Privacy Policy — AI features

Effective date: 2026-09-04  ·  Last updated: 2026-09-04

This policy covers Review Diary (com.sskplay.a3diary, Android), an app published by sskplay (“we”, “our”). Review Diary can send a diary entry to an AI model to write a reflection on it, and it keeps a small amount of data on a server we operate. Because of that it is not covered by our general privacy policy, which describes apps that keep everything on your device. Where the two differ, this page is the one that applies to Review Diary.

Overview

Your diary lives on your phone. No diary text is sent anywhere until you ask for something that requires it, and there are exactly two such things:

If you do neither, no diary text ever leaves your device. Both are off until you act, and both can be stopped at any time.

Separately from your diary, the app does send us a small amount of data that is not diary content: an anonymous installation record, and any feedback you choose to send us from inside the app. Those are listed in full under What we keep on our server below.

Separately again, the app reports crashes and usage analytics to Google, and the free version shows banner ads. Neither carries your diary: see Crash reports and usage analytics and Advertising below.

AI reflections — what is sent

When you explicitly request a reflection on a diary entry:

The entry passes through our server in order to reach the model, and the app tells you so before you use the feature: “Your entry is stored on our server and reviewed by AI.” Today, once the reflection has been returned, we do not keep the entry text in our database. Treat the in-app notice as the promise we are held to: if that ever stops being true, this page and the in-app notice change together, and neither will ever claim less handling than actually happens.

When a request fails

If a request to an AI provider fails, our gateway writes an error log that can include part of the request and part of the response — up to 900 characters, kept for up to 90 days, then deleted.

This is not a hypothetical: some providers echo the content of a request back in their error response, so on a failed reflection a fragment of your entry can end up in that log. The logs are used only to diagnose failures. They are not read for any other purpose, not linked to a name or email address, and not shared.

Model training

We do not use your diary entries to train any model of our own, and we require our AI providers not to use them for training either. We want to be exact about the limit of that promise: once a request leaves our gateway, this depends on the provider honouring its own terms. It is a contractual commitment we hold them to, not something we can technically enforce or independently verify.

What we keep on our server

Our server runs on Cloudflare, and the database is Cloudflare D1. Your diary text is not in it. What is:

Encrypted backup (optional, paid, off by default)

Backup exists so a diary survives a lost or replaced phone. It is off until you turn it on.

Google sign-in is used for backup and nothing else. It is what lets a restore on a new phone find the backup that belongs to you; without an account there is no way to identify a backup as yours after the old device is gone. Signing in is only required if you use backup.

Crash reports and usage analytics

The app includes Firebase Crashlytics and Firebase Analytics, both from Google. They tell us when the app breaks and which parts of it people actually use.

Both are processed by Google under the Google Privacy Policy. You can turn either one off on its own, under ⋮ > Privacy in the app. They start on, your choice is remembered between launches, and switching either off costs you no features at all.

No diary content is attached to any of these events, and that is enforced in the code rather than left to care: titles, entry text, and reflection results are never passed as event parameters, and even the length of a piece of writing is reported as a bucket (short, medium, long) rather than an exact count, because an exact character count is itself information about what you wrote. A source check fails the build if an analytics call so much as references an entry or title variable.

One honest exception: a crash report can contain a fragment of what you typed, because an exception message can carry the input that caused it. We cannot rule that out, so we would rather say it than let you assume otherwise.

Advertising (free version)

The free version of Review Diary shows banner ads provided by Google AdMob (Google LLC). Subscribing to premium removes them.

The ads and your diary are kept apart, and we want to be specific about what that means rather than leaving it to be inferred:

What Google may use to choose an ad is its own signals, not ours: the device's advertising ID, approximate location derived from your IP address, and coarse device information such as model, OS version, and language. That is Google's processing, governed by the Google Privacy Policy and AdMob's ads personalisation policy. On Android you can reset or delete the advertising ID, and opt out of ad personalisation, in Settings > Privacy > Ads.

In the EEA, the UK, and Switzerland, Google's UMP consent form is shown first, and no ad is requested until you have answered it. You can reopen that form from inside the app at any time and change what you chose.

What we do not do

Service providers

In-app purchases

The subscription is handled by Google Play Billing. Google receives and processes the payment — we never receive or store your payment details. We keep only the purchase token and whether the subscription is active, so the app knows what you are entitled to.

Children's privacy

Review Diary is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has used the app and sent us data, contact us and we will delete it.

Retention and deletion

How to ask us to delete your data

Email contact@sskplay.com with your installation ID, which is what identifies your records to us. You can find it by tapping the title on the diary screen seven times. We respond within 30 days.

Your choices

Changes to this policy

We may update this policy. When we do, we will update the “Last updated” date at the top of this page. Because this page is also the basis of our Google Play Data safety declaration, any change to how the app actually behaves is reflected here, in the in-app notice, and in that declaration together.

Contact