Privacy Policy
Be in Mood with Friends
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Be in Mood with Friends is a private reflection journal without user accounts. On your iPhone it stores your optional profile name, manually entered friend names, communication tags and notes, selected friend and memory photos, meeting dates, text places or addresses, meeting notes and memories, mood, energy and social-battery ratings, reminder preferences, language, pending synchronization records and cached analysis. Photos are copied from items you select and re-encoded for the local journal. The app does not read your contacts, location, entire photo library or existing calendar events. Our backend stores a random installation identifier, a hash of its private authorization secret, creation dates, check-in timestamps and ratings, and meeting dates, formats, tags and before-and-after ratings. Friend names, profile names, photos, addresses, notes and memory text are not uploaded to our backend. The installation secret is stored in the iPhone Keychain. Requests to the API, home page and this policy necessarily expose connection information such as IP address, request time, route and browser or client headers to hosting infrastructure. Application operational logs contain request identifiers, route templates, methods, status codes and generic error codes, not journal bodies or authorization secrets.
How we use information
Local data enables check-ins, manual friend management, suggestions based on your current state and past reflections, meeting planning and a personal memory journal. The backend accepts queued records and calculates private summaries of how meeting formats and friend tags relate to changes in your own mood and energy. The installation identifier and secret authorize access to only that installation's records. Operational information supports service delivery, request limits, security and fault diagnosis. Ratings and summaries are for personal reflection, not diagnosis or medical care. Optional local notifications remind you to check in or attend a meeting. We do not use advertising, cross-app tracking or third-party behavioral analytics.
Service providers and sharing
Railway hosts the application backend and its PostgreSQL database and processes network requests, stored server records and infrastructure logs to operate the service. Access is limited to service operation and authorized administration; there is no public profile or sharing of private journal records with other installations. The native app includes no third-party advertising or analytics SDK. If you explicitly add a meeting to Calendar, its friend's name, date, place and note are sent to the system calendar, where Apple or your chosen calendar provider may synchronize and process that copy under its own settings and policy. System photo selection and notifications are handled by iOS. Visiting the public website involves Railway infrastructure even if you do not use the app. We do not sell journal data. Information may also be disclosed when a binding legal obligation requires it.
Data retention
The local journal remains on the iPhone until you delete it in the app or remove the app. The journal storage directory is excluded from device backups by the app, and the installation secret uses a device-only Keychain accessibility class. Server check-ins, meeting metadata and the installation identifier remain until an authorized deletion request; the app does not configure an automatic expiration period. Uninstalling alone does not delete server records. Losing the installation secret prevents recovery or linkage to a new installation. The app does not configure scheduled database backups. Railway may retain infrastructure logs or provider-managed copies according to its service practices; we have not established a fixed retention period for those records and do not promise immediate removal from provider backups. Calendar copies and the original photos in your photo library follow the retention settings of those separate services.
Deleting your information
Use Settings, Delete all data to remove the journal. When a server identity exists, the app first requests deletion of that installation and its check-ins and meetings from the active PostgreSQL database; an internet connection is required. After confirmed deletion or confirmation that the old identity is no longer authorized, it clears local journal records, copied photos, cached analysis, the installation secret and its scheduled and delivered local notifications. A failed request is not presented as successful deletion and can be retried. Deleting a friend removes its local name and profile, while historical meetings remain without the name. Delete all data removes those meetings as well. This does not delete original photos from the photo library or events already copied to Calendar; remove those in the respective apps. Deletion from the active database does not assert instant erasure of hosting logs or any provider-managed backup copies. Delete server data before uninstalling because the app cannot recover the previous installation secret after reinstalling.
Permissions and your choices
Photo selection uses the system picker and grants access only to the selected items; no broad photo-library permission is requested. Cancel the picker to decline, remove a copied photo from a record, or delete the journal to remove local copies. Optional Calendar access is write-only and requested when you choose to add a meeting. Optional notification permission is requested when you enable reminders. You can withdraw Calendar or notification permission in iPhone Settings and turn off reminders inside the app. Declining these permissions does not prevent local check-ins or meeting records. Withdrawing permission does not automatically remove existing Calendar copies, original photos or previously copied journal images. The app does not request contact, camera, location, microphone or tracking permission.
Your privacy rights
For privacy questions or to exercise applicable data rights, contact ariadne.botting@icloud.com. This address is a public privacy contact, not an account identifier, login method or in-app email delivery service. Depending on the law that applies to you, you may have rights to access, correct, delete, restrict or object to processing, receive a copy of your data, withdraw consent where relevant, and complain to a data-protection authority. You can edit local friends and meeting reflections and use the in-app deletion control. Because the service uses an installation identifier instead of a name or email, we may need information sufficient to identify the relevant records and verify authority; never send your installation secret. We cannot recover or reliably associate abandoned server records with you after that secret is lost. Processing is limited to delivering the journal and maintaining its security, with optional device permissions under your control.
Security
The app communicates with the public API over HTTPS. Every private server endpoint verifies a separately generated 256-bit random installation secret, and the database stores only its cryptographic hash. Server database queries are scoped to the authorized installation. Inputs are validated and requests are subject to size and rate limits. The database is connected through Railway's private service network. Local journal files use iOS file protection and the secret is held in the device-only Keychain. No common client credential unlocks all installations. These measures reduce risk but no system guarantees absolute security. We do not claim an independently audited certification or a verified provider backup-erasure schedule for this app.
Children’s privacy
This app is intended for adults and young people reflecting on their friendships, not for children under 13. It does not ask for a birth date or intentionally create profiles of children under 13. A parent or guardian who believes a child has supplied data can contact ariadne.botting@icloud.com and can use Delete all data on the child's installation. Young people should use the app consistently with applicable age and parental-permission requirements. The journal is not a medical service or a substitute for professional support.
Changes to this policy
We may update this policy when the app's processing, features, hosting arrangements or legal requirements change. The updated English policy will be published at this Privacy Policy page with a new effective date. Material changes will be communicated through an appropriate app or policy notice. Review this page periodically; the Settings privacy link opens the current published policy. Contact ariadne.botting@icloud.com if you need clarification about a change.