Dearest — Privacy Policy
Last updated: 2026-07-25
Dearest ("the app", "we", "us") is a private journaling app for iPad in which you write by hand and a fictional "spirit" — whose replies are generated by artificial intelligence — writes back. This policy explains what happens to your information. Dearest is intended for users aged 16 and over.
Operator: Mathias Malellari, Windoferstraße 1, 04229 Leipzig, mathiasmalellari@gmail.com. Full provider details are in our Impressum.
The short version
- Your diary — the pages you write and the spirit's replies — is stored on your device and, if you enable it, in your own private iCloud. We do not run a database of your entries; our server keeps no copy. To generate a reply, this content is transmitted to our AI providers, but it is not retained by us.
- We ask for no account, no name, no email, and no real-world identity. We show no ads and use no cross-app advertising trackers. The app reports anonymous usage events (which screens are reached, whether a purchase happened — never what you write) to one analytics processor, Superwall, under a random install identifier. If you found Dearest through one of our Apple Ads, Apple may provide campaign-level attribution so we can measure whether that ad led to a trial or subscription.
- Because it is a diary, what you write may be deeply personal. You decide what to write; please read "Sensitive content".
What we process, and why
1. Your handwriting and entries. When you finish an entry, the app captures an image of what you wrote and sends it, with a short "memory" summary of your past entries and the recent conversation, to our AI providers so a reply can be generated. Legal basis: performance of our contract with you (the app's core function) — Art. 6(1)(b) GDPR; for special-category content, your explicit consent (see "Sensitive content").
2. The spirit's replies and your app "memory". Generated replies and a distilled summary of durable facts the book "remembers" are stored on your device and, if you turn on iCloud memory, in your own private iCloud. We cannot read your iCloud data.
3. Subscription status. If you subscribe, Apple tells the app whether an active subscription exists, tied to a random anonymous identifier — not your name or email. Legal basis: performance of contract (Art. 6(1)(b)) and our legitimate interest in operating, securing, and preventing abuse or fraud of the paid features (Art. 6(1)(f)).
4. Anonymous usage events. To understand where the app loses people, it sends flat event signals — screen names, counts, flags, and observed purchase confirmations — to our analytics processor Superwall, tied to a random install identifier. These events never contain your entries, your handwriting, your spirits' names, or anything you wrote, and safety-related moments are never reported in any form. Legal basis: our legitimate interest in improving the app (Art. 6(1)(f)).
5. Apple Ads attribution. If you install Dearest after interacting with one of our ads in Apple's App Store, Apple's AdServices framework can provide an attribution token. Superwall resolves it into limited advertising metadata such as campaign, ad group, keyword, storefront, and whether the install was a download or redownload. We use this only to measure our own Apple Ads and connect advertising cost to anonymous trial and subscription outcomes. It is not combined with third-party data, used for cross-app targeting, or shared with data brokers, and it never contains anything you write. Legal basis: our legitimate interest in measuring and improving our own advertising (Art. 6(1)(f)).
We do NOT collect: your name, email, phone, contacts, precise location, photos, microphone, or an IDFA. We do not use cross-app tracking.
Sensitive content
A diary can contain sensitive information — about your health, feelings, beliefs, relationships or sexuality (special categories under Art. 9 GDPR). The app tells you plainly, on first use and in this policy, that replies are written by generative AI and that a finished entry is carried to our AI providers so the reply can be generated. An entry is transmitted only when you choose to write it to a spirit — that act is your consent to the processing of that entry, including any sensitive content you chose to include (Art. 9(2)(a)). Nothing is transmitted while you merely read or browse, and you can stop at any time by not writing to a spirit; pages already written never leave the device again. Stopping does not affect processing already carried out.
The crisis check never leaves the exchange. It runs inside the app and within the reply itself; its outcome is not stored by us, is never sent onward or reported to anyone, no person reviews it, it triggers no report or alert, and the app cannot contact emergency services on your behalf. It only surfaces supportive information locally.
The spirit's replies and the safety feature are produced by automated processing. They do not make decisions that produce legal or similarly significant effects about you; the safety feature only surfaces supportive information. Dearest is not a medical, mental-health, or emergency service — see the Terms.
Who processes your data (processors and recipients)
To generate replies and run paid features, your completed entry and/or subscription status is processed by:
- OpenRouter, Inc. (USA) — routes the request to the AI model.
- Anthropic, PBC (USA) — AI model for some features (creating a custom spirit; memory distillation).
- Google LLC (USA) — AI model that writes the replies.
- Cloudflare, Inc. (USA/global) — runs the stateless server that forwards the request.
- Superwall, Inc. (USA) — receives anonymous usage events, observed purchase confirmations, and — after an Apple Ads install — limited Apple Ads attribution metadata (random install identifier only; never your entries).
The AI/proxy providers act as our processors under Art. 28 GDPR data-processing agreements. Separately, Apple Inc. stores your own entries in your own iCloud and processes App Store payments — for those, Apple acts as its own controller under your relationship with Apple, not as our processor.
Each of these providers is contractually bound to protect your data to a standard at least equal to this policy and to Apple's App Store requirements, to use it only to provide the service, and not to sell it. We do not sell your content, and we do not use it to train any model of our own; your entry is sent to our providers solely to generate your reply and to operate the service.
International transfers. These providers are in the USA. Where a provider is certified under the EU-U.S. Data Privacy Framework, transfers rely on the European Commission's adequacy decision of 10 July 2023; otherwise, and as a fallback if a certification lapses, they rely on the EU Standard Contractual Clauses with supplementary measures. You can request a copy of the relevant safeguards at mathiasmalellari@gmail.com.
Retention
- On your device / your iCloud: your entries remain until you delete them (use "let it forget" in Settings, or delete the app / clear the data in your iCloud). We cannot delete this for you because we do not hold it.
- On our server: nothing is stored; requests are processed and discarded.
- With AI providers: your entry is processed to generate the reply, subject to each provider's own retention.
- Subscription status: retained by Apple per its policies.
- Usage events: retained by Superwall per its policy, under the random install identifier only.
- Apple Ads attribution: retained by Superwall with the random install identifier according to its policy.
Your rights (GDPR)
You have rights of access, rectification, erasure, restriction, portability, and objection, and to withdraw consent. Because your content lives on your device and in your own iCloud — not on our servers — you exercise most of these directly: edit or delete entries in the app, use "let it forget", delete the app, or remove the data from iCloud. For anything else, contact mathiasmalellari@gmail.com. You may complain to the competent supervisory authority, Die Sächsische Datenschutz- und Transparenzbeauftragte (SDTB), datenschutz.sachsen.de, or to the data-protection authority of your own place of residence.
We have not appointed a Data Protection Officer, as we are not legally required to; for all data-protection matters contact mathiasmalellari@gmail.com.
Children
Dearest is intended for users aged 16 and over and is not directed to children. We do not knowingly process data from anyone under 16.
Security
Entries are stored using the device's and Apple's standard protections. Requests to our server are sent over encrypted connections (HTTPS). Because we store no content, there is no content database to breach.
Changes
We may update this policy; the "last updated" date will change and material changes will be reflected in the app.
Contact
Mathias Malellari, Windoferstraße 1, 04229 Leipzig, mathiasmalellari@gmail.com. See also the Impressum.