privacy policy
the short version
- your photos, videos, notes and moods stay on your device. we cannot see them.
- no account, so we hold no name, email or profile for you.
- we collect crash reports and usage counters tied to a random app id, never to your identity.
- if you allow notifications, a push service holds your device's push token and a few counts about your streak.
- no ads, no ad sdks, no advertising profiles, no selling or sharing of your data. ever.
1 · who is responsible
komkat studio is the data controller for the limited data described here. contact: komkat.studio@gmail.com.
2 · what stays on your device
everything you log — photos and videos taken in or imported into loggoo, mood entries, notes, streak history and frames you generate — is written to your device's local storage. it is not uploaded to any loggoo server, because we do not run one for user content. camera, microphone, photo library and notification permissions are requested only when you use those features, and can be withdrawn in your device settings at any time.
3 · optional icloud sync
on iphone and ipad, loggoo plus members can turn on icloud sync. loggoo then copies your entries and their media into the private database of your own icloud account, so a second device signed into the same apple id sees the same journal. that copy lives under your apple id, governed by apple's privacy policy. we have no access to it and cannot read, restore or delete it on your behalf. turning sync off stops future uploads; removing the existing copy is done from your icloud account. the android build has no icloud transport and never syncs.
4 · what we do collect
to keep the app working we collect a small set of data that is not linked to your identity:
- crash and error reports — device model, os version, app version, a random installation id, and the technical stack trace of the failure.
- usage events — bounded product signals such as "a record was logged" (with its type, the hour of day, the day of week and the mood you picked), "a frame was exported" (with the template), streak length, screen names, and sync outcomes. never the photo, the video, the note text, or an exact date and time.
- push subscription — see section 5.
- purchase validation — the receipt token from apple or google needed to confirm what you bought, a random purchase-service id, the store country and the state of your loggoo plus entitlement.
we do not collect your name, email, phone number, contacts, precise location, health data or advertising identifiers. we do not run ads, do not build advertising profiles, do not track you across other companies' apps or websites, and do not attempt to re-identify this data.
5 · notifications
loggoo sends two different kinds of notification, and both need the one notification permission you grant on your device.
- your daily reminder is a local notification scheduled on your device at the hour you choose. it does not travel through any server and carries no content about your log.
- reminders we send (for example, when a streak is about to break) go through onesignal, our push provider. it holds your device's push token, a random subscription id, device model, os version, app version, language, and the ip address the device connects from, which it turns into a coarse country and timezone.
so those messages can be timed and targeted without a backend of ours, the app writes a few counts to onesignal: the time of your most recent entry and of your first entry — both rounded down to the hour — your current and longest streak, your total number of entries, whether loggoo plus is active, and whether your daily reminder is on and at what hour. no caption, mood, photo, entry id or exact timestamp is ever sent. turning off notifications for loggoo in your device settings stops every push; you can also ask us to delete your push record at the address in section 14.
6 · purchases
in-app purchases are processed entirely by the apple app store or google play, with revenuecat validating the receipt and telling the app whether loggoo plus is active. we never receive your payment card, billing address or full store account details — only what is needed to unlock what you bought and to let you restore it later.
7 · service providers we use
we use a small number of processors, strictly for the purposes above:
- google (firebase) — analytics, crashlytics crash reporting and remote config.
- onesignal — delivery and targeting of the push notifications described in section 5.
- revenuecat — purchase validation and entitlement state.
- apple and google — app distribution, payments, and, on ios and at your choice, icloud storage.
each is bound to process this data only on our instructions and may not use it for its own advertising. we do not sell or share personal information, and we have never received a legal request for user content — if that changes we will disclose what the law allows us to disclose.
8 · legal bases (eea / uk)
where the gdpr applies, we rely on: contract — to deliver the app and the purchases you make; legitimate interests — to keep the app stable and secure through diagnostics and bounded usage counters; and consent — for camera, microphone, photo library, notifications (including the push messages in section 5) and optional icloud sync, each of which you grant or withdraw yourself.
9 · your rights
you can delete every moment you have logged from settings → delete all data, and uninstalling loggoo removes the local database entirely. because your content never reaches us, deletion is immediate and complete on your side.
under the gdpr you also have rights of access, rectification, erasure, restriction, portability and objection; under the ccpa/cpra, californian residents have rights to know, delete and correct, and to opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of. we do not discriminate against anyone who exercises these rights. write to komkat.studio@gmail.com and we will respond within 30 days; note that diagnostics and usage events carry no identifier we can trace back to you, so we may not be able to isolate your specific records.
10 · retention
your log stays on your device until you delete it. crash and usage data is retained for up to 14 months, then discarded. your push record and its counts are held while your device stays subscribed and are removed when you turn notifications off or uninstall. purchase receipts are retained as long as needed to honour restores and to meet tax and accounting duties.
11 · children
loggoo is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data. loggoo has no social features, no public content and no messaging.
12 · security and international transfers
local data is protected by your device's own encryption and lock screen; keeping a passcode on your phone is the single most effective protection for your log. everything the app does send is encrypted in transit. the limited data our processors receive may be processed on servers outside your country, including in the united states, under standard contractual clauses or equivalent safeguards. no method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.
13 · changes to this policy
if this policy changes materially, we will update the date above and flag it in the app release notes before the change takes effect.
14 · contact
privacy questions, data requests, or anything that reads wrong here: komkat.studio@gmail.com.