Privacy Policy
Last updated August 16, 2026
Tinta is built so your journal stays on your phone. That makes this page short — but the parts that aren't zero are spelled out in full, because a policy that only lists the flattering half isn't worth reading.
The short version
- Your journal content never leaves your phone. Not for AI, not for backup, not ever.
- There are no accounts and no servers of ours. There is nothing to sign into.
- Entries, chat history, drafts, moods and embeddings are encrypted on the device with AES-256. Voice recordings are not yet.
- Tinta does collect content-free usage analytics and crash reports through Google Firebase. Analytics can be turned off in Settings → Privacy.
- Nothing is sold. No advertising ID, no ads, no data brokers.
- You can export or delete everything yourself, at any time, without asking us.
What stays on your phone
All of it: journal entries, dictated text, chat history, drafts, the mood labels and reflective cues the AI produces, the embeddings that let Tinta find related entries, your settings, the voice recordings, and the two AI model files. Everything sits in app-private storage on your device, where other apps cannot reach it. Uninstalling Tinta removes the lot.
Encryption. Entries, chat history, drafts, mood data and embeddings are stored encrypted with AES-256. The key is generated on your device and kept in the phone's own secure keystore; it is never transmitted and we never see it.
One exception, stated plainly. When you dictate an entry, the voice recording is saved on your device alongside it as an audio file. That file is not yet encrypted at rest, unlike the text. It never leaves the phone, and deleting the entry or uninstalling the app deletes it — but until we encrypt those files too, this is the one place where the encryption promise above does not reach.
Dictation uses your phone's own recognizer. Tinta asks Android for on-device speech recognition and gets it where your phone supports it. That recognizer is a system service outside our control, so on devices without on-device support the audio is handled by the phone's speech provider rather than by Tinta. We receive nothing from it either way — the transcript comes back to the app and stays there.
What we collect
This is the complete list. If it isn't here, Tinta doesn't send it.
Crash reports and diagnostics
- What
- Stack traces, the app version, the device model and OS version, and a random per-install identifier.
- Why
- To find and fix what breaks. We cannot reproduce a crash we never hear about.
- Where
- Google Firebase Crashlytics, acting as our processor.
- Retention
- Held by Firebase on Google's Crashlytics retention schedule. We keep no separate copy.
- Opt-out
- None in-app. Crash reports carry no journal content and stay on so the app can be repaired.
Usage analytics
- What
- Which screens and features are opened and how often, a random per-install identifier, device and app version, your chosen theme and language, whether the app lock is on, and roughly how many entries you have (as a bucket — "1-9", "10-49", "50-199", "200+" — never the entries themselves). Firebase also derives an approximate location — country and region — from your IP address.
- Why
- To see which parts of the app are used and which are ignored, so the next version is better.
- Where
- Google Firebase Analytics, acting as our processor, together with the Firebase installation and session services it requires to tell one install from another.
- Retention
- Held by Firebase on Google's Analytics retention schedule. We keep no separate copy.
- Opt-out
- Settings → Privacy, any time. Collection stops immediately.
Feature switches
- What
- Tinta asks Firebase Remote Config for two on/off switches, one for the Chat screen and one for Patterns. They exist so we can turn a screen off if it breaks in the field. That is the whole of what they can change: they cannot alter the models, the prompts, what is stored, or what is collected.
- Why
- To disable a broken feature without waiting for a store update to reach everyone.
- Where
- Google Firebase Remote Config. The request sends nothing you have written.
- Opt-out
- None. Switching it off would remove our only way to disable a feature that is failing.
The model download
- What
- An ordinary web request for two public model files — so Hugging Face sees your IP address, as any website would.
- Why
- The AI has to be on your phone before it can run there. This happens once, on first launch.
- Where
- huggingface.co. We receive nothing from it and hold no account there tied to you.
- Opt-out
- None — but it happens once, and after it, the AI never needs a network again.
Google processes this data on our behalf under its Firebase privacy terms. None of it is linked to a name, an email or an account, because Tinta has none of those. Tinta contains no advertising SDK and collects no advertising ID; the Play advertising-ID permission is stripped from the app at build time, so it cannot be collected even by accident. Tinta also has no over-the-air update channel, so its code changes only through a Google Play update.
What we never collect
Your journal entries, dictated text, chat messages, drafts, moods, voice recordings, or anything derived from them. Your name, email address, phone number or contacts. Your precise location. An advertising ID. Anything at all from your phone's other apps.
Nothing you write is used to train an AI model — ours or anyone else's. Nothing is sold or shared with data brokers, advertisers or insurers. There is no server holding your journal, so there is no breach that could expose it and no subpoena that could reach it through us.
Your rights
The data controller is Elmar Abbasov, trading as Ubicray, reachable at ubicray@gmail.com. There is no data protection officer, because the scale of processing does not require one.
Legal bases (GDPR Art. 6). Crash reports and diagnostics: our legitimate interest in a working app. Usage analytics: our legitimate interest in improving it, which you can object to at any moment by switching analytics off in Settings → Privacy. Your journal content has no legal basis listed because we never process it.
Your rights (GDPR Art. 15–21). You may request access to, correction of, or deletion of the diagnostic data described above, restrict or object to its processing, and receive it in a portable form. Write to the address above; we'll answer within a month. Note what the architecture costs here: that data carries only a random per-install identifier we cannot match to you, so we usually cannot single out your records, and Art. 11 does not require us to collect more data to make you identifiable. Switching analytics off is the control that actually works. Your journal needs no request at all — it is on your phone, yours to export or erase.
Complaints. If you think we've handled your data badly, tell us — and you also have the right to complain to your national data protection supervisory authority.
Retention. We hold no journal data at all, for any period. The diagnostic data above is retained by Firebase on Google's schedules, noted per item.
Deleting and exporting
Delete a single entry inside the app, or delete all journal data from Settings. Uninstalling Tinta removes everything it ever stored, including the voice recordings and the model files. There is no account to close, because there is no account.
Export gives you a plain zip file holding three views of the same entries: Markdown you can read in any editor, JSON that Tinta imports back, and a second JSON that other journal apps understand. Nothing in it is encrypted or locked to Tinta, so the archive stays useful even if Tinta doesn't. It carries every entry with its date, mood and cue; chat history and voice recordings are not included.
One consequence worth knowing: with no cloud copy, a lost or wiped phone means a lost journal. Export when it matters to you.
Children
Tinta is not directed at children under 13, and we knowingly collect nothing from them. Since there is no sign-up, we hold no age information about anyone.
Changes to this policy
Changes are dated here rather than announced by email — we don't have your email.
- August 16, 2026
- Named the Firebase installation and session services that Analytics requires, gave Remote Config its own entry stating the two switches it controls, noted that dictation falls back to the phone's own speech provider where on-device recognition is unavailable, and recorded that the export archive excludes chat history and voice recordings.
- August 16, 2026
- Rewritten in full. Added the collection table with retention and opt-out per item, the approximate location Firebase derives from your IP, GDPR controller details and rights, and an explicit note that dictated voice recordings are stored unencrypted. An earlier version said audio was not stored; that was wrong, and this corrects it.
- April 5, 2026
- First published.
Questions
Write to ubicray@gmail.com, or use the developer contact on the Google Play listing. If something on this page turns out to be inaccurate, that is a bug and we want to hear about it.