Florea is a personal journaling, notes and planning app. This policy explains exactly what we collect, why, the legal basis for it, and how you can get rid of it. We do not sell your data, and we do not use your journal content for any purpose other than showing it back to you.
The controller of your personal data is RuiCodex. Contact for all privacy matters, including data-subject requests: info@ruicodex.com. We respond within 30 days.
| Data | Why | Legal basis (GDPR Art. 6) | Kept for |
|---|---|---|---|
| Email address, display name | Create and authenticate your account | Contract (6(1)(b)) | Until you delete your account |
| Password, as a bcrypt hash only | Sign you in. We never store or can read your actual password. | Contract (6(1)(b)) | Until you delete your account |
| Journal entries, notes, calendar events, tasks, mood and sticker selections | This is the content of the app. Shown only to you. | Contract (6(1)(b)) | Until you delete it, or your account |
| Photos, video and voice memos you attach | So your entries keep their attachments | Contract (6(1)(b)) | Until you delete them, or your account |
| Apple user identifier, if you use Sign in with Apple | Link your Apple login to your Florea account. Apple may supply a private relay email address instead of your real one; we store whichever address you choose to share | Contract (6(1)(b)) | Until you delete your account |
| Google account identifier, if you use Google Sign-In | Link your Google login to your Florea account | Contract (6(1)(b)) | Until you delete your account |
| Purchase token, product ID and subscription expiry | Verify your Premium entitlement with the store you purchased from — the App Store on iOS, Google Play on Android — and prevent one purchase being reused on several accounts | Contract (6(1)(b)); legal obligation for tax records (6(1)(c)) | Until you delete your account |
| Advertising identifier and related ad-request data | Used by Google AdMob to serve ads to users on the free tier. On iOS the app asks for your permission through Apple’s App Tracking Transparency prompt before any tracking identifier (IDFA) is used; if you decline you still see ads, but they are not personalised. You can change this at any time in Settings › Privacy & Security › Tracking. On Android you can reset or delete your Advertising ID in Settings › Google › Ads | Consent (6(1)(a)) where required; otherwise legitimate interests (6(1)(f)) in funding a free tier | Controlled by Google — see section 6 |
| Server logs (IP address, timestamp, endpoint, error detail) | Security, abuse prevention and debugging | Legitimate interests (6(1)(f)) | Rotated within 30 days |
No system is perfectly secure. If a breach affects your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform you without undue delay, as required by GDPR Articles 33 and 34 and the equivalent provisions of other applicable data-protection law.
We share data only with the providers that make the app work:
| Provider | What they receive | Their policy |
|---|---|---|
| Google Play Billing | Purchase token, product ID | Google Privacy Policy |
| Apple App Store / StoreKit (iOS) | Purchase token, product ID | Apple Privacy Policy |
| Sign in with Apple (only if you use it) | Your Apple user identifier and, at your choice, an email address (possibly Apple’s private relay) | Apple Privacy Policy |
| Google AdMob | Advertising ID, ad-request metadata | How Google uses data |
| Google Sign-In (only if you use it) | Your Google account identifier and verified email | Google Privacy Policy |
| Our hosting provider | Hosts the database and uploaded media | Bound by a data-processing agreement |
We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims.
Free users see banner and occasional full-screen ads served by Google AdMob, which may use your advertising ID to personalise them. You can:
Where the law requires consent for personalised advertising, Google presents the applicable consent prompt on our behalf and honours your choice.
Florea is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it promptly.
Under the GDPR, the UK GDPR and comparable data-protection law elsewhere, you have the right to access, rectify, erase, restrict and object to processing, and to data portability. We extend these rights to every user, wherever you live. In practice:
Deletion is immediate and irreversible: your account row, every diary entry, note, calendar event and uploaded media file is removed from the database and from file storage. Residual copies in rotating server backups are overwritten within 30 days.
You may lodge a complaint with the data-protection authority for the country you live in — in the EU, the supervisory authority of your Member State; in the UK, the Information Commissioner’s Office.
Our servers are located in the United States. If you use Florea from the European Economic Area, the United Kingdom or elsewhere, your data is transferred there.
For transfers out of the EEA/UK we rely on the European Commission’s Standard Contractual Clauses together with supplementary technical measures (encryption in transit, access control, minimisation). Where another country’s law requires a separate basis for the transfer, we rely on your consent given when you create your account. You may request a copy of the relevant safeguards from info@ruicodex.com.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.
If we make a material change we will update the date at the top of this page and, where the change affects how we use your data, notify you in the app before it takes effect.
Questions, complaints or data-subject requests: info@ruicodex.com. We respond within 30 days.