Fillday privacy policy
- Effective date: August 4, 2026
- Operator: Hyeonwoo Kim
- Contact: ialskdji@gmail.com
- Where this policy is published: https://kugorang.github.io/Fillday/privacy/en.html
At a glance
Fillday is a personal journaling app that works entirely on your device.
- It does not collect personal data. There are no accounts, no developer servers, and no third-party analytics, advertising, or crash-reporting tools.
- Everything you write is stored only on your device.
- The promise of this policy in one line: "What you write does not go to our servers — it can be included in your device's OS backup."
1. Scope
This policy applies to the Fillday mobile app (the "app"). The operator is aware that Korea's Personal Information Protection Act, the EU General Data Protection Regulation (GDPR), and Japan's Act on the Protection of Personal Information (APPI) may be relevant. As described below, the current version of the app is local-only and does not collect or transmit personal data, so in all three jurisdictions the operator holds no personal data — that fact underpins this entire policy.
2. Personal data we collect — none
- There are no accounts and no sign-up. The app does not ask for your name, email address, phone number, or date of birth.
- The app includes no third-party analytics, advertising, or crash-reporting tools (SDKs).
- The app has no feature that sends data to a developer server. The Android release build does not include the internet access permission (INTERNET) at all.
- The privacy questionnaires of both app stores are answered accordingly: no data collected.
3. Where your entries are stored
- All entries — events, tasks, journal entries, moods — are stored only in a data file on your device (a single SQLite file in the app's private storage area).
- The entries you write from here on do not go to our servers. The current version has no feature that could send them.
- They can, however, be included in your device's OS backup — see section 4.
4. Device OS backups
- Your device's automatic backup (iCloud backup on iOS, Android backup) can include the app's data file. That backup is performed by the OS; the operator cannot access backup data.
- The two platforms protect backups differently:
- Android 9 and later: backup data is end-to-end encrypted with a key derived from your lock screen secret (PIN, pattern, or password).
- iOS (iCloud backup): under standard data protection, Apple holds the encryption keys. Backups are end-to-end encrypted only if you have turned on Advanced Data Protection yourself, and that setting is off by default.
- If you prefer not to have the app included in backups, you can turn backups off for this app (or for the whole device) in your device settings.
5. App lock (PIN and biometrics)
- With app lock turned on, access to the app's screens is gated behind a PIN (or biometrics, where your device supports them).
- App lock gates access to the app's screens. It does not provide file-system-level protection on the device (it does not encrypt the data file).
- Biometric authentication is handled by the device OS. The app does not store, collect, or access biometric data such as fingerprints or facial data; it only receives the authentication result from the OS.
- For this feature the app uses the following permissions: the Face ID usage permission on iOS and the biometric permission (USE_BIOMETRIC) on Android. Both are used solely for app lock.
6. Diagnostic information
- To help investigate problems, the app keeps a small rolling log on your device (a fixed-size buffer where the oldest entries are dropped first) containing only the error class, error code, call site, and timestamp.
- This log never includes anything you wrote — no journal text, no moods.
- Nothing is sent automatically. This information leaves your device only if you choose to copy and send it yourself from the settings screen, and you choose where it goes.
7. Data export (where provided)
Where the app provides a data export feature, these rules apply:
- The export file is created in a temporary location that lasts only for the session.
- Delivery is a one-time hand-off through the OS share sheet, and you choose the destination.
- Once sharing completes or is cancelled, the temporary file is deleted right away.
8. Notifications (where provided)
Where the app provides notifications, these rules apply:
- Only reminders you turned on yourself produce notifications. The app does not send nagging notifications.
- Quiet hours are observed from 10 pm to 7 am.
- Notification text never exposes the content of your journal entries or moods.
- Showing notifications may require the OS notification permission, which you decide on when asked.
9. Children's personal data
- The app does not collect age information such as date of birth.
- The app is not a service directed at children under 13.
10. Deleting your data
- You can delete entries directly in the app — both individual entries and a full per-module data deletion.
- The current version keeps no server copy, so deleting on your device is the end of it.
- Copies already included in a device OS backup can be cleaned up through the OS's backup management (deleting backups or turning them off).
11. Your rights
Korea's Personal Information Protection Act, the GDPR, and the APPI provide rights such as access, correction, deletion, and restriction of processing. In the current version of the app, the operator collects and holds no personal data, so there is no operator-held data for those rights to act on. Everything you wrote lives on your device, where you can read, edit, and delete it yourself. Questions are welcome at the contact details in section 13.
12. Changes to this policy and what's ahead
- If this policy changes, we will announce it in the app or by updating the published copy. Significant changes are announced before they take effect.
- A future version may introduce optional accounts and sync between devices. Before any of that ships, this policy will be revised first, with notice of exactly what changes. The sync design being prepared assumes per-user access control (row-level security) and a structure in which the operator cannot read journal content.
13. Contact
- Operator: Hyeonwoo Kim
- Contact: ialskdji@gmail.com