Florea Privacy Policy

Last updated 24 August 2026 · Applies to the Florea Android app (com.ruicodex.florea) and florea.ruicodex.com

Florea is a personal journaling, notes and planning app. This policy explains exactly what we collect, why, the legal basis for it, and how you can get rid of it. We do not sell your data, and we do not use your journal content for any purpose other than showing it back to you.

1. Who we are (data controller)

The controller of your personal data is RuiCodex. Contact for all privacy matters, including data-subject requests: info@ruicodex.com. We respond within 30 days.

2. What we collect, why, and on what legal basis

DataWhyLegal basis (GDPR Art. 6)Kept for
Email address, display nameCreate and authenticate your accountContract (6(1)(b))Until you delete your account
Password, as a bcrypt hash onlySign you in. We never store or can read your actual password.Contract (6(1)(b))Until you delete your account
Journal entries, notes, calendar events, tasks, mood and sticker selectionsThis is the content of the app. Shown only to you.Contract (6(1)(b))Until you delete it, or your account
Photos, video and voice memos you attachSo your entries keep their attachmentsContract (6(1)(b))Until you delete them, or your account
Apple user identifier, if you use Sign in with AppleLink your Apple login to your Florea account. Apple may supply a private relay email address instead of your real one; we store whichever address you choose to shareContract (6(1)(b))Until you delete your account
Google account identifier, if you use Google Sign-InLink your Google login to your Florea accountContract (6(1)(b))Until you delete your account
Purchase token, product ID and subscription expiryVerify your Premium entitlement with the store you purchased from — the App Store on iOS, Google Play on Android — and prevent one purchase being reused on several accountsContract (6(1)(b)); legal obligation for tax records (6(1)(c))Until you delete your account
Advertising identifier and related ad-request dataUsed by Google AdMob to serve ads to users on the free tier. On iOS the app asks for your permission through Apple’s App Tracking Transparency prompt before any tracking identifier (IDFA) is used; if you decline you still see ads, but they are not personalised. You can change this at any time in Settings › Privacy & Security › Tracking. On Android you can reset or delete your Advertising ID in Settings › Google › AdsConsent (6(1)(a)) where required; otherwise legitimate interests (6(1)(f)) in funding a free tierControlled by Google — see section 6
Server logs (IP address, timestamp, endpoint, error detail)Security, abuse prevention and debuggingLegitimate interests (6(1)(f))Rotated within 30 days
We do not collect your contacts, precise or coarse location, call logs, SMS, installed-app list, health-app data, or any biometric template. The app requests no location, contacts or calendar permission at all — you can verify this on the Play listing's permissions list.
A note on sensitive content. A journal can contain deeply personal information, and some of what you choose to write might qualify as a special category of data under GDPR Article 9 (for example, notes about your health or beliefs). We never ask for such data, do not analyse your entries, and process whatever you write purely as opaque content in order to store and return it to you. You decide what goes in.

3. What we never do

4. How your content is protected

No system is perfectly secure. If a breach affects your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform you without undue delay, as required by GDPR Articles 33 and 34 and the equivalent provisions of other applicable data-protection law.

5. Who we share it with (processors)

We share data only with the providers that make the app work:

ProviderWhat they receiveTheir policy
Google Play BillingPurchase token, product IDGoogle Privacy Policy
Apple App Store / StoreKit (iOS)Purchase token, product IDApple Privacy Policy
Sign in with Apple (only if you use it)Your Apple user identifier and, at your choice, an email address (possibly Apple’s private relay)Apple Privacy Policy
Google AdMobAdvertising ID, ad-request metadataHow Google uses data
Google Sign-In (only if you use it)Your Google account identifier and verified emailGoogle Privacy Policy
Our hosting providerHosts the database and uploaded mediaBound by a data-processing agreement

We may also disclose data where we are legally required to, or to establish, exercise or defend legal claims.

6. Advertising and your choices

Free users see banner and occasional full-screen ads served by Google AdMob, which may use your advertising ID to personalise them. You can:

Where the law requires consent for personalised advertising, Google presents the applicable consent prompt on our behalf and honours your choice.

7. Children

Florea is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it promptly.

8. Your rights

Under the GDPR, the UK GDPR and comparable data-protection law elsewhere, you have the right to access, rectify, erase, restrict and object to processing, and to data portability. We extend these rights to every user, wherever you live. In practice:

Deletion is immediate and irreversible: your account row, every diary entry, note, calendar event and uploaded media file is removed from the database and from file storage. Residual copies in rotating server backups are overwritten within 30 days.

You may lodge a complaint with the data-protection authority for the country you live in — in the EU, the supervisory authority of your Member State; in the UK, the Information Commissioner’s Office.

9. International transfers

Our servers are located in the United States. If you use Florea from the European Economic Area, the United Kingdom or elsewhere, your data is transferred there.

For transfers out of the EEA/UK we rely on the European Commission’s Standard Contractual Clauses together with supplementary technical measures (encryption in transit, access control, minimisation). Where another country’s law requires a separate basis for the transfer, we rely on your consent given when you create your account. You may request a copy of the relevant safeguards from info@ruicodex.com.

10. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.

11. Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change affects how we use your data, notify you in the app before it takes effect.

12. Contact

Questions, complaints or data-subject requests: info@ruicodex.com. We respond within 30 days.