Controller and contact details
- Name
- Nikolay Bilev
- Address
- Wuhlestraße 7a12683 BerlinGermany
- privacy@oflate.app
Overview
Oflate is designed as a local journal app. Notes, signals, day notes, chapters, and personal settings are generally processed on your device. Oflate does not operate its own user account or server for your journal content. The Oflate provider does not receive or have access to journal content during ordinary app use.
Data in the app
You can store free-form entries and structured signals. You choose their names, subject, values, and meaning. Because the fields are user-defined, you may choose to record sensitive information, including health information. Oflate does not require this, determine the subject of a field, or interpret your content as a medical or psychological conclusion.
At your direction, the app stores, searches, and displays this data and calculates the descriptive summaries you choose to view on your device.
On-device storage and protection
App data is stored locally in Oflate’s app storage on your device. If enabled, app lock uses biometric or device authentication provided by the operating system. It does not separately encrypt stored app data and protects only the act of opening Oflate. Protecting your device, operating-system account, and device backups therefore remains important.
If you enable a reminder, Oflate provides its content and schedule to your device’s notification system. Depending on your device settings, the notification content may appear on the lock screen; app lock does not hide it.
Oflate calculates descriptive signal summaries on your device. It does not transmit journal content for advertising or product analytics, create a developer-held advertising or marketing profile from it, or make solely automated decisions that produce legal or similarly significant effects.
Export, backup, restore, and deletion
You can manually create a readable share export or a restorable backup file. Oflate does not add separate encryption to these files. After delivery, you and the destination app or storage location you choose control further copies and their deletion.
For a database schema change or a restore, Oflate may create one bounded temporary database recovery copy. Oflate removes and verifies that copy after the operation is resolved. If recovery or cleanup cannot be verified, the copy remains for a later startup recovery attempt instead of being treated as backup history. A backup selected for restore is read from a temporary system-provided copy, which Oflate removes and verifies before changing your journal. Temporary files used for sharing are removed after the platform handoff settles; if cleanup cannot be verified, Oflate reports that cleanup is still pending and retries later.
The delete-content function removes your current journal content and Oflate-controlled temporary copies from this device. Oflate changes your journal content only after it has verified the required temporary-file cleanup and cancellation of your scheduled Oflate reminders. Some settings, content-free deletion records, bytes in unused database pages, filesystem or device snapshots, and other technical remnants may remain. Oflate cannot remove exports or backups you saved elsewhere, operating-system backups, copies held by a sync provider, or files already delivered to another app or location.
Subscriptions and purchases
Apple processes purchases and subscriptions. Oflate initializes RevenueCat during ordinary app startup, including when no active paid subscription exists. RevenueCat receives purchase, receipt, product, and entitlement information and limited technical information about the app, device, platform, operating system, build, preferred locale, storefront, and, when available from the system, Apple’s identifier for vendor. Oflate does not send a developer-assigned account or user identifier.
RevenueCat generates a random service identifier for the installation. It does not directly contain your name or email address, but RevenueCat can associate it with purchase history, so Oflate does not describe it as anonymous. The data is used for receipt validation, fraud prevention, entitlement management, and subscription-service analysis. Without it, paid functionality cannot be verified.
Communications
If you choose to send a feedback, support, or privacy email, the Oflate provider processes through Google Workspace your sender address and, where supplied, your name, message, and attachments. The feedback action may also place the app version, build, operating-system version, and device model in a visible draft. You decide what to send.
Please do not send journal content or sensitive details unless they are necessary for your request. Feedback, support, and privacy requests are handled separately. Unrequested sensitive material is not reused for a new purpose; access is restricted and unnecessary detail is deleted or minimized.
Website
Cloudflare delivers Oflate’s static website. Cloudflare therefore processes technically necessary connection and security data, especially IP address, time, requested resource, and technical request information. Oflate does not add analytics, advertising, forms, cookies, or local browser storage to the website.
Purposes and legal bases
Depending on the processing activity, the legal allocations include:
- local app processing and exports you initiate: performance of the app functionality you use;
- reminders: performance of the reminder function you enable and delivery through the operating system;
- subscription and receipt checks: contract performance and provision of purchased functionality;
- product feedback: handling your feedback and legitimate interest in traceable product improvement;
- support: handling your specific request and legitimate interest in secure, traceable assistance;
- privacy requests: compliance with legal obligations;
- website delivery and protection: legitimate interest in a secure and available information site.
Where information is voluntary, not providing it has no consequence other than that the relevant voluntary feature or request cannot be handled. Purchase and entitlement data is necessary to acquire and unlock paid access. Information used to verify identity may be legally necessary for a particular privacy request.
Recipients and transfers
Apple acts as an independent controller for store, payment, and platform transactions under the terms that apply there. RevenueCat processes subscription and entitlement data on behalf of the Oflate provider. Google Workspace processes communications you initiate on behalf of the Oflate provider. Cloudflare processes connection and security data on behalf of the Oflate provider for website delivery; any provider purpose determined separately by contract or law is assessed separately.
RevenueCat, Google Workspace, and Cloudflare may process data in the United States. RevenueCat’s current data processing addendum incorporates the EU Standard Contractual Clauses for restricted transfers. For Google Workspace and Cloudflare, depending on the processing route, safeguards may include the EU-US Data Privacy Framework and, where required, the EU Standard Contractual Clauses. You can request a copy of applicable safeguards through the privacy contact.
Retention
Active local app data remains stored until you change or delete it or remove the app data. Reminder records remain in the local database until changed or deleted successfully; the operating-system request remains until cancellation is verified. If a reminder change cannot be completed consistently, Oflate attempts to keep or restore the earlier reminder state. If Oflate cannot verify that state, it reports a distinct failure and the operation can be retried. Exports and backups you create follow the storage location you choose. Oflate-controlled import, export, migration-recovery, and restore-recovery copies are bounded by purpose and normally removed as soon as their operation is resolved. A copy remains only while cleanup or recovery is still pending and is retried at a later startup or deletion attempt.
RevenueCat retains data under its applicable contract and backup rules. Feedback remains in the active mailbox for up to 24 months. After removal from the active mailbox, the email provider’s standard deletion and backup procedures apply. Support mail is kept for up to 12 months after the case closes, and the minimum record of a privacy-rights request for up to three years after closure. Unneeded identity evidence and attachments are removed earlier where possible. Legal holds may extend these periods. These periods are therefore not promises that every provider backup is erased on the same day.
Your rights
Subject to the applicable legal conditions, you have, in particular, rights of access, rectification, erasure, restriction, portability, and objection. You can correct, export, or delete much local data directly in Oflate. Data processed by Apple is also subject to Apple’s account, purchase, and privacy routes.
Where processing is based on legitimate interests, you may object at any time on grounds relating to your particular situation. The relevant processing will then stop unless compelling legitimate grounds are demonstrated that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend legal claims. Oflate does not use this data for direct marketing.
Contact routes are available on Support and in the Legal notice.
If you believe the processing of your personal data infringes data-protection law, you also have the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA country where you usually live, where you work, or where you believe an infringement occurred.
Changes to this notice
We update this notice when Oflate’s processing activities, purposes, or recipients change and, where required, before the change takes effect.