Privacy Policy
This policy covers the Diaroo phone and watch apps, diaroo.app, and support communications. Taoftware LLC is responsible for the practices described here. Core journaling works without an account. Your journal can contain sensitive health information; we describe below when it stays on your device and when service providers process it.
1. Your journal and account
Your entries may contain bowel movement type and time, duration, Bristol scale, stool color, symptoms, food and water information, mood, notes, and optional location coordinates. Entries are saved on your device. Signing in enables synchronization of your journal and profile, including journal entries already saved on that device, with our Supabase database. Changes wait for a connection when offline. A successful sign-out clears the app’s local account data; it does not delete your account or synchronized journal. You can continue using the journal without signing in.
Supabase processes your email address, account identifier, authentication credentials, profile, consent records, and synchronized entries. Passwords are hashed by the authentication service. The authentication service also processes technical information such as IP addresses and login activity to operate and protect accounts. We do not receive your App Store or Google Play password or payment-card information. Core journaling without an account does not mean the app makes no network requests: purchases, maps, ads, and optional diagnostics can contact the providers described below.
Bowel details and the bladder diary update
Optional bowel details may include straining, incomplete emptying, urgency, pain, stool amount, leakage, pad changes, manual assistance and bowel medicines. The bladder update records bathroom visits, leaks, drinks and pad changes, with optional measured volume and original units, estimated amount, urgency, pain or burning, activity, drink type, pad count, waking to urinate, notes and location. Records also include time, available time-zone offset and the originating phone/watch platform; an unknown source remains unknown. These are self-reported observations, not sensor measurements or diagnoses. Bladder records use the same local storage, optional account sync, access controls, export and deletion choices described in this policy. They are not inputs to ads, analytics, AI analysis or bowel game scores.
Standalone Apple Watch and Wear OS apps
In version 1.4.0 and later, the installed watch app saves Poo entries and displays local history offline without a diary account. Phone–watch sync is optional. When Diaroo is installed on compatible paired devices, it attempts to connect; a previous Disconnect choice requires manual reconnection. New connected logs sync automatically. Earlier local logs transfer only after you choose Sync local logs and confirm the destination journal. Connected apps exchange entry type, mood, timestamp, recorded origin, identifiers, a journal/connection identifier, language/theme preferences, structured bladder details, validated saved location coordinates and a Premium-access flag. The watch retains local entries and a cache of up to 50 recent bowel and 50 recent bladder entries, plus unsent linked logs. Free-text notes, bowel symptom and food fields, passwords and authentication tokens are not sent to the watch. Premium Pee access is confirmed through the paired phone. No heart-rate, Apple Health or Health Connect data is read. Watch apps contain no advertising SDK; map-provider processing is described below.
With location permission, the watch requests one foreground fix for up to five seconds when you save. Saving returns you to the home page while an available fix is attached locally; connected logs can then transfer to the phone. Signed-in phone journals can synchronize those coordinates through Supabase. Opening a map may also request one fresh fix to center the view, without creating an entry. Phone and watch location permissions are separate. Automatic map centering does not prompt for new permission. If permission or a fix is unavailable, logging still works and the map uses located entries or an empty state. There is no continuous or background location tracking. Recent-history sync includes saved coordinates so mapped entries can appear on the watch.
Apple Watch uses Apple’s WatchConnectivity service. Wear OS uses Google Play services’ Data Layer, which can transfer through Bluetooth or relay through Google-owned servers; Google documents end-to-end encryption for that cloud relay. These operating-system services process the information needed to deliver transfers. Phone–watch sync does not require a Diaroo account. If you sign in on the phone, imported watch entries also participate in that phone’s account synchronization described above.
The paired apps exchange device manufacturer and model information so each can identify the other in Settings, including before journal sharing is enabled. This information stays in the phone–watch connection storage and is not added to your cloud journal. Connection choices, opaque device identifiers, manufacturer/model details, reachability, and receipt times are stored locally to display connection status and prevent old transfers from entering a different journal. Disconnecting on a watch stops sharing with that watch. Disconnecting on the phone stops Diaroo sharing with all watches. Connected Wear OS watches share the same phone journal; iPhone exchanges with the active Apple Watch selected by iOS. The watch clears visible phone history immediately when disconnected on the watch, or when it receives a phone-side disconnection or journal-reset update. An offline watch cannot receive a remote change immediately. Unsent logs remain locally held across disconnection or a journal change and require explicit confirmation to move to the current journal. Disconnecting does not delete the phone journal or remove system-level device pairing.
