide the service. Invitation records are retained until deleted through account deletion or other cleanup.

Service providers may retain security logs and backups for limited periods under their own retention policies and legal obligations.

iCloud/CloudKit data is retained and managed through Apple's services and the controls available in Dear Us and your Apple account.

Account and Data Deletion

If you created a Google/Firebase account, you can delete it from the Android Pairing or Settings area in Dear Us.

Deletion removes:

Your partner's independently authored entries may remain associated with their account. Deleting your Google/Firebase account does not delete your separate iCloud journal.

Likewise, deleting or changing iCloud data does not automatically delete your Google/Firebase account or cross-platform journal.

You may contact us using the address below for assistance with a privacy or deletion request.

Your Choices and Rights

Depending on your location, you may have rights to access, correct, export, restrict, object to processing of, or delete personal information. You may also have the right to lodge a complaint with a local data-protection authority.

You may:

International Data Processing

Apple, Google, and Firebase may process information in countries other than the country where you live. Firebase Authentication is operated from infrastructure in the United States, while Cloud Firestore may use Google's global infrastructure.

Where required, information is transferred using legally recognized safeguards.

Children's Privacy

Dear Us is not directed to children under 13, or the higher minimum age required in a particular country. We do not knowingly collect personal information from children below the applicable minimum age.

If you believe a child has provided personal information, contact us so that we can investigate and delete it where appropriate.

Third-Party Privacy Information

Changes to This Policy

We may update this Privacy Policy when the app, our service providers, or applicable requirements change. We will publish the revised policy and update the effective date above.

Contact Us

If you have questions or requests concerning this Privacy Policy or your personal information, contact us at: dojcinovicp@gmail.com