Privacy Policy

Last updated: August 27, 2026

Privacy at a glance

sosohan is local-first. You can create, edit, view, and export your diary without creating an account. Your pages, photos, videos, overlays, stickers, and tags stay on your device by default and are not uploaded automatically. An account is optional and is used when you choose encrypted backup and restore on another device.

The current app does not provide AI analysis and does not send your diary content to an AI provider.

What we collect

If you use sosohan without an account, your diary is handled locally by the app or browser. We do not need your diary content to let you use the local diary.

If you create an account, Supabase receives your email address and the account and session information needed to authenticate you. When you use encrypted backup and restore, our service receives an encrypted vault and the operational metadata needed to store, version, and retrieve it. This may include vault, revision, object, size, and timestamp metadata.

Local storage

Diary pages and related media are stored locally, including original and processed images, thumbnails, videos, overlays, stickers, tags, and edits. Local data remains on the device until you clear it, clear app or browser storage, or the operating system or browser removes it. Signing out does not remove a local copy.

Local storage is not a substitute for a backup. If you lose the device or remove its app or browser data before creating an encrypted backup, we may not be able to recover that diary.

Encrypted backup and restore

Backup and restore is optional. Before diary content or media leaves your device, the app encrypts it using a key derived from your backup passphrase. Supabase stores account and synchronization metadata, and Cloudflare R2 stores the encrypted vault objects. These providers do not receive your backup passphrase or the unwrapped key needed to read the vault.

We cannot read the plaintext pages, photos, videos, overlays, stickers, or tags in an encrypted backup. If you lose your backup passphrase, the encrypted backup cannot be unlocked by us. The web app only downloads and decrypts a backup locally for viewing; it does not create, edit, or upload diary content.

How we use information

We use account information to provide sign-in, account security, and backup and restore. We use synchronization metadata to store and deliver encrypted backups. We do not sell your diary content or use it for advertising. We do not make your diary public or share it with other users.

Retention and deletion

Your local diary remains on your device until you remove it. The encrypted backup and account information remain until you delete the account or ask us to remove them, subject to limited technical, security, or legal records that may need to be retained.

Clear this device removes the local diary from that device only. Delete account removes your account and encrypted backup data held by our service. It cannot remove local copies already stored on your devices, and account deletion cannot be undone.

Security

Connections to our services are encrypted in transit. Encrypted backup is designed so that the service does not have the key needed to read your diary. No method of storage or transmission is completely risk-free, so keep your devices and backup passphrase secure.

Contact

Questions about privacy or your data? Contact us at support@pineple.com.

Back to sign inTerms of Use