Local-only watch logs remain on the watch until you explicitly transfer them or remove the app and its data. Unsent linked logs remain until acknowledged by the phone; held logs remain until recovered or the app data is removed. Removing the app can lose local or unsent logs. OS transfer queues may retain messages until delivery or cleanup. We exclude watch journal, queue and connection files from app backups where supported. Device reset and unpairing behavior is controlled by Apple or the watch manufacturer. Setup and disconnection help.
2. Location, maps, exports, and reminders
Location is optional. Diaroo requests device permission before attaching coordinates to an entry. You can decline and still log entries, or disable location in Settings or your device permissions. Previously saved coordinates remain in their entries until you remove those entries or delete your account.
Phone maps load tiles from the OpenStreetMap Foundation. Version 1.4.0 watch maps use Google Maps SDK for Android on Wear OS and Apple MapKit on Apple Watch. Map providers receive network information such as IP address and the area being viewed. Google Maps SDK also collects device metadata, crash metrics, map interactions and a unique identifier as described in Google’s SDK disclosure. This map-service processing is separate from Diaroo’s optional phone analytics. Diaroo does not send journal notes, symptoms or other health fields to map providers. See Google’s Privacy Policy, Google Maps terms and Apple Maps privacy. PDF and CSV reports are created on your device; you choose the diary, date range and whether to include notes. JSON includes the complete journal, including notes and saved coordinates. Export controls are in Settings → Manage your data. In version 1.4.0 and later, PDF, CSV and JSON exports require active Premium; earlier builds retain their existing export access. You choose where exported files are shared and are responsible for those copies.
Diaroo does not track your location continuously in the background. Reminders are optional notifications scheduled on your device. Notification and location permissions can be changed in your device settings.
3. Premium purchases
Apple or Google processes purchases. RevenueCat processes app user identifiers, purchase and subscription history, product identifiers, transaction information, entitlement status, and technical app/device and network information so Diaroo can unlock and restore Premium access. Store purchase records may remain after account deletion for billing, refund, fraud-prevention, and legal obligations. Deleting Diaroo or its account does not cancel a store subscription.
4. Advertising and consent
The free app uses Google AdMob for banner and optional rewarded advertisements. Google may process IP address, device and advertising identifiers when available, app and device information, ad interactions, and diagnostics for ad delivery, measurement, and fraud prevention. Diaroo requests non-personalized ads and does not provide your journal entries, symptoms, notes, or saved location coordinates as advertising inputs.
Where required, Google’s consent form appears before ads can be requested. You can revisit available choices using Settings → Ad privacy choices. If a consent check fails, Diaroo does not request an ad. Ad-free Premium removes advertisements. Non-personalized ads may still use device storage and identifiers for purposes such as frequency capping and fraud prevention.
5. Optional analytics and crash reports
Diaroo’s optional phone analytics and crash reporting are off until you choose to allow them. Google Maps SDK processing is described separately above. If enabled, Amplitude receives app interactions such as screen views, sign-in events, purchase events, language choice, app/device and network information (which may include approximate location inferred from IP), and an account identifier when signed in. Sentry receives diagnostic error information, app/device and network information, and an account identifier when signed in. We do not intentionally include journal content, symptoms, saved coordinates, passwords, or authentication tokens in these events. Console breadcrumbs are excluded from crash reports.
You can withdraw this permission in Settings → Privacy → Usage Analytics. Withdrawal stops new collection; it does not automatically erase records previously received by the providers. Contact us to request erasure of those records. PDF reports and Premium 7-, 30-, and 90-day summaries are calculated on your device. Journal content is not sent to an AI or report-generation service to create them. This release does not offer public journal posting, leaderboards, or community games.
