Privacy Policy
1. Introduction
This Privacy Policy describes how Devran Aydinoglu (“we,” “us,” or “our”) collects, uses, stores, shares, and protects your personal information when you use the Life Dump mobile application (the “App”). We are committed to protecting your privacy and handling your data responsibly.
By using the App, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App. Continued use of the App after any changes constitutes your acceptance of the updated Privacy Policy.
2. Data Controller
Devran Aydinoglu is the data controller responsible for your personal data processed through the App. For any privacy-related inquiries, please contact us through the support channels provided within the App.
We collect the following categories of information:
- Account Information: Email address, password (stored in hashed form on our servers), and gender (selected during onboarding).
- Journal Entries (“Dumps”): The encrypted text content you write in your journal entries (up to 1,500 characters per entry).
- Mood and Theme Selections: The mood and theme you associate with each journal entry, or that are automatically classified.
- Feedback: Any feedback or suggestions you submit through the App (up to 1,000 characters).
- Authentication Data: If you sign in using Apple Sign-In, we receive your identity token and authorization code. Your Apple ID email may be shared depending on your Apple privacy settings.
- Device Information: Device model, operating system and version, platform (iOS or Android), and app version.
- Device Identifier: A device-specific identifier (identifierForVendor on iOS; device ID on Android) used solely for trial eligibility tracking.
- Usage Data: Timestamps of journal entries, weekly entry counts, and subscription tier.
- Language Preference: Your selected language within the App.
- AI-Generated Responses: Automated responses generated in reply to your journal entries.
- Entry Summaries: Automated summaries of your journal entries.
- Insights Data: Aggregated analytics derived from your entries, including mood/theme frequency and patterns.
- We do not collect precise geolocation data.
- We do not access your contacts, photos, camera, or microphone.
- We do not use third-party analytics or advertising SDKs.
- We do not sell your personal data to third parties.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contract Performance (Article 6(1)(b) GDPR): Processing necessary to provide the App’s services as agreed upon when you create an account.
- Consent (Article 6(1)(a) GDPR): Where you have given explicit consent, such as when submitting journal entries or opting to use AI-generated responses.
- Legitimate Interest (Article 6(1)(f) GDPR): For service improvement, security, and fraud prevention, balanced against your fundamental rights.
- Legal Obligation (Article 6(1)(c) GDPR): Where processing is necessary for compliance with applicable laws.
Special Category Data: Your journal entries and mood data may reveal information about your mental health. We process this data based on your explicit consent (Article 9(2)(a) GDPR). You may withdraw this consent at any time by deleting your account.
We use your information for the following purposes:
- To Provide the Service: Creating and managing your account, storing and displaying your journal entries, generating AI responses, computing insights and analytics, and managing your subscription.
- To Improve the Service: Analyzing usage patterns in aggregate to improve App features, performance, and reliability.
- To Manage Subscriptions: Verifying your subscription status and entitlements through RevenueCat.
- To Manage Trial Access: Using device identifiers to enforce the one-time trial per device.
- To Communicate With You: Responding to your feedback or support requests.
- To Ensure Security: Protecting against unauthorized access, fraud, and abuse.
- To Comply With Law: Meeting our legal obligations under applicable laws and regulations.
We do not sell, rent, or trade your personal data. We share your information only with the following categories of recipients and only as necessary:
- Cloud Infrastructure Provider: Our backend is hosted on third-party cloud infrastructure. Your data is transmitted to and stored on these servers to provide the App’s services.
- AI Service Provider: Your journal entry text is sent to an AI service provider to generate responses. The content is processed for the sole purpose of generating a response and is subject to the AI provider’s data handling policies.
- RevenueCat: Your user ID and subscription status are shared with RevenueCat for in-app purchase and subscription management.
- Apple / Google: If you use Apple Sign-In, authentication data is shared with Apple. Payment processing is handled entirely by the Apple App Store or Google Play Store.
- Legal Compliance: We may disclose your information if required by law, regulation, legal process, or governmental request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections.
We require all third-party service providers to respect the security of your personal data and to treat it in accordance with applicable law.
