Privacy Policy
for the Android app “Buddiary” · Last updated: 28 September 2026
This is a translation. In case of doubt, the German version applies.
1. Controller
Baomi Raumi – name and address: see legal notice (Impressum)
Email: info@buddiary.app
2. Principle: your data stays on your phone
Buddiary is a private journal for your friendships. Everything you enter – people, profiles, entries, photos, lists and connections – is stored only on your device. There is no account, no server of our own, no advertising and no analytics or tracking services. We have no access to your data.
- The database is encrypted (SQLCipher); the key is kept in your device’s protected keystore (Android Keystore).
- Photos are kept in the app’s private storage, which other apps cannot access.
- Android cloud backup and device-to-device transfer are turned off for the database – the app has its own backup feature instead (section 4).
- An optional app lock (fingerprint, face or PIN) protects the interface.
3. When data leaves your device
Only in these cases and only with the information listed:
| Feature | What is sent | To whom | How to turn off |
|---|---|---|---|
| Suggesting a place for an entry or searching for a place | Coordinates or search term | Android’s location service (geocoder) – usually Google | Settings → “Suggest place automatically”; don’t search for places |
| Dictation in an entry | Voice recording | Your device’s speech recognition – usually Google, often online | Don’t use dictation |
For technical reasons, your IP address is transmitted to the respective service. Names, entries or photos are not transmitted. Before first use, the app explains what each permission is for. The legal basis is your consent by using the feature (Art. 6(1)(a) GDPR), which you can withdraw at any time by turning the feature off or revoking the permission in Android settings. Processing by these services is subject to Google’s privacy policy (policies.google.com/privacy).
Triggered by you: When you share something yourself (e.g. a backup, a friendship book PDF, the error log or birthday wishes via messenger/SMS), make a call or add an event to your calendar, you pass the data to the app you choose. That app’s privacy policy then applies.
4. Backups
You create backups (a ZIP file with entries and photos) yourself – manually or automatically in a folder you choose. Backup files are not encrypted. Keep them safe; anyone who has the file can read its contents.
5. Permissions
| Permission | What for |
|---|---|
| Location | Suggest a place for a new entry (foreground only, can be turned off) |
| Contacts (read only) | Import profile picture, phone number and birthday – only when you trigger it, only on the device |
| Microphone | Dictation in an entry |
| Notifications | Reminders for birthdays, meet-ups and “not seen in a while” – scheduled on the device |
| Biometrics | App lock |
| Run at startup | Reschedule reminders after a restart |
| Internet | Connection for the features in section 3 |
6. Error log
The app writes unexpected errors to a log on the device (time, app version, error message). It is only transmitted if you share it yourself.
7. Deletion
You can delete people and entries in the app at any time. Uninstalling removes all of the app’s data from the device; backup files in your folder remain until you delete them.
7a. Purchases (Buddiary Plus, support)
You buy Buddiary Plus and optional support contributions through Google Play. Payment is handled by Google (Google Play Billing); Google’s terms and privacy policy apply. Buddiary receives no payment details – only which product was bought – and stores on the device that Plus is unlocked. At startup the app asks Google Play for earlier purchases so that Plus is active again after a reinstall.
8. Your rights
Since we do not receive or store any personal data from you, all data is in your hands. If you have questions, contact us at info@buddiary.app. You have the right to lodge a complaint with a data protection supervisory authority.
9. This website
buddiary.app is served via Cloudflare Pages. Cloudflare processes technically necessary connection data (e.g. IP address) to deliver and secure the site. The site sets no cookies and uses no analytics or tracking services.
Contact form and email
When you write to us via the contact form or by email, we process your email address, your name (if given) and your message in order to reply. The legal basis is Art. 6(1)(b) GDPR where your request concerns the app, otherwise Art. 6(1)(f) GDPR (our interest in answering requests).
The form is received by a Cloudflare Worker and forwarded to our mailbox via Cloudflare Email Routing; Cloudflare also processes your IP address, among other things to prevent abuse. Cloudflare, Inc. (USA) is certified under the EU-U.S. Data Privacy Framework. The message is stored only in our mailbox until your request has been dealt with and is then deleted, unless statutory retention periods require otherwise. The form sets no cookies.