6. Service providers
| Provider | Purpose and privacy information |
|---|---|
| Supabase | Account authentication and journal synchronization. Privacy policy |
| RevenueCat | Purchase validation and Premium access. Privacy policy |
| Apple / Google Play | Store billing, subscriptions, refunds, distribution, and the optional phone–watch transport described above. Apple privacy · Google privacy |
| Google AdMob | Advertising and consent management. Google’s use of information from apps |
| Amplitude / Sentry | Optional analytics and crash diagnostics. Amplitude privacy · Sentry privacy |
| Google Maps / Apple MapKit | Watch maps and the provider processing described above. Google privacy · Apple Maps privacy |
| OpenStreetMap Foundation | Map tiles. Map libraries are bundled in the app; they are not downloaded from a CDN at runtime. OpenStreetMap privacy |
| Cloudflare / Google Fonts | Website hosting, security, performance measurement, and font delivery; network and browser information when you visit. Cloudflare privacy · Google Fonts privacy |
We use these services to operate Diaroo and do not sell journal content. We may disclose information when required by law, to protect account security, or in a business transfer subject to applicable privacy obligations.
7. Retention and deletion
Local journal data remains until you remove it, successfully use Clear This Device, or uninstall Diaroo. Device or operating-system backups may retain their own copies. Synced journal data remains while your account is active or until you delete it. When an entry deletion synchronizes successfully, its journal content is removed from the active database. We keep entry/account identifiers and deletion or synchronization timestamps while the account exists to prevent an older device from restoring a deleted entry and to handle repeat sync attempts. These records do not contain the deleted entry’s notes or health fields. Other devices need to reconnect and synchronize to receive a deletion. Settings → Manage your data → Delete Account deletes the Diaroo authentication account and associated journal, profile, consent, synchronization/deletion metadata, and server credit records from the active database after successful verification. If a shared account also contains another Taoftware app’s data, the operation stops and directs you to contact us so those records can be handled without accidental loss.
Clear This Device synchronizes pending account changes before signing you out and clearing local app data. If synchronization fails, it asks you to retry rather than clearing unsynced records. It does not erase synchronized cloud data, which can return when you sign in again. Account deletion does not delete files you previously exported, cancel subscriptions, or erase records the stores must retain.
You can also request deletion without the app at diaroo.app/delete-account. We verify control of the account and aim to complete requests within 30 days. We may retain limited billing, security, or legal records when necessary for those purposes. Provider backups and logs are subject to their retention schedules and may not disappear immediately; retained records are not used to restore a deleted account for ordinary use. Contact us for the scope and status of your request.
8. Security and your choices
Connections to our backend use HTTPS. Database access policies restrict journal access to its account. Local application storage relies on your device’s protection. Journal synchronization is not end-to-end encrypted; our service and hosting provider can process the data to operate the service. Protect your device with a passcode and keep it updated. No system can guarantee absolute security.
You may request access, correction, a portable copy, deletion, restriction, or an objection to processing, where applicable. You can withdraw optional consent without losing core journaling. Depending on your location, you may complain to a privacy regulator and exercise additional rights without discrimination. We use account data to provide the service you request, optional consent for analytics and applicable advertising choices, and limited security/legal processing where necessary. Service providers may process data outside your country, including the United States.
9. This website and support
The website loads fonts from Google Fonts and is hosted through Cloudflare. Requests can include your IP address, browser details, requested page or file, and technical security or error information. Cloudflare also supplies a Web Analytics performance beacon on the live site. It reports page views and technical information such as page/referrer information, browser/device characteristics, and page-load or interaction timing to help us understand site performance. Cloudflare describes this measurement as not using cookies or browser storage and not tracking people across sites. This website measurement is separate from the mobile app’s optional Usage Analytics setting. See Cloudflare’s collection and privacy details. We do not provide a website account login or journal-upload form. Theme preview choices are not stored in cookies or browser storage. Hosting and font providers handle their operational information as described in their policies.
If you email support, privacy, or legal, we and our email service providers process your address, message, attachments, and correspondence to respond, verify requests, and keep necessary support records. Please do not send passwords, payment-card details, or unnecessary journal content. We retain correspondence as needed to handle your request and applicable recordkeeping obligations.
10. Age and changes
Diaroo is intended for people aged 13 or older, or the higher minimum age required in their location. A parent or guardian should review the terms for users under 18. If you believe a child has provided personal information, contact us. We update this page when practices change and request new consent when required.
11. Contact
Taoftware LLC
21520 Yorba Linda Blvd Ste G #3007
Yorba Linda, California 92887
[email protected]