7. Data Storage and Security
We implement reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in Transit: All data transmitted between the App and our servers uses HTTPS/TLS encryption.
- Secure Local Storage: Authentication tokens are stored using platform-native secure storage (iOS Keychain; Android Encrypted Shared Preferences).
- Access Controls: Server-side access to user data is restricted and protected by authentication mechanisms.
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. You acknowledge and accept this inherent risk.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the App’s services. Specifically:
- Account Data: Retained until you delete your account.
- Journal Entries and AI Responses: Retained until you delete individual entries or your account.
- Device Identifiers (Trial): Retained to enforce the one-time trial limit.
- Feedback: Retained for service improvement purposes and deleted when no longer needed.
Upon account deletion, we will delete or anonymize your personal data from our active systems within a reasonable timeframe, except where retention is required by law or for legitimate business purposes (such as resolving disputes or enforcing our agreements).
Backup copies may persist for a limited period as part of our standard backup procedures before being overwritten.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data.
A. Rights Under GDPR (EEA, UK, Switzerland)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data.
- Right to Restriction of Processing: Request that we limit how we use your data.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to certain types of processing, including processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority.
B. Rights Under CCPA/CPRA (California Residents)
- Right to Know: Request information about the categories and specific pieces of personal information we have collected.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- Right to Limit Use of Sensitive Personal Information: You may request limits on the use of sensitive personal information. Your journal entries and mood data are considered sensitive personal information under the CPRA.
C. Rights Under Other Jurisdictions
If you are located in Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), or other jurisdictions with data protection laws, you may have similar rights. We will honor reasonable requests in accordance with applicable law.
To exercise any of these rights, you may:
- Delete your account through the App’s profile settings.
- Delete individual journal entries within the App.
- Contact us through the support channels provided within the App.
We will respond to verifiable requests within the timeframes required by applicable law (generally within 30 days for GDPR and 45 days for CCPA/CPRA).
10. International Data Transfers
Your personal data may be transferred to, stored, and processed in countries other than your country of residence, including countries that may not provide the same level of data protection. When we transfer data internationally, we implement appropriate safeguards as required by applicable law, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Reliance on adequacy decisions for specific countries.
- Your explicit consent to the transfer.
By using the App, you acknowledge and consent to the transfer of your data to jurisdictions outside your country of residence.
11. Children’s Privacy
The App is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to promptly delete that information.
If you believe that a child under 16 has provided us with personal information, please contact us immediately through the support channels provided within the App.
12. Sensitive Data
We recognize that your journal entries, mood data, and AI-generated responses may contain or reflect sensitive personal information related to your mental and emotional state. We treat this data with the highest degree of care and:
- Process it only for the purposes described in this Privacy Policy.
- Do not use it for advertising or marketing purposes.
- Do not share it with third parties except as described in Section 6.
- Allow you to delete it at any time through the App.
Under CPRA, this data is classified as Sensitive Personal Information. Under GDPR, mood and mental health data are Special Categories of Personal Data processed only with your explicit consent.
13. Cookies and Tracking Technologies
The App does not use cookies, web beacons, or similar tracking technologies. We do not engage in cross-app tracking or behavioral advertising. The device identifier collected is used solely for trial eligibility verification and is not used for tracking or profiling purposes.
14. Third-Party Links and Services
The App may contain links to or integrate with third-party services. We are not responsible for the privacy practices or content of third-party services. We encourage you to review the privacy policies of any third-party service before providing them with your information.
Key third-party services used by the App:
15. Do Not Track Signals
The App does not respond to “Do Not Track” browser signals because it does not engage in cross-site or cross-app tracking. We do not track users across third-party websites or applications.
16. Data Breach Notification
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify affected users and applicable supervisory authorities as required by law. Notification will be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach (as required by GDPR Article 33).
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or other factors. We will indicate the Last Updated date at the top of this policy. We encourage you to periodically review this Privacy Policy.
If we make material changes that significantly affect how we handle your personal data, we will make reasonable efforts to notify you through the App before the changes take effect.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through the support channels provided within the App. Alternatively you can email devranindie@gmail.com for any questions, issues, or concerns.
If you are in the EